757eaf5e34e4dc73648a115987403dc122c4b4f74b3c57472e7ec90bb5002b94

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2023-Oct-11 10:28:38
Detected languages English - United Kingdom
English - United States
Debug artifacts D:\a\GameMaker\GameMaker\GameMaker\Runner\VC_Runner\x64\Release-Zeus\Runner.pdb
CompanyName Airdorf Games LLC & New Blood Interactive
FileDescription FAITH: The Unholy Trinity v1.5
FileVersion 1.5.0.0
LegalCopyright 2024 Airdorf Games LLC
PrivateBuild 01.00.00.00
ProductName FAITH: The Unholy Trinity v1.5
ProductVersion 1.5.0.0

Plugin Output

Info Matching compiler(s): MASM/TASM - sig2(h)
Info Interesting strings found in the binary: Contains domain names:
  • RetroUSB.com
  • adobe.com
  • http://ns.adobe.com
  • http://ns.adobe.com/xap/1.0/
  • http://ns.adobe.com/xap/1.0/mm/
  • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
  • http://www.w3.org
  • http://www.w3.org/1999/02/22-rdf-syntax-ns#
  • https://yoyogames.zendesk.com
  • https://yoyogames.zendesk.com/hc/en-us/articles/360002243797
  • memtest86.com
  • ns.adobe.com
  • sourceware.org
  • www.memtest86.com
  • www.w3.org
  • yoyogames.zendesk.com
  • zendesk.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Suspicious The PE is possibly packed. Unusual section name found: minATL
Unusual section name found: .mydata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegCloseKey
  • RegQueryValueExW
  • RegOpenKeyExW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Uses Windows's Native API:
  • ntohs
  • ntohl
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
  • CallNextHookEx
Has Internet access capabilities:
  • InternetOpenA
  • InternetWriteFile
  • InternetConnectA
  • InternetCloseHandle
  • InternetCanonicalizeUrlA
  • InternetCrackUrlA
  • InternetReadFile
  • InternetGetConnectedState
Leverages the raw socket API to access the Internet:
  • setsockopt
  • sendto
  • inet_ntop
  • recvfrom
  • recv
  • listen
  • inet_ntoa
  • inet_addr
  • getsockopt
  • ioctlsocket
  • gethostname
  • closesocket
  • bind
  • accept
  • getpeername
  • select
  • __WSAFDIsSet
  • ntohs
  • ntohl
  • htons
  • htonl
  • socket
  • WSAStartup
  • WSACleanup
  • WSAGetLastError
  • WSAAddressToStringA
  • getaddrinfo
  • freeaddrinfo
  • connect
  • getsockname
  • send
Enumerates local disk drives:
  • GetDriveTypeW
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious The file contains overlay data. 50912 bytes of data starting at offset 0x6bfb20.
Safe VirusTotal score: 0/69 (Scanned on 2026-07-07 06:29:44) All the AVs think this file is safe.

Hashes

MD5 ee78fa80296960db9bf897c7c39dd5bf
SHA1 f3c231ef547a8fdfa2c778417bcb8f3e40e09dd4
SHA256 757eaf5e34e4dc73648a115987403dc122c4b4f74b3c57472e7ec90bb5002b94
SHA3 974c7de9eb44684980c8ccb0653b24fc1ed24db0f661ffd44a2ad3302c5cd337
SSDeep 196608:vGpCAFwgiOezfgOXbmDVkdwOis7TecaB/5nn2Qj4LQqyX:2kwOJfsR2WsE
Imports Hash 56045b07b2bd59adf96efcde457fa628

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x120

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 8
TimeDateStamp 2023-Oct-11 10:28:38
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x466400
SizeOfInitializedData 0x265a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000003C86E4 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x931000
SizeOfHeaders 0x400
Checksum 0x6c19b5
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 7a7a13b0d9c9d7d141d7348832b7b661
SHA1 6b1d83b2b5c682f9374bba9c03d90194e87549c2
SHA256 34c7283282569cfe1e3ed5ad294905874d11457de6e56a6e467b9caa40df105c
SHA3 e1c684e201c03755d73208b95e1354e0610cf9eb949fbbb3d2250fd5801bb68b
VirtualSize 0x4663e4
VirtualAddress 0x1000
SizeOfRawData 0x466400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.51626

