0edab561db9e95d2255dffb08d1e700a936bc0a14bdb9059c6d375794484c649

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jun-09 19:26:55
Detected languages English - United States
Debug artifacts C:\Users\777\Desktop\folder\manet\attempt2\ParamExtender\bin\x64\Release\MA3NodeEmulation.pdb
CompanyName u8nit
FileDescription MA3 Parameters Extender
FileVersion 1.0.0.0
InternalName MA3NodeEmulation
OriginalFilename MA3NodeEmulation.exe
ProductName GMA3 Node Emulationr
ProductVersion 1.0.0.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • github.com
  • https://github.com
Info Cryptographic algorithms detected in the binary: Uses constants related to AES
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryExW
Possibly launches other programs:
  • ShellExecuteW
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 4/65 (Scanned on 2026-07-22 02:31:46) APEX: Malicious
Bkav: W32.Malware.2DC08C01
Elastic: malicious (high confidence)
Symantec: ML.Attribute.HighConfidence

Hashes

MD5 5352f1944dcc5dfde8ff4870ed2e4b84 🔍
SHA1 f2afaae20670e2bd499ee657265cd769ccfc97e5 🔍
SHA256 0edab561db9e95d2255dffb08d1e700a936bc0a14bdb9059c6d375794484c649 🔍
SHA3 3e7164a33973f83ba9e785701817555fea516cd0ce335e40ff9191c92ce16e89 🔍
SSDeep 12288:FLsRNuDgs5QL7QMfBQt0SkqJv6D7Wqvw1rTR+bYiXnl1P:FLNDTdugZJvqWqveziXnPP 🔍
Imports Hash d0a28aa4077a53ef6b548e92aefc31e3 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Jun-09 19:26:55
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x90400
SizeOfInitializedData 0x31400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000648A0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xc6000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 4b607de1a86dbea95d7d24c447f6a65c 🔍
SHA1 3a3536d79aec0bb829dce7008ac9e150c21e6394 🔍
SHA256 bdd8f21ddab6a5de5f72dbb45831d9d709be348b71b21297941070a1e87e56dc 🔍
SHA3 c4822cbfca59663c89133143afcec7bd6c856745ab7c0a10049a7f7a82ad60a2 🔍
VirtualSize 0x902b0
VirtualAddress 0x1000
SizeOfRawData 0x90400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.55112

.rdata

MD5 1b349a4781e8312e9f7b0253dc2a6eab 🔍
SHA1 5f576c7ca6b39ab9355da85fcb1e43484bd9d822 🔍
SHA256 9918587f28e836fceb8582e2d8f47eaf47842819f04ac635200f75e1778fa80d 🔍
SHA3 ee69743658972e21789f6c3bc05cd75536fa18868316d53032de3d2c41b79f9b 🔍
VirtualSize 0x262c8
VirtualAddress 0x92000
SizeOfRawData 0x26400
PointerToRawData 0x90800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.88821

.data

MD5 32d71466a4e3703d88a9ddc5326a82b4 🔍
SHA1 eae4b059507606d0ca4db82008e1be640cb1935a 🔍
SHA256 217fef8f0c712961efb4ea8d5e01711f3272b9eb3f3272e8cab20b9faa34d94e 🔍
SHA3 4f2278388ee7e079a0a1e3f42a529a6366637e03291b1f207e2f535fbc21a7c7 🔍
VirtualSize 0x2e44
VirtualAddress 0xb9000
SizeOfRawData 0x1400
PointerToRawData 0xb6c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.83846

.pdata

MD5 5d6f431e532c42770e7b21c4f83aaae2 🔍
SHA1 d29e4c8dc7d89ffd2ad6928611daf782b90318ad 🔍
SHA256 ad46d324f34eab81aed69538e5e6ed93885f88c55f60f848f41f58e14afcb283 🔍
SHA3 387e75111e6f6f8310bc28aeccb473857e5c78c90f287127bb8d047942539614 🔍
VirtualSize 0x6a5c
VirtualAddress 0xbc000
SizeOfRawData 0x6c00
PointerToRawData 0xb8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.92676

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0xc3000
SizeOfRawData 0x200
PointerToRawData 0xbec00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 7d697e5483d53d0786ccfec9482eb05c 🔍
SHA1 a3a25f4e82fa312a0e0461864a4144495265df1e 🔍
SHA256 e62b379f99acb24e35e3dbd67750f447d6f0e0b6a6ad1f82e6f01d1122162884 🔍
SHA3 8c6aa78c26124a48270d0b00bc4e4b16b8bd834e402b0bb4422951697cc612f0 🔍
VirtualSize 0x4c8
VirtualAddress 0xc4000
SizeOfRawData 0x600
PointerToRawData 0xbee00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.56332

