789366c51628fce7d44d628ed1ddcc6050baa38a130a53e76bceede09295d801

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Mar-09 17:52:10
Debug artifacts P:\Work\Projects\Terraria\Terraria\Terraria\obj\Linux\Release (Steam)\Terraria.pdb
Comments
CompanyName Re-Logic
FileDescription Terraria
FileVersion 1.4.5.6
InternalName Terraria.exe
LegalCopyright Copyright © 2026 Re-Logic
LegalTrademarks
OriginalFilename Terraria.exe
ProductName Terraria
ProductVersion 1.4.5.6
Assembly Version 1.4.5.6

Plugin Output

Info Matching compiler(s): Microsoft Visual C# v7.0 / Basic .NET
.NET DLL -> Microsoft
.NET executable -> Microsoft
Suspicious PEiD Signature: HQR data file
Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • Virus
  • virus
Contains domain names:
  • Content.de
  • Content.es
  • Content.fr
  • Content.it
  • Content.ru
  • Localization.Content.de
  • Localization.Content.es
  • Localization.Content.fr
  • Localization.Content.it
  • Localization.Content.ru
  • Pond5.com
  • SoundSnap.com
  • Terraria.Localization.Content.de
  • Terraria.Localization.Content.es
  • Terraria.Localization.Content.fr
  • Terraria.Localization.Content.it
  • Terraria.Localization.Content.ru
  • codeplex.com
  • crl.microsoft.com
  • forums.terraria.org
  • github.com
  • http://127.0.0.1
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl0Z
  • http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0
  • http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
  • http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl0Z
  • http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0X
  • http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
  • http://james.newtonking.com
  • http://james.newtonking.com/projects/json
  • http://www.codeplex.com
  • http://www.codeplex.com/DotNetZip
  • http://www.microsoft.com
  • http://www.microsoft.com/PKI/docs/CPS/default.htm0
  • http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
  • http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0
  • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
  • http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
  • http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0
  • http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
  • http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0
  • http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a
  • http://www.microsoft.com/pkiops/docs/primarycps.htm0
  • http://www.microsoft.com0
  • http://www.newtonsoft.com
  • http://www.newtonsoft.com/jsonschema
  • http://www.w3.org
  • http://www.w3.org/2000/xmlns/
  • https://bsky.app
  • https://discord.gg
  • https://forums.terraria.org
  • https://forums.terraria.org/index.php
  • https://github.com
  • https://steamcommunity.com
  • https://terraria.org
  • https://terraria.wiki.gg
  • https://terraria.wiki.gg/
  • https://twitter.com
  • https://www.instagram.com
  • https://www.instagram.com/terraria_logic/
  • https://www.nuget.org
  • https://www.nuget.org/packages/Newtonsoft.Json.Bson
  • https://www.reddit.com
  • https://www.reddit.com/r/Terraria/
  • instagram.com
  • james.newtonking.com
  • microsoft.com
  • newtonking.com
  • newtonsoft.com
  • nuget.org
  • reddit.com
  • steamcommunity.com
  • terraria.org
  • twitter.com
  • www.codeplex.com
  • www.instagram.com
  • www.microsoft.com
  • www.newtonsoft.com
  • www.nuget.org
  • www.reddit.com
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to Blowfish
Safe VirusTotal score: 0/71 (Scanned on 2026-05-25 20:48:07) All the AVs think this file is safe.

Hashes

MD5 15c5b36710fa6d5d911c474e60022df2
SHA1 87151e77f228c23ed22e312e06265e2d31a60cd3
SHA256 789366c51628fce7d44d628ed1ddcc6050baa38a130a53e76bceede09295d801
SHA3 0812e1d9a3a368ea56e6866f64ea8ec34a9320293f0b303b8ff8c2daddb4a4fb
SSDeep 98304:rBUOnsULg4ZvSf2nSE85ldEP3+OeHdr2ScB4I:rBbsUvZvSf2S35ldEP3+OMdc
Imports Hash f34d5f2d4577ed6d9ceec516c1f5a744

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 3
TimeDateStamp 2026-Mar-09 17:52:10
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32
LinkerVersion 48.0
SizeOfCode 0x18a7a00
SizeOfInitializedData 0x21800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x018976E6 (Section: .text)
BaseOfCode 0x2000
BaseOfData 0x18aa000
ImageBase 0x400000
SectionAlignment 0x2000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x18ce000
SizeOfHeaders 0x200
Checksum 0x18cda82
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 ca0493156248ba0f264839b3edad0acd
SHA1 a7bf8f58bbadee1b94ec3bcbb8f53af46f1d95db
SHA256 45b65ca17ffd043346fedb789ba055c3bca645b814cfc8ff71817236beee934b
SHA3 378f3e390a240f81f7b177dbd964b06e33035bd739e9a1fefb9e8d3446ecd727
VirtualSize 0x18a78e4
VirtualAddress 0x2000
SizeOfRawData 0x18a7a00
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.5717

.rsrc

MD5 07af0d54770273f6d999eb2b7f35c333
SHA1 560f7af4fce440c7aa4dc4e9eea2e81e92efc5b8
SHA256 7b4d9eb2d2806f95b509c70e2451356b9be50a7660797628e85be4e466b63684
SHA3 df06040030596cb1f86c62fa6a5f1f85168a817a53eec59a9f943de9d2da04ab
VirtualSize 0x2144c
VirtualAddress 0x18aa000
SizeOfRawData 0x21600
PointerToRawData 0x18a7c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.65742

.reloc

MD5 00fca420a398ea15c11d379fb71eeb8a
SHA1 8baccc2f93713a34452df5542f73f141f9832afa
SHA256 33a7bd5ddfabf83f50f9f918e43407d831562d4474be43f939f723b04cacb9a7
SHA3 4c5ca271a1b434700fe85f25b67686296bec8d2821caad891b68a10ec39a758d
VirtualSize 0xc
VirtualAddress 0x18cc000
SizeOfRawData 0x200
PointerToRawData 0x18c9200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.122276

Imports

mscoree.dll _CorExeMain

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x809e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9765
Detected Filetype PNG graphic file
MD5 5af79e5787fb9cb4600cb07736ef2771
SHA1 cffbbd54357735042bb0c3ff899c0551bfe355eb
SHA256 3b72fa0697ff6829c07d6f5625ddfd9e304947f3e84ee26549eaa5fb714e8958
SHA3 8b9fc132b1c10f313bba83cfe9635615b626c08129f80261dcb87429deb7e3ad

2

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.77835
MD5 825ddda1650c068569b75e9165f58fde
SHA1 f0b747682bdc64e8c20b90cbecfe6bf71ce6a470
SHA256 571928b21dd1edbcad994ac9655894a05e3d2a6ddd8d976818a7cac3de9f1127
SHA3 9a76f1fe95e8ecad6e5686c913b2ea63f3bc632060d93cf102d0653080dacd52

3

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.01776
MD5 45cb75cbe7e7ed55f0e461afb5fda9ad
SHA1 a25e427237592e9839ce8dc121aa6528ed8fb995
SHA256 a81e269c5779652af9a1e60088d76f596641331fc747b53dd1ff5d22a5ab3429
SHA3 5c861a8c5f2e15a48af7c409f5f495952e234e443584f982e8804e5388c42f2c

4

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.18292
MD5 bf5c739eac6e9ba3ed39c9bc2f5613bd
SHA1 6916526550616a9324197139f651db33ec9cb9d5
SHA256 50fed7f0351d7d5e0cff3424f37f5e59510638c9ffcbff670a9588c054e79523
SHA3 5d9e96971349914e4b1f5d42482c6c0f69a0d02df1898da81c0cf510f294b783

5

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3912
MD5 560d9b7fa77d81695eed9384807b2f14
SHA1 94bf05f726a008208dd9b670e3daf0fd1982cc35
SHA256 6673400ed9fa20dbf71770985c73f762757d7ec7a22ec298d73d688e2c1e9da8
SHA3 b325cf48eec2e234329ec46deda2e68b8886056c62c3216b06b820f0d763a18f

6

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.7334
MD5 4a0db7cf1173e492f35c5139e96658ce
SHA1 a1f9c76c8eaa64245d02cc704b1a433af31097e9
SHA256 2a283af31144109c7c632d350f888f632b41f81c76d329c0aad6dea2079984a2
SHA3 1e2591597c8c6087a68222e5a6568aa31d9455d221c1e2a33afba5c1dc75692d

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.76847
Detected Filetype Icon file
MD5 b26905080411fa274d212b990a6a7278
SHA1 f329566cc38b3da1e288f3d18022d4e3f62fc167
SHA256 3adffeadd07d3133c5726d11d7927d87400691a34883753969f6da7ef58ba0b6
SHA3 f55c48d028b372b05427367247ef57c8ea840e4bae765f58d10721b5f0bf4ab4

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x33c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32957
MD5 15afb8170e84c7438d872bc06eba575f
SHA1 59c6b0ee0a64a19771a4566872e6e3bfe5b52f0b
SHA256 bcc453ea2f2370132344ec44777b247c43bc9b0a316df3c2344c676d0ad53f9c
SHA3 62de05aa99147609444893347a22481922e071375dcf3bc329a13cbafb24e0f9

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x8e7
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.15001
MD5 8339fc4c91b9253342860e2cea90b17d
SHA1 cac486048a5f6b9f2813a873d6a68f1fb82cd7d4
SHA256 1ecd1cf6cfc8e941ccdab043ddb4a0f1bbe7769ad3fb31f49333749b81e185ee
SHA3 b2d2a8f683f44661102ad8d5f3f47d9f2cc11c11dbc91544b976101a3a956872

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.4.5.6
ProductVersion 1.4.5.6
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments
CompanyName Re-Logic
FileDescription Terraria
FileVersion (#2) 1.4.5.6
InternalName Terraria.exe
LegalCopyright Copyright © 2026 Re-Logic
LegalTrademarks
OriginalFilename Terraria.exe
ProductName Terraria
ProductVersion (#2) 1.4.5.6
Assembly Version 1.4.5.6
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Mar-09 17:52:09
Version 0.0
SizeofData 284
AddressOfRawData 0x1897578
PointerToRawData 0x1895778
Referenced File P:\Work\Projects\Terraria\Terraria\Terraria\obj\Linux\Release (Steam)\Terraria.pdb

TLS Callbacks

Load Configuration

RICH Header

Errors

Leave a comment

No comments yet.