.rdata

MD5 9330b6ce635c2ea74b4489a654dc92ce
SHA1 4c5c62b5caaed0f6a35e2ae71ad62d820e3a94d2
SHA256 5f406525f9197a14921902d03bea5cf2d9d506141a9ffe32f2c3718235e67f31
SHA3 671ebcbca24b35d5be055b5fb6225fb9c4e0f0bf87fdefe420107bc96ac52f6c
VirtualSize 0x180250
VirtualAddress 0x468000
SizeOfRawData 0x180400
PointerToRawData 0x466800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.69055

.data

MD5 f886ee5fea5bc294343861f8361afd87
SHA1 fced9348e09bf4da10a0ad82d2b57b7214791983
SHA256 99830a4372b663065cce2d207c693f17e55a3f548d22b0d2bfbcdc38f8fe5828
SHA3 2317d662cbdab2a821054b501f75aac18281de193a6d2f3fafbade23c836dbd8
VirtualSize 0x2e9840
VirtualAddress 0x5e9000
SizeOfRawData 0x8aa00
PointerToRawData 0x5e6c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.77591

.pdata

MD5 c821cb9ef01228376a4ca0168f7d3b45
SHA1 bac2400a6a00c7ed45016fc127765c95c9cec4c6
SHA256 cb53898406765f007d6672d79f1ac9126ca9aa2c6bc25f801e3bb1cee9e96002
SHA3 c443637c5415975f1f2fc492546c8751f45d8beab96f88b1b9a0785216241dd2
VirtualSize 0x408e4
VirtualAddress 0x8d3000
SizeOfRawData 0x40a00
PointerToRawData 0x671600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.4983

minATL

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x18
VirtualAddress 0x914000
SizeOfRawData 0x200
PointerToRawData 0x6b2000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0

.mydata

MD5 9475a59226943a3ad422e18169989f66
SHA1 4174927c59854c80d33c69e7a43856b2b6c6af84
SHA256 d839a3521723b8a55d09d8eed9848940b284828e4d09218202c3ee11046bc16d
SHA3 6a93cc87909571d767d237e39dc48f437ee4242cf646fe335698b2b191003d4e
VirtualSize 0x10
VirtualAddress 0x915000
SizeOfRawData 0x200
PointerToRawData 0x6b2200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
IMAGE_SCN_MEM_WRITE
Entropy 0.0203931

_RDATA

MD5 953ede4bc39178e51c8d537f147b9a09
SHA1 7a33939f7f948e735d7e7098c6b0a9622c39b928
SHA256 9fd078306e9fcabc541163f82936364bdd6881346ad13d8b489717048e3aa117
SHA3 aa4017fa5d433e3d8273d8bea991639aaede0e893262988f9b03365c9a43fe4e
VirtualSize 0xfc
VirtualAddress 0x916000
SizeOfRawData 0x200
PointerToRawData 0x6b2400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.46842

.rsrc

MD5 9b585a0a0c1a8849d89f274a3fbec5c4
SHA1 312c74a4a2e76b21dd8b9285aa18393397f57da7
SHA256 888bed5fbf2c8ccbf45724f76cab840bbded932d3e1fc3a1ba6f68780c94ace4
SHA3 440da194312839a25b5f6f008666cd133f78fe7faa4d0f45877168378fa5246e
VirtualSize 0x19ba8
VirtualAddress 0x917000
SizeOfRawData 0x19c00
PointerToRawData 0x6b2600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.50593