.reloc

MD5 8597fe2ba916e5f3ae1a46675878d014 🔍
SHA1 fa439064e1de7134261e60820e0355cfa835e242 🔍
SHA256 0e288dc9b6cda9965232a817c028c99151f66700af8a5572917e0b1de49287c1 🔍
SHA3 f706f8ab6ab4707ebbb64dbba99819f3e20ee0db03d1b03fc62b95b8f413d324 🔍
VirtualSize 0xb7c
VirtualAddress 0xc5000
SizeOfRawData 0xc00
PointerToRawData 0xbf400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.34947

Imports

WS2_32.dll inet_pton
WSAGetLastError
setsockopt
ioctlsocket
htons
getsockopt
recv
connect
socket
send
WSAStartup
select
closesocket
bind
__WSAFDIsSet
WSACleanup
inet_ntop
bcrypt.dll BCryptOpenAlgorithmProvider
BCryptGenRandom
BCryptFinishHash
BCryptCloseAlgorithmProvider
BCryptDestroyHash
BCryptHashData
BCryptCreateHash
BCryptGetProperty
IPHLPAPI.DLL FreeMibTable
GetAdaptersAddresses
GetUnicastIpAddressTable
dwmapi.dll DwmSetWindowAttribute
d3d9.dll Direct3DCreate9
KERNEL32.dll GetCommandLineA
GetOEMCP
GetACP
IsValidCodePage
FindNextFileW
FindFirstFileExW
GetEnvironmentStringsW
GetFileSizeEx
GetConsoleOutputCP
FlushFileBuffers
EnumSystemLocalesW
GetUserDefaultLCID
IsValidLocale
FreeEnvironmentStringsW
FindClose
GetProcessHeap
GetLocaleInfoW
LCMapStringW
VirtualProtect
GetLocaleInfoA
MultiByteToWideChar
LoadLibraryA
QueryPerformanceFrequency
IsDBCSLeadByte
GetProcAddress
FreeLibrary
QueryPerformanceCounter
OutputDebugStringA
GlobalAlloc
GlobalFree
GlobalLock
WideCharToMultiByte
GlobalUnlock
Sleep
GetWindowsDirectoryA
GetCommandLineW
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
HeapFree
HeapAlloc
GetFileType
ReadConsoleW
GetConsoleMode
SetFilePointerEx
WriteFile
GetStdHandle
GetModuleFileNameW
ExitProcess
GetModuleHandleExW
FreeLibraryAndExitThread
ExitThread
CreateThread
ReadFile
LoadLibraryExW
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
SetLastError
GetLastError
RaiseException
RtlPcToFileHeader
RtlUnwindEx
GetCPInfo
GetStringTypeW
LCMapStringEx
DecodePointer
EncodePointer
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
SetStdHandle
HeapReAlloc
CreateFileW
HeapSize
WriteConsoleW
SetEndOfFile
LocalFree
RtlVirtualUnwind
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
RtlCaptureContext
RtlLookupFunctionEntry
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
CloseHandle
WaitForSingleObjectEx
GetExitCodeThread
TryAcquireSRWLockExclusive
InitializeCriticalSectionEx
USER32.dll AdjustWindowRectEx
SetProcessDpiAwarenessContext
DispatchMessageA
PostMessageA
GetSystemMetrics
ShowWindow
GetWindowLongA
MessageBoxA
DefWindowProcA
CreateWindowExA
TranslateMessage
SystemParametersInfoA
PeekMessageA
PostQuitMessage
RegisterClassExA
UpdateWindow
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
DefWindowProcW
GetKeyState
GetMessageExtraInfo
LoadCursorA
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
SetCapture
SetCursor
GetClientRect
IsWindowUnicode
ReleaseCapture
SetCursorPos
GetCursorPos
GDI32.dll GetStockObject
SHELL32.dll ShellExecuteW
CommandLineToArgvW
IMM32.dll ImmSetCompositionWindow
ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow

Delayed Imports

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x2a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.30358
MD5 413761ac02dbdb7691260fe7a83656da 🔍
SHA1 22fb5c348d91d53df2d7919f2ae9fff137214557 🔍
SHA256 dