| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jul-22 18:21:40 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
D:\Jenkins\workspace\BOP_phoenix_release_2.52.5\phoenix\Release\Battle.net.exe.pdb
|
| CompanyName | Blizzard Entertainment |
| FileDescription | Battleâ¤net |
| FileVersion | 2.52.5.17620 |
| InternalName | Battle.net |
| LegalCopyright | © 2012-2024 Blizzard Entertainment Inc. |
| OriginalFilename | Battle.net.exe |
| ProductName | Battle.net |
| ProductVersion | 2.52.5.17620 |
| Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE's digital signature is invalid. |
Signer: Blizzard Entertainment
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 The file was modified after it was signed. |
| Malicious | VirusTotal score: 41/71 (Scanned on 2026-09-09 03:12:46) |
ALYac:
Trojan.GenericKD.81097979
AVG: FileRepMalware [Drp] AhnLab-V3: Infostealer/Win.ACRStealer.R791359 Alibaba: Trojan:Win32/Shelma.6b2352ea Arcabit: Trojan.Generic.D4D574FB Avast: FileRepMalware [Drp] BitDefender: Trojan.GenericKD.81097979 Bkav: W32.Malware.9424E855 CTX: exe.trojan.shelma CrowdStrike: win/malicious_confidence_100% (W) Cylance: Unsafe DeepInstinct: MALICIOUS ESET-NOD32: Win32/GenKryptik.HUCV trojan Elastic: malicious (high confidence) Emsisoft: Trojan.GenericKD.81097979 (B) GData: Trojan.GenericKD.81097979 Google: Detected Kaspersky: Trojan.Win32.Shelma.chzl Kingsoft: Win32.Trojan.Shelma.chzl Lionic: Trojan.Win32.Shelma.W!c Malwarebytes: Trojan.Injector MaxSecure: Trojan.Malware.699266356.susgen McAfeeD: ti!A64F579AADDB MicroWorld-eScan: Trojan.GenericKD.81097979 Microsoft: Trojan:Win32/Wacatac.B!ml Paloalto: generic.ml Rising: Trojan.Injector!1.127AD (CLASSIC) Sangfor: Trojan.Win32.Shelma.Vrm8 Sophos: Mal/Generic-S Symantec: Trojan.Gen.MBT Tencent: Win32.Trojan.FalseSign.Iflw Trapmine: malicious.moderate.ml.score TrellixENS: Artemis!503F6644D405 TrendMicro: Trojan.Win32.SHELMA.USBLHE26 TrendMicro-HouseCall: Trojan.Win32.SHELMA.USBLHE26 VBA32: Trojan.Win32.HeavensGate VIPRE: Trojan.GenericKD.81097979 Varist: W32/ABTrojan.VZNJ-7359 VirIT: Trojan.Win32.GenusC.KCN Zillya: Trojan.Shelma.Win32.16295 alibabacloud: Trojan:Win/Wacatac.B9nj |
| MD5 | 503f6644d405ea64eeb00eb9a29767a1 🔍 |
|---|---|
| SHA1 | 2a279952b72ed00104981cd34ff04a900eafce3b 🔍 |
| SHA256 | a64f579aaddbfe0f05cf6fdbd528ed98e35ef54d2c9869b35fdd800ef559420b 🔍 |
| SHA3 | 6a19ead58cfb067a7e8bf7450dbd5554b629c59733b521a1ac3f00f2b9acf5d7 🔍 |
| SSDeep | 24576:qH8HmJaIgNYsfbDJvioYMhBt5svWNGFpZC9dYh:4pq/5svCGRCHYh 🔍 |
| Imports Hash | 0578002c9fc8279f752de56cfee7a485 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2026-Jul-22 18:21:40 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xab200 |
| SizeOfInitializedData | 0x4ce00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00078309 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xad000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x129000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x127170 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | db17c532f5636bf4ae6da88bd2f48fb6 🔍 |
|---|---|
| SHA1 | 54718d8311f7d809bbf870d6ab5e8fc0fb920e34 🔍 |
| SHA256 | b2a5039f65abf0f58e2ae83e3bfb6e53718fcdc4c96de2e11f0394aeed59f275 🔍 |
| SHA3 | 33bb4816b02253c4e2aca5e49aecc4e10010bf7285e09ba7058864e59a7ab032 🔍 |
| VirtualSize | 0xab1cc |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0xab200 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.62146 |
| MD5 | ea871a57dcae4138102cdec76d1b0592 🔍 |
|---|---|
| SHA1 | 0635d901efe68d33d03c4e11a123a0418bd66cdc 🔍 |
| SHA256 | 96750c49a2169c8b2dae499c09fa3beaba3dfdf519dce1a7654d33a2231379a4 🔍 |