Imports

RPCRT4.dll UuidCreate
UuidToStringW
WININET.dll InternetOpenA
InternetWriteFile
HttpOpenRequestA
InternetConnectA
InternetCloseHandle
InternetCanonicalizeUrlA
InternetCrackUrlA
InternetReadFile
HttpSendRequestA
HttpEndRequestW
HttpQueryInfoA
InternetGetConnectedState
d3d11.dll D3D11CreateDevice
dbghelp.dll SymInitialize
MiniDumpWriteDump
SymFromAddr
WINMM.dll mciSendStringA
joyGetPosEx
joyGetPos
timeGetTime
timeGetDevCaps
timeBeginPeriod
timeEndPeriod
mciGetErrorStringA
WS2_32.dll setsockopt
sendto
inet_ntop
recvfrom
recv
listen
inet_ntoa
inet_addr
getsockopt
ioctlsocket
gethostname
closesocket
bind
accept
getpeername
select
__WSAFDIsSet
ntohs
ntohl
htons
htonl
socket
WSAStartup
WSACleanup
WSAGetLastError
WSAAddressToStringA
getaddrinfo
freeaddrinfo
connect
getsockname
send
gdiplus.dll GdiplusStartup
GdiplusShutdown
COMCTL32.dll InitCommonControlsEx
VERSION.dll GetFileVersionInfoW
VerQueryValueW
GetFileVersionInfoSizeW
MFPlat.DLL MFCreateMediaType
MFShutdown
MFStartup
MFCreateSourceResolver
MF.dll MFCreateMediaSession
MFCreateSampleGrabberSinkActivate
MFCreateAudioRendererActivate
MFGetService
MFCreateTopologyNode
MFCreateTopology
KERNEL32.dll HeapReAlloc
GetTimeZoneInformation
SetStdHandle
ReadConsoleW
SetFilePointerEx
GetFileSizeEx
GetConsoleMode
GetConsoleOutputCP
FlushFileBuffers
EnumSystemLocalesW
GetUserDefaultLCID
IsValidLocale
LCMapStringW
CompareStringW
GetTimeFormatW
GetDateFormatW
GetTempPathW
SetConsoleCtrlHandler
WriteFile
GetStdHandle
FreeLibraryAndExitThread
ResumeThread
ExitThread
PeekNamedPipe
GetFileType
GetFileInformationByHandle
IsValidCodePage
FileTimeToSystemTime
SystemTimeToTzSpecificLocalTime
FindFirstFileExW
MoveFileExW
SetFileAttributesW
GetFileAttributesExW
GetModuleHandleExW
HeapWalk
HeapValidate
RtlUnwind
LoadLibraryExW
InterlockedFlushSList
InterlockedPushEntrySList
RtlPcToFileHeader
RtlUnwindEx
VirtualQuery
GetProcessHeap
HeapFree
HeapAlloc
InitializeSListHead
RaiseException
GetStartupInfoW
IsDebuggerPresent
CreateEventW
GetACP
GetOEMCP
ResetEvent
SetEvent
IsProcessorFeaturePresent
TerminateProcess
GetCommandLineA
SetCurrentDirectoryW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
OutputDebugStringW
SetEndOfFile
HeapSize
GetDriveTypeW
RtlCaptureStackBackTrace
EnterCriticalSection
LeaveCriticalSection
GetProcAddress
LoadLibraryW
WideCharToMultiByte
GetLastError
LoadLibraryA
MultiByteToWideChar
CloseHandle
WaitForSingleObjectEx
CreateEventExW
OutputDebugStringA
GetConsoleWindow
GetCurrentDirectoryW
DeleteFileW
GetFullPathNameW
SetLastError
CreateThread
GetExitCodeThread
GetModuleHandleW
LocalFree
FormatMessageW
SetCurrentDirectoryA
GetCurrentDirectoryA
CreateFileW
GetFileAttributesW
GetFileSize
ReadFile
SetFilePointer
FreeLibrary
FormatMessageA
GetEnvironmentVariableW
CreateDirectoryW
FindClose
FindFirstFileW
FindNextFileW
RemoveDirectoryW
Sleep
GetExitCodeProcess
CreateProcessW
QueryPerformanceCounter
QueryPerformanceFrequency
WaitForSingleObject
