902f12d9deea71d6e11b770bac772c2e66d1f9791b6ce0fbd8dbc3ee2f521103

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Aug-20 01:20:25
Detected languages English - United States
Debug artifacts C:\Users\kazim\Desktop\GG Emu\build\loader.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentControlSet\Services
Miscellaneous malware strings:
  • System32\drivers\etc\hosts
  • cmd.exe
Contains domain names:
  • a.pvp.net
  • ac.pvp.net
  • ap.vg.ac.pvp.net
  • auth.riotgames.com
  • br.vg.ac.pvp.net
  • cgauth.com
  • eu.vg.ac.pvp.net
  • github.com
  • google.com
  • https://cgauth.com
  • https://github.com
  • https://guns.lol
  • kr.vg.ac.pvp.net
  • latam.vg.ac.pvp.net
  • na.vg.ac.pvp.net
  • pool.ntp.org
  • riotgames.com
  • s.a.pvp.net
  • time.google.com
  • time.windows.com
  • valorant-api.com
  • vg.ac.pvp.net
  • windows.com
Info Cryptographic algorithms detected in the binary: Uses constants related to AES
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Possibly launches other programs:
  • CreateProcessA
  • ShellExecuteA
  • system
Uses Microsoft's cryptographic API:
  • CryptCreateHash
  • CryptAcquireContextW
  • CryptReleaseContext
  • CryptHashData
  • CryptDestroyHash
  • CryptGetHashParam
  • CryptDecodeObjectEx
  • CryptStringToBinaryA
  • CryptBinaryToStringA
  • CryptImportPublicKeyInfoEx2
Can create temporary files:
  • CreateFileA
  • CreateFileW
  • GetTempPathW
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
Has Internet access capabilities:
  • WinHttpOpen
  • WinHttpQueryHeaders
  • WinHttpReadData
  • WinHttpReceiveResponse
  • WinHttpSetOption
  • WinHttpCloseHandle
  • WinHttpConnect
  • WinHttpQueryDataAvailable
  • WinHttpSendRequest
  • WinHttpOpenRequest
  • WinHttpSetTimeouts
  • InternetConnectA
  • InternetCloseHandle
  • InternetOpenA
  • InternetQueryOptionA
  • InternetReadFile
  • InternetSetOptionA
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Interacts with services:
  • QueryServiceStatus
  • OpenSCManagerW
  • ControlService
  • OpenServiceW
  • QueryServiceStatusEx
Manipulates other processes:
  • Process32FirstW
  • OpenProcess
  • Process32NextW
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 30/70 (Scanned on 2026-08-20 16:50:15) ALYac: Generic.Dacic.21894.03467B04
APEX: Malicious
AVG: FileRepMalware [Misc]
Arcabit: Generic.Dacic.21894.03467B04
Avast: FileRepMalware [Misc]
BitDefender: Generic.Dacic.21894.03467B04
Bkav: W32.Malware.187B31E1
CTX: exe.trojan.dacic
CrowdStrike: win/malicious_confidence_90% (D)
Cylance: Unsafe
DeepInstinct: MALICIOUS
ESET-NOD32: Win64/GameHack.AAO potentially unsafe application
Elastic: malicious (high confidence)
Emsisoft: Generic.Dacic.21894.03467B04 (B)
GData: Generic.Dacic.21894.03467B04
Google: Detected
K7GW: Unwanted-Program ( 006e45b61 )
Lionic: Trojan.Win32.Dacic.4!c
Malwarebytes: Generic.Malware/Suspicious
McAfeeD: ti!902F12D9DEEA
MicroWorld-eScan: Generic.Dacic.21894.03467B04
Microsoft: Trojan:Win32/Kepavll!rfn
Paloalto: generic.ml
SentinelOne: Static AI - Malicious PE
Sophos: Generic Reputation PUA (PUA)
Symantec: ML.Attribute.HighConfidence
TrellixENS: Artemis!649F422C2D92
TrendMicro-HouseCall: TROJ_GEN.R002H09HK26
VIPRE: Generic.Dacic.21894.03467B04
Varist: W64/ABApplication.FQVK-1318

Hashes

MD5 649f422c2d9234aa4e2695669651cd25 🔍
SHA1 5e46e8835f0e522624e47d344b0d9165b578a6a3 🔍
SHA256 902f12d9deea71d6e11b770bac772c2e66d1f9791b6ce0fbd8dbc3ee2f521103 🔍
SHA3 e90fb7af42f14ca585fde157b92c4759c480628df69fe5ed959752e009938ec9 🔍
SSDeep 12288:QK8W6uGSz7PfXEWshqc2DbwMt3S6weB5ImwS/Ui+n8EK:QK8Wue7PfI92QMt31w65lwS/Ui+nXK 🔍
Imports Hash a26d736d50167e35d1442a8425440361 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-20 01:20:25
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x82800
SizeOfInitializedData 0x2b400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000007D7D0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xb2000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 fee54865701e49b4d8a3b69e6ec34cf0 🔍
SHA1 e0a2f9b5c798356ea7e6bc23778b6a4b127d3e5d 🔍
SHA256 08b51496392c1782ba594258b8c939bc6069ad3d6f497ece2daa3f038f753314 🔍
SHA3 8a47d92bccec227402743c63c6a16deaac1ef90f5372b2fb0fbd1916f3f5242c 🔍
VirtualSize 0x82703
VirtualAddress 0x1000
SizeOfRawData 0x82800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.48154