| SHA3 | e16856ebad384b7984965ea05a843c1b83efde4780ed1e477674e155433e92c6 🔍 |
| VirtualSize | 0x21eae |
| VirtualAddress | 0xad000 |
| SizeOfRawData | 0x22000 |
| PointerToRawData | 0xab600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.66778 |
| MD5 | fd8dc279438f37b82c79af3ee9fd771d 🔍 |
|---|---|
| SHA1 | d5f9b6b55f64842b25dfa1b55962f7458fc92085 🔍 |
| SHA256 | 71d36f90e807b6d9131925260b332a6f93d93dd54ff9bbcbf8e1d5a20282b210 🔍 |
| SHA3 | 1bac1efecb1b106bbb91bc9aa62134710c6984203d04ae14383c8b6b7a59b3eb 🔍 |
| VirtualSize | 0x701c |
| VirtualAddress | 0xcf000 |
| SizeOfRawData | 0x2800 |
| PointerToRawData | 0xcd600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 4.51412 |
| MD5 | 0727baf9eaa7915d67d0a3c49942fa5d 🔍 |
|---|---|
| SHA1 | 796c941b8bde449359d615ba7c67fa4a00c6f392 🔍 |
| SHA256 | dbd9f6f049c20887a182c7c129a62412220bd1de06ca45a8e17356d78232c605 🔍 |
| SHA3 | 56a999a795e0a2b9da6af1e72999c082c83faade66d934580c55d487ce020609 🔍 |
| VirtualSize | 0x1c080 |
| VirtualAddress | 0xd7000 |
| SizeOfRawData | 0x1c200 |
| PointerToRawData | 0xcfe00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 3.44801 |
| MD5 | d70b65f9a61bc4c198c7803472a1915e 🔍 |
|---|---|
| SHA1 | 65001950e56221280df7a1bf510b8821843d3aaa 🔍 |
| SHA256 | 91afc7c124794c2a54fa37232c9d40d668671ba0a21ad7ec4205d4afd906cf43 🔍 |
| SHA3 | a56b6c11bb226c14e5801e81eb724ac9131e5ec0027263adcb3f63ea42c8c065 🔍 |
| VirtualSize | 0x34200 |
| VirtualAddress | 0xf4000 |
| SizeOfRawData | 0x34200 |
| PointerToRawData | 0xec000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 7.30485 |
| WININET.dll |
HttpQueryInfoA
InternetReadFileExA InternetCloseHandle HttpSendRequestA InternetSetCookieW HttpOpenRequestA InternetCrackUrlA InternetSetOptionA InternetConnectA InternetSetStatusCallbackA InternetOpenA |
|---|---|
| KERNEL32.dll |
WriteFile
TerminateProcess CreateDirectoryW GetFileAttributesW GetModuleFileNameW FindFirstFileW FindClose GetComputerNameW GetModuleHandleA SetEvent CreateEventW LoadLibraryW ReadFile GetFileSizeEx GetFileSize GetCompressedFileSizeW GetFileAttributesExW SetCurrentDirectoryW GetCurrentDirectoryW FindNextFileW FlushFileBuffers GetShortPathNameW GetDiskFreeSpaceExW SetFilePointer MoveFileW RemoveDirectoryW SetEndOfFile GetVolumeInformationW DeviceIoControl GetFileInformationByHandle SetFileTime SetFileAttributesW DeleteFileW SetFilePointerEx SetFileValidData GetSystemInfo SetThreadAffinityMask LocalFree LocalAlloc WideCharToMultiByte InitializeCriticalSection EnterCriticalSection LeaveCriticalSection DeleteCriticalSection OpenProcess MultiByteToWideChar SetThreadPriority GetThreadPriority TlsAlloc TlsSetValue TlsGetValue TlsFree QueryPerformanceCounter GetSystemTimeAsFileTime QueryPerformanceFrequency GetTickCount FileTimeToSystemTime SystemTimeToFileTime GetSystemDefaultLCID GetCommandLineW SetLastError WriteConsoleW GetStartupInfoW EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW UnhandledExceptionFilter GetCurrentThread GetModuleHandleW VirtualQuery SetUnhandledExceptionFilter IsDebuggerPresent OutputDebugStringW WaitForSingleObject CreateThread GetCurrentThreadId GetCurrentProcess GetCurrentProcessId CreateFileW Sleep GetLastError GetDiskFreeSpaceW FreeLibrary CloseHandle GetProcAddress GetDriveTypeW GetConsoleOutputCP GetConsoleMode HeapReAlloc ReadConsoleW FindFirstFileExW IsValidCodePage GetACP GetOEMCP GetEnvironmentStringsW FreeEnvironmentStringsW CompareStringW GetTimeFormatW GetDateFormatW HeapFree HeapAlloc GetStdHandle ExitProcess GetFileType SetStdHandle GetTimeZoneInformation GetCommandLineA IsProcessorFeaturePresent WaitForSingleObjectEx ResetEvent InitializeCriticalSectionAndSpinCount GetFullPathNameW GetModuleHandleExW FreeLibraryAndExitThread SetEnvironmentVariableW GetProcessHeap HeapSize RtlUnwind InterlockedPushEntrySList LoadLibraryExW RaiseException GetStringTypeW InitializeSRWLock ReleaseSRWLockExclusive AcquireSRWLockExclusive TryAcquireSRWLockExclusive InitializeCriticalSectionEx EncodePointer DecodePointer CompareStringEx GetCPInfo LCMapStringEx InitializeSListHead ExitThread |