SetWaitableTimer
CreateWaitableTimerW
GetTickCount64
GetCurrentProcess
K32GetProcessMemoryInfo
GetFileAttributesA
GetCurrentThread
SetThreadPriority
SetPriorityClass
GlobalAlloc
GlobalUnlock
GlobalLock
GlobalMemoryStatusEx
GetSystemInfo
GetVersionExW
GetLocaleInfoW
VerSetConditionMask
VerifyVersionInfoW
GetCurrentProcessId
DebugBreak
GetEnvironmentVariableA
ExitProcess
lstrlenA
GetCommandLineW
ExpandEnvironmentStringsW
GetFinalPathNameByHandleW
SetUnhandledExceptionFilter
SetErrorMode
GetCurrentThreadId
GetModuleFileNameW
MoveFileA
InitializeCriticalSectionAndSpinCount
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
GetStringTypeW
GetLocaleInfoEx
GetCPInfo
CompareStringEx
LCMapStringEx
DecodePointer
EncodePointer
CreateSymbolicLinkW
GetFileInformationByHandleEx
CloseThreadpoolWait
SetThreadpoolWait
CreateThreadpoolWait
CloseThreadpoolTimer
WaitForThreadpoolTimerCallbacks
SetThreadpoolTimer
CreateThreadpoolTimer
CloseThreadpoolWork
SubmitThreadpoolWork
CreateThreadpoolWork
FreeLibraryWhenCallbackReturns
GetSystemTimeAsFileTime
GetCurrentProcessorNumber
FlushProcessWriteBuffers
CreateSemaphoreExW
InitOnceExecuteOnce
DeleteCriticalSection
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
SetFileInformationByHandle
GetNativeSystemInfo
SwitchToThread
SleepConditionVariableSRW
SleepConditionVariableCS
WakeAllConditionVariable
WakeConditionVariable
InitializeConditionVariable
TryEnterCriticalSection
InitializeCriticalSectionEx
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
InitializeSRWLock
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
WriteConsoleW
USER32.dll UpdateWindow
GetForegroundWindow
SetProcessDPIAware
SetWindowLongPtrW
IsDialogMessageW
PeekMessageW
DispatchMessageW
TranslateMessage
MonitorFromWindow
GetMonitorInfoW
EnumDisplaySettingsA
RegisterClassExW
GetRawInputDeviceInfoA
GetRawInputDeviceList
MessageBoxW
SendMessageW
PostMessageW
DefWindowProcW
GetDlgItem
CreateWindowExW
DestroyWindow
SetDlgItemTextA
MessageBoxA
GetFocus
IsClipboardFormatAvailable
EmptyClipboard
GetClipboardData
SetClipboardData
CloseClipboard
OpenClipboard
keybd_event
GetAsyncKeyState
wsprintfW
GetCursorPos
GetActiveWindow
EnumDisplayDevicesW
EnumDisplaySettingsW
MapWindowPoints
ClientToScreen
SetCursorPos
MoveWindow
SetWindowTextW
ReleaseDC
GetDC
DrawTextW
GetDlgItemTextW
SetDlgItemTextW
EndDialog
DialogBoxParamW
CreateDialogParamW
LoadImageW
LoadCursorW
CallNextHookEx
ScreenToClient
SetCursor
AdjustWindowRectEx
GetWindowRect
GetClientRect
SetForegroundWindow
GetSystemMetrics
ReleaseCapture
SetCapture
GetKeyState
SetFocus
BringWindowToTop
SetWindowPos
ShowWindow
GDI32.dll GetDeviceCaps
SelectObject
GetStockObject
COMDLG32.dll GetOpenFileNameW
GetSaveFileNameW
ADVAPI32.dll RegCloseKey
RegQueryValueExW
RegOpenKeyExW
SHELL32.dll ShellExecuteW
SHGetFolderPathW
ole32.dll CoCreateInstance
PropVariantClear
CoInitialize
CoTaskMemFree
CoCreateFreeThreadedMarshaler
dwmapi.dll DwmGetCompositionTimingInfo

Delayed Imports

1

Type RT_ICON
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.07704
MD5 892f0f6732ef0f73cf6db51e62017a74
SHA1 7d4428613b8ec9c1380ed96e18d4f2d0c380c94a
SHA256 96c7b054d2e1d983e964da4f6749b7a8e4fe6296cb4803b5668bf61a1d5deda4
SHA3 aaff03cd3c772f9407539198680994d4b6303f226f27df7ddba46096d6373f36

2

Type RT_ICON
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x139
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.27644
Detected Filetype PNG graphic file
MD5 3c4d1c48f960496001146d757369e385
SHA1 c7f9e77a6018fe34b70a8b545d9ee3dd54bf3b87
SHA256 5a9c63382cdebb96c73ebf2d6679b3370fb67adf69ebad7030eed1859b516d4f
SHA3 02ae3309f97917cd58c3d3728e255b2b7bfcc7f5d3517141cf8c6bf4019c538c

3

Type RT_ICON
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.17929
MD5 bccc7b495a3f6e569d03792b2109a0dd
SHA1 2fc0dc0b7897cda0f831f41c39c3b2eb9b9cdddf
SHA256 9b4eac904058460c2d4e470c7c9d247e4b3985957fe767730a8341a25e3aecc2
SHA3 6249c232900104405675df06f3b081dcd5346a12cdb7c17c62e110f760547191

4

Type RT_ICON
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.22472
MD5 350b659427b26a65405e587c1d64850a
SHA1 1ecc4cdb8e755d9e7f1a9b5972f1f84d4af82f82
SHA256 2a1ef63497c5a52fac9cd23a1f20ff7083454aa8dbb777a859b37a7339b7d999
SHA3 8b0987861df3dfb579a22d473a9ad440fdc7320b04587635e4aa21ea41bb254b

5

Type RT_ICON
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.23517
MD5 6729ad96df975f6fb78afd003fe8daf9
SHA1 f35613768fadeb716d2e7c49d17945179fd023cb
SHA256 03af3b35f36d1522e298a818a36c09d9c1b8032617223159a9d3f66b5f7b4834
SHA3 95c62472b2e1fc8c497a2cb0a3515c5add36327a98ed730befe40078a9d2fcb0

6

Type RT_ICON
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.3084
MD5 4c2b33610facdb4a66c0063b91f1bedf
SHA1 650b3a11de2f7a9cba586280bd1345006cc416e0
SHA256 f74cc406bd1064d196aba5f6841d6ccb05dc9c66e6a196ee5b0bbbb4f745d5fe
SHA3 b861eee456cc29a0c671d41cb5adf8aa96e8d5c5ab81b922961679f96381d6bd

7

Type RT_ICON
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.42098
MD5 dbbc6c80cd29d9085d8d710940ac78fe
SHA1 7bed5feabe5c53fb071ea8d7a01b5be70f7a1f1c
SHA256 6bd2917aa9f0647103712cf0e507b6adddec2a14cb859c70cf39329bf87e6221
SHA3 7420839beebeb8333715a845a38e2d91f78bc36634ee2cc9cec53ade2ea11651

IDD_ERROR_CODE

Type RT_DIALOG
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x120
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11903
MD5 ac3f07c5aa93e413823a32f659240ad1
SHA1 d78e110cb30ccff6366e410f6a16009383f8f2e9
SHA256 b45c6a3366adc913f8d1f3cd2289aeddc2b4dae28c0e39daa911009f50234c43
SHA3 89f27075d14968fef9bdad5097adf1e3f751b7238149ba82eec741da3e19086a

IDD_INPUTQUERY

Type RT_DIALOG
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0xf0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.06903
MD5 c2624d0a67009076569b24ceaf5c25f0
SHA1 9430e62b31117c2a62b30d5067a9a485b2b92262
SHA256 6bd1990b830571c05426131c936352f081dbf227a5f1f8708be380bb68c0ef1e
SHA3 87c0e1470f39b15c7cde38546d123ea57c64a448bb9ec5e30e1582325f7d6497

IDD_LOGIN_ASYNC

Type RT_DIALOG
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x13c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.07583
MD5 6b0f04cd06a91ff5ee96decd8eb6dbc6
SHA1 240236f7e7f1c2cea21c1d5eac0bef98094eb18a
SHA256 28ae1807e280b537ef8a9b5df66942cd52adf418cd5a2e0b07ef48b25bd08955
SHA3 f3d6f5a0f7c6fb4bd8a283c4f8bfc9337364cb28e696784dcb8f543d9d79e89b