.rdata

MD5 0c0dee607df9d6b448f9d58c5f096a12 🔍
SHA1 c371a345a5114f029fd55a0a5f581c7db315238e 🔍
SHA256 cee08f55a6e084bac9d59ef153b7e39c36bf985f07605f876f06920b604668dd 🔍
SHA3 6e5fab6bef8bf2a9f56d52cc22f8f0c127af112783499575b65d7592a29c606a 🔍
VirtualSize 0x2162a
VirtualAddress 0x84000
SizeOfRawData 0x21800
PointerToRawData 0x82c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.02689

.data

MD5 e3c569a0c7972d4ded9a79bf5b69a0f1 🔍
SHA1 5bef35e4533b42075b77e9b18e4612d274028e78 🔍
SHA256 284cf90e50f77c87b9175d929be8be835a51161e844a984c517e0d3e23fd8ae5 🔍
SHA3 c548aeef3114eea12e9fb7a5b37f0703321f9c76fd433b2371f0e5c2b96a951c 🔍
VirtualSize 0x2988
VirtualAddress 0xa6000
SizeOfRawData 0x1800
PointerToRawData 0xa4400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.2166

.pdata

MD5 0aee504f388bb94f1abc4f00ff564c0e 🔍
SHA1 c29ee69533143a3e7c2c038ff9099702aba7f036 🔍
SHA256 66257963bf8464f66cb6cc322e34347c3d1256a585a9fb0fba4d426cb97abdc4 🔍
SHA3 97efc410f4d8ad6563c47521def0d665c6e92d81f5cb09651f53b6985d0defe1 🔍
VirtualSize 0x5a00
VirtualAddress 0xa9000
SizeOfRawData 0x5a00
PointerToRawData 0xa5c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.94143

.rsrc

MD5 44411dbe48a5a8b23e29748dfe0f9a24 🔍
SHA1 e3b9a52c4f21fd809df6e5c08da55127d7d2d4c3 🔍
SHA256 ed1f69eb65bca072f43639d2930f51eefec03b7f00dbf346c9a989586aa924a7 🔍
SHA3 4a9e826f06d057536b45fdda7179fd50a80d3f75f642ec62782836b80657a714 🔍
VirtualSize 0x1190
VirtualAddress 0xaf000
SizeOfRawData 0x1200
PointerToRawData 0xab600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.33156

.reloc

MD5 50adc15ecb1bed6256c0ebbe2e69e38c 🔍
SHA1 51beab33bcabb997e6199b837ad5ae8ade13953d 🔍
SHA256 c9cb89173105064184402787b4c47c9e1994f4eff5dac337c5cfb6e83f566f3e 🔍
SHA3 5e4f05d8fa019c8b7789c88d10c3771b63cc3409dbe05bd930f48e503ac67448 🔍
VirtualSize 0x5d8
VirtualAddress 0xb1000
SizeOfRawData 0x600
PointerToRawData 0xac800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.34334