| USER32.dll |
GetShellWindow
GetWindowThreadProcessId MessageBoxW GetForegroundWindow |
| ADVAPI32.dll |
OpenProcessToken
ConvertStringSecurityDescriptorToSecurityDescriptorW LookupPrivilegeValueW GetTokenInformation AdjustTokenPrivileges DuplicateTokenEx MapGenericMask AccessCheck CloseServiceHandle QueryServiceConfigW OpenServiceW OpenSCManagerW ConvertSecurityDescriptorToStringSecurityDescriptorW SetEntriesInAclW GetNamedSecurityInfoW SetNamedSecurityInfoW GetFileSecurityW AllocateAndInitializeSid BuildTrusteeWithSidW OpenThreadToken DuplicateToken |
| SHELL32.dll |
ShellExecuteExW
CommandLineToArgvW SHGetFolderPathW |
| OLEAUT32.dll |
VariantClear
|
| WINTRUST.dll |
WinVerifyTrust
|
| CRYPT32.dll |
CertFindCertificateInStore
CryptQueryObject CertFreeCertificateContext CertCloseStore CryptMsgClose CertGetNameStringW CryptMsgGetParam |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x10828 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 2.33768 |
| MD5 | 0e3b4e1e2d3dcd6fb6d8305ada43334d 🔍 |
| SHA1 | e85677678b4fec39e0a973d836278fa771e4236e 🔍 |
| SHA256 | c7754f4f421cb79e50ec4781d417c15db1af7196d2c3e7f76f43079ccbc3299c 🔍 |
| SHA3 | d15320720378ce7b361191f06864773a82eebdff6b471009d246c27adcc4ff11 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x468 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.83735 |
| MD5 | e526d7298e657cb6d283403ff925604e 🔍 |
| SHA1 | 4eabb364437d63770fb9186eb93574ff31b762d0 🔍 |
| SHA256 | 8df1e13ef6f884828658886b39d3efe4e6c9db204033a4de6067838e00239a04 🔍 |
| SHA3 | e3d0e4f72f4e46e897138feed2d53e9ecbabc137740e1e18c76cd81a2fecf5be 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x988 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.47141 |
| MD5 | e85370a97f7f378b6cddf29e3940e1a4 🔍 |
| SHA1 | 02591364930629aa733906285911258171925768 🔍 |
| SHA256 | 7a6e5ace5d8698f47617ce4115914f8cb5b6aedd35d4d6b775ca85c8b2b9b47d 🔍 |
| SHA3 | 8010010686302271c6390530cbb604e2a012d8b47066e53e950886f114c202bf 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x2754 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 7.92586 |
| Detected Filetype | PNG graphic file |
| MD5 | ea085b9d26d58203d15019f17bbd899f 🔍 |
| SHA1 | dd228613fa1eeeeaf4a32d82598fc3a56970c19f 🔍 |
| SHA256 | a904b117aa214a821446b600a16259ce3a8997064c510df2ed48b3fbd59755ef 🔍 |
| SHA3 | 3e7ed23c07f807a9a735f4e1afe8e4b952e29cfb9667870f4257d0ef8aee57be 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x10a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.24851 |
| MD5 | f2b6d5d473f9630432c3d99af5bd9030 🔍 |
| SHA1 | b6797fea703c9eac5dba5b2e4bfb872666041411 🔍 |
| SHA256 | bf2858aa648113865d7d7c14e61f6cb99d4ef31385f2315dc1127d7a564609b2 🔍 |
| SHA3 | b7c4a8ee4858ffe34b71d5facea36f4c0ca99453f70f1b3ec57b0526d13a4dbd 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x25a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 2.86021 |
| MD5 | d2414e2a58f6bb29eb014db8ed46317c 🔍 |
| SHA1 | f801b2f646fe277376637c26d16a95da0f1ac11f 🔍 |
| SHA256 | afb991079fc125e3f030eaa80715af5808bf74a34ede72a4d1e0e04f59993267 🔍 |