IDD_MESSAGE_ASYNC

Type RT_DIALOG
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x9c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00453
MD5 ed9d6ad0e3e5f287913a8c39386eb08e
SHA1 3856ad95adbb8ffdb971bd44a43e32ff7da10c9e
SHA256 09ae8082cc363799b57616423e47409390c11fc632c0958826d98420683aa83a
SHA3 19d277b2aea915c99d664198e3339347acae3070829ba1269eda8de02a6b820e

IDD_QUESTION

Type RT_DIALOG
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0xcc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11344
MD5 c73c99bc6638f100b097bf7fcca8f264
SHA1 1713cd590521632bcfb0be68c27b18a740edec1c
SHA256 a0c9982c1806c9802b63ba6a73a9deedd2825fe0b7a6b86ec16c098d8422587d
SHA3 ac3b5ddd8e27e4d89cce23d9fd85784ffc8e1a7b827a762e384f4a9bb45b3f08

152

Type RT_GROUP_ICON
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.79908
Detected Filetype Icon file
MD5 c5637a12bdb86f37f898c6e4736c08e1
SHA1 059a7c08ee1c326564390fe73891c6ea3309b3bf
SHA256 91d505a1cb0db01445b94577c314e8cad55293744c46080e2016e4600e171748
SHA3 12a151ba991c8235f9a028e736508b0e699412662d4dc7dc6b87adc90a497f67

1 (#2)

Type RT_VERSION
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x308
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44441
MD5 705549e8fd4e202b6ddc8c4b7cfcc6ec
SHA1 df8f0a93bfc2ea1fe8bfcf670abc435f06e48abe
SHA256 165fa3eba138cdcc7911f845baa8a3b7252cd75736fdba5b50e05ec6c73bf299
SHA3 82429c5cae25738134173deb15ff834617c9d0248b28d0d9792dc3238006557c

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x3ed
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.1455
MD5 3e6e632b2b185b437f93065c7c3426ae
SHA1 5fa71bc80f327b1ec2eeb873cfd4e42e329ae8e8
SHA256 303329582a7a97ae5d873a1497b4af9edee9dd407e63cdad6dc268b3e1401419
SHA3 091a2aa6b7e002e26ec7e475c9a3da7a8109243a053bd65c5f6fc696e5f3e46a

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.5.0.0
ProductVersion 1.5.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_DLL
Language English - United Kingdom
CompanyName Airdorf Games LLC & New Blood Interactive
FileDescription FAITH: The Unholy Trinity v1.5
FileVersion (#2) 1.5.0.0
LegalCopyright 2024 Airdorf Games LLC
PrivateBuild 01.00.00.00
ProductName FAITH: The Unholy Trinity v1.5
ProductVersion (#2) 1.5.0.0
Resource LangID English - United Kingdom

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2023-Oct-11 10:28:38
Version 0.0
SizeofData 104
AddressOfRawData 0x57acd0
PointerToRawData 0x5794d0
Referenced File D:\a\GameMaker\GameMaker\GameMaker\Runner\VC_Runner\x64\Release-Zeus\Runner.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2023-Oct-11 10:28:38
Version 0.0
SizeofData 20
AddressOfRawData 0x57ad38
PointerToRawData 0x579538

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2023-Oct-11 10:28:38
Version 0.0
SizeofData 1156
AddressOfRawData 0x57ad4c
PointerToRawData 0x57954c

TLS Callbacks

StartAddressOfRawData 0x14057b200
EndAddressOfRawData 0x14057b208
AddressOfIndex 0x1408d1268
AddressOfCallbacks 0x140469000
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14066e1f8

RICH Header

XOR Key 0x18df31a6
Unmarked objects 0
ASM objects (30795) 30
253 (28518) 8
C objects (30034) 20
ASM objects (30034) 12
C++ objects (30034) 93
C objects (30795) 48
C++ objects (30795) 222
173 (VS2010 build 30319) 1
Imports (21202) 2
Imports (30795) 37
Total imports 350
C objects (30152) 177
C++ objects (30152) 373
Resource objects (30152) 1
151 1
Linker (30152) 1

Errors

[*] Warning: The WIN_CERTIFICATE appears to be invalid.
Leave a comment

No comments yet.