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
KERNEL32.dll Process32FirstW
CloseHandle
LoadResource
FindResourceW
FillConsoleOutputAttribute
Beep
GetProcAddress
SetFilePointerEx
CreateFileMappingA
LocalFree
GetCurrentProcessId
GetModuleHandleW
FreeLibrary
GetConsoleWindow
CreateProcessA
GetSystemTimeAsFileTime
SetConsoleCursorPosition
QueryPerformanceCounter
GetTickCount
SetConsoleTitleW
ConnectNamedPipe
FlushFileBuffers
GlobalAlloc
GlobalFree
GlobalLock
WideCharToMultiByte
QueryPerformanceFrequency
GetLocaleInfoA
OpenProcess
CreateFileA
GetFileAttributesExW
FindNextFileW
FindFirstFileExW
FindFirstFileW
FindClose
GetLocaleInfoEx
FormatMessageA
AreFileApisANSI
GetFileInformationByHandleEx
Process32NextW
GetLastError
DeleteFileW
LockResource
LoadLibraryA
GlobalUnlock
FileTimeToSystemTime
InitOnceComplete
InitOnceBeginInitialize
ReleaseSRWLockExclusive
GetModuleHandleA
DuplicateHandle
CreateFileW
AcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
RtlCaptureContext
RtlLookupFunctionEntry
GetTickCount64
Sleep
MultiByteToWideChar
WaitForSingleObject
CreateMutexA
GetEnvironmentVariableA
GetTempPathW
SetSystemTime
CreateNamedPipeW
TerminateProcess
OutputDebugStringA
WriteFile
GetStdHandle
GetCurrentProcess
SetConsoleTextAttribute
GetConsoleScreenBufferInfo
GetFileSizeEx
SetConsoleCtrlHandler
SizeofResource
FillConsoleOutputCharacterA
ReadFile
CreateToolhelp32Snapshot
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
IsDebuggerPresent
GetCurrentThreadId
InitializeSListHead
SetFileInformationByHandle
USER32.dll ScreenToClient
GetCapture
ClientToScreen
GetMessageExtraInfo
PeekMessageW
DispatchMessageW
RegisterClassExW
UnregisterClassW
GetKeyState
SetWindowPos
DestroyWindow
GetWindowRect
PostMessageW
DefWindowProcW
SetClipboardData
GetClipboardData
EmptyClipboard
CloseClipboard
OpenClipboard
SetCursorPos
ReleaseCapture
IsWindowUnicode
GetClientRect
SetCursor
SetCapture
LoadCursorW
GetForegroundWindow
GetKeyboardLayout
TrackMouseEvent
TranslateMessage
PostQuitMessage
UpdateWindow
IsIconic
GetCursorPos
ShowWindow
GetAsyncKeyState
CreateWindowExW
ADVAPI32.dll CryptCreateHash
LookupPrivilegeValueW
AdjustTokenPrivileges
CryptAcquireContextW
QueryServiceStatus
CloseServiceHandle
OpenSCManagerW
ControlService
CryptReleaseContext
CryptHashData
CryptDestroyHash
OpenProcessToken
OpenServiceW
CryptGetHashParam
QueryServiceStatusEx
SHELL32.dll ShellExecuteA
ShellExecuteExW
bcrypt.dll BCryptEncrypt
BCryptDestroyKey
BCryptGetProperty
BCryptFinalizeKeyPair
BCryptDecrypt
BCryptGenerateSymmetricKey
BCryptCreateHash
BCryptSetProperty
BCryptHashData
BCryptImportKeyPair
BCryptDestroyHash
BCryptCloseAlgorithmProvider
BCryptFinishHash
BCryptExportKey
BCryptGenRandom
BCryptOpenAlgorithmProvider
BCryptGenerateKeyPair
CRYPT32.dll CryptDecodeObjectEx
CryptStringToBinaryA
CryptBinaryToStringA
CryptImportPublicKeyInfoEx2
MSVCP140.dll ?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
??Bios_base@std@@QEBA_NXZ
??7ios_base@std@@QEBA_NXZ
?good@ios_base@std@@QEBA_NXZ
?always_noconv@codecvt_base@std@@QEBA_NXZ
??1facet@locale@std@@MEAA@XZ
?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z
?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
?_Incref@facet@locale@std@@UEAAXXZ
?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ
??1_Locinfo@std@@QEAA@XZ
??0_Locinfo@std@@QEAA@PEBD@Z
_Cnd_broadcast
??0facet@locale@std@@IEAA@_K@Z
?tolower@?$ctype@D@std@@QEBADD@Z
_Strxfrm
_Query_perf_frequency
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?_Throw_Cpp_error@std@@YAXH@Z
?id@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@2V0locale@2@A
?uncaught_exceptions@std@@YAHXZ
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?_Xbad_alloc@std@@YAXXZ
?_Id_cnt@id@locale@std@@0HA
?_Xout_of_range@std@@YAXPEBD@Z
?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z
?_Winerror_map@std@@YAHH@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z
?id@?$ctype@D@std@@2V0locale@2@A
?_Xlength_error@std@@YAXPEBD@Z
?id@?$collate@D@std@@2V0locale@2@A
?_Syserror_map@std@@YAPEBDH@Z
_Mtx_lock
_Strcoll
_Cnd_do_broadcast_at_thread_exit
_Cnd_wait
_Thrd_id
_Query_perf_counter
_Thrd_detach
_Xtime_get_ticks
_Thrd_join
_Mtx_unlock
?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?_Getcat@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?put@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@QEBA?AV?$ostreambuf_iterator@DU?$char_traits@D@std@@@2@V32@AEAVios_base@2@DPEBUtm@@PEBD3@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z
?getloc@ios_base@std@@QEBA?AVlocale@2@XZ
?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_J@Z
?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@V?$fpos@U_Mbstatet@@@2@@Z
WINHTTP.dll WinHttpOpen
WinHttpQueryHeaders
WinHttpReadData
WinHttpReceiveResponse
WinHttpSetOption
WinHttpCloseHandle
WinHttpConnect
WinHttpQueryDataAvailable
WinHttpSendRequest
WinHttpOpenRequest
WinHttpSetTimeouts
WININET.dll HttpSendRequestA
InternetConnectA
InternetCloseHandle
InternetOpenA
HttpQueryInfoA
InternetQueryOptionA
InternetReadFile
HttpOpenRequestA
InternetSetOptionA
HttpAddRequestHeadersA
WS2_32.dll htons
recv
connect
socket
send
WSAStartup
inet_pton
closesocket
setsockopt
Secur32.dll DecryptMessage
FreeCredentialsHandle
QueryContextAttributesW
EncryptMessage
AcquireCredentialsHandleW
InitializeSecurityContextW
DeleteSecurityContext
FreeContextBuffer
IMM32.dll ImmSetCandidateWindow
ImmReleaseContext
ImmGetContext
ImmSetCompositionWindow
D3DCOMPILER_47.dll D3DCompile
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll memset
_CxxThrowException
memcpy
memchr
memcmp
strstr
strchr
__std_terminate
__std_exception_copy
memmove
__std_exception_destroy
__current_exception_context
__C_specific_handler
__current_exception
api-ms-win-crt-runtime-l1-1-0.dll _invoke_watson
__p___argv
abort
__p___argc
_exit
exit
_c_exit
_initterm_e
_beginthreadex
system
_initterm
_get_initial_narrow_environment
terminate
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_cexit
_seh_filter_exe
_set_app_type
_register_thread_local_exe_atexit_callback
api-ms-win-crt-stdio-l1-1-0.dll __stdio_common_vswprintf_s
__acrt_iob_func
__stdio_common_vsscanf
_wfopen
_set_fmode
fflush
fseek
ftell
fclose
__p__commode
_fseeki64
__stdio_common_vsprintf_s
fgetc
__stdio_common_vfprintf
fwrite
__stdio_common_vsprintf
_get_stream_buffer_pointers
fgetpos
fread
fsetpos
ungetc
setvbuf
fputc
api-ms-win-crt-heap-l1-1-0.dll _callnewh
malloc
realloc
_set_new_mode
free
api-ms-win-crt-string-l1-1-0.dll strcpy_s
_wcsicmp
_stricmp
strcmp
api-ms-win-crt-time-l1-1-0.dll _localtime64_s
api-ms-win-crt-filesystem-l1-1-0.dll _lock_file
_unlock_file
api-ms-win-crt-convert-l1-1-0.dll atoi
api-ms-win-crt-math-l1-1-0.dll sinf
acosf
cosf
fmodf
ceilf
sqrtf
__setusermatherr
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
___lc_codepage_func
api-ms-win-crt-utility-l1-1-0.dll qsort

Delayed Imports

101

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0xb2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.38467
MD5 6651c7406d46d245125b2223c11e3cd5 🔍
SHA1 b054c1a0ecbad483bcd6a67c72f910611f37c1ec 🔍
SHA256 bf07c955bc792bc9ed9e669a24ae8591dcc85559c676d22558464ea94116c5e9 🔍
SHA3 236c5b2f3fa0a1493ed454f9d74273fea90b69fe99d01a70ed5659c633c2ec07 🔍

102

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0xe88
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.24092
MD5 ffb5ba2f59ba1036b67a5a8586efaf90 🔍
SHA1 24ce311c1f9b0f1301f79a87807735452fea3c3e 🔍
SHA256 ea644d162f38bddf473c8e80c1a2cc70ea53d71cfd9f163aa1a6bb4c2d7389df 🔍
SHA3 502e05f2b3a1f0dc5792f0d294d0e0937fca19476944b9e8c3bb8114d9e94ee5 🔍

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-20 01:20:25
Version 0.0
SizeofData 71
AddressOfRawData 0x96270
PointerToRawData 0x94e70
Referenced File C:\Users\kazim\Desktop\GG Emu\build\loader.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-20 01:20:25
Version 0.0
SizeofData 20
AddressOfRawData 0x962b8
PointerToRawData 0x94eb8

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-20 01:20:25
Version 0.0
SizeofData 912
AddressOfRawData 0x962cc
PointerToRawData 0x94ecc

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-20 01:20:25
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x140096680
EndAddressOfRawData 0x140096688
AddressOfIndex 0x1400a7c80
AddressOfCallbacks 0x140084ed0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1400a6040

RICH Header

XOR Key 0xe1798b17
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 20
C objects (35207) 10
C objects (33145) 1
C++ objects (35207) 43
ASM objects (35207) 6
Imports (35207) 6
Imports (33145) 35
Total imports 495
C++ objects (LTCG) (35228) 16
Resource objects (35228) 1
151 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.