| SHA3 | 6fcfda24e9800018a4c3a6cbdcbcc0d14a66b55710d02cd4399245171e46a823 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x4228 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 2.67363 |
| MD5 | a7ede35cb7ef4ea941be84a6a71a62d5 🔍 |
| SHA1 | e1f8a0ef06d6fc5bc0b941b5dbaa83fd5a3438f4 🔍 |
| SHA256 | e8fa5964d76b6a6c524838fc084b3e3650a8936c23b012144a7859cbfee590fa 🔍 |
| SHA3 | dde3cfa2adbafa7c60bfff2d0307bd344e24b1813ba11b21e2e923ee0951cf3a 🔍 |
| Type |
RT_GROUP_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x68 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 2.91902 |
| Detected Filetype | Icon file |
| MD5 | aab2e0c754a941d0d7875ef807ce15c8 🔍 |
| SHA1 | 395e7b6d4d08a7c900693551b11a994fc0ce3f03 🔍 |
| SHA256 | f0a24c26d88e6b13ace5046ab09098375a13d5e8107526e299aa7e15da12a597 🔍 |
| SHA3 | 252d6ca69afb6302f252b8394e00de67a94a46718c3c82dbfb7c15b10dc0bbb8 🔍 |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x314 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.36694 |
| MD5 | 2d6a05e4e6e197aa430c7ef5c9a08921 🔍 |
| SHA1 | 33a18ca02dd1af24901f967c444dbe0ea4d60d39 🔍 |
| SHA256 | da876ba8df932802812ea738629ea0e6d5f6d7ddfb2962fb514310d1da085d11 🔍 |
| SHA3 | 12b33bc019a0922a0a72f1ce276e6d8b289ffd1f36548c286662e40f7f8a6d0a 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x4c3 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.29228 |
| MD5 | 69fe2ae1cf88be2030f71897bb1a2b30 🔍 |
| SHA1 | 66eec2258ebd419205076865062218e3aaa403fe 🔍 |
| SHA256 | f8aa54fde0ad78572178efc7c1f2b8263bc014be4ec4e781cd2e259591a5c1d5 🔍 |
| SHA3 | 8bc6a8be84c0238463a31536da92aa22b63bef6c4e23205125078910131b1c9f 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.52.5.17620 |
| ProductVersion | 2.52.5.17620 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | Blizzard Entertainment |
| FileDescription | Battleâ¤net |
| FileVersion (#2) | 2.52.5.17620 |
| InternalName | Battle.net |
| LegalCopyright | © 2012-2024 Blizzard Entertainment Inc. |
| OriginalFilename | Battle.net.exe |
| ProductName | Battle.net |
| ProductVersion (#2) | 2.52.5.17620 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-22 18:21:40 |
| Version | 0.0 |
| SizeofData | 107 |
| AddressOfRawData | 0xc66d8 |
| PointerToRawData | 0xc4cd8 |
| Referenced File | D:\Jenkins\workspace\BOP_phoenix_release_2.52.5\phoenix\Release\Battle.net.exe.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-22 18:21:40 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xc6744 |
| PointerToRawData | 0xc4d44 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-22 18:21:40 |
| Version | 0.0 |
| SizeofData | 960 |
| AddressOfRawData | 0xc6758 |
| PointerToRawData | 0xc4d58 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-22 18:21:40 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x4c6b28 |
|---|---|
| EndAddressOfRawData | 0x4c6b30 |
| AddressOfIndex | 0x4d1988 |
| AddressOfCallbacks | 0x4ad3c4 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks |
0x0043B990
|
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x4cf060 |
| SEHandlerTable | 0 |
| SEHandlerCount | 0 |
| XOR Key | 0x9eee3449 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 17 |
| C++ objects (30795) | 188 |
| C objects (VS2022 Update 4 (17.4.2) compiler 31935) | 19 |
| ASM objects (VS2022 Update 4 (17.4.2) compiler 31935) | 26 |
| C objects (30795) | 25 |
| C++ objects (VS2022 Update 4 (17.4.2) compiler 31935) | 91 |
| Imports (30795) | 21 |
| Total imports | 318 |
| C++ objects (LTCG) (VS2022 Update 5 (17.5.3) compiler 32216) | 18 |
| Resource objects (VS2022 Update 5 (17.5.3) compiler 32216) | 1 |
| 151 | 1 |
| Linker (VS2022 Update 5 (17.5.3) compiler 32216) | 1 |
No comments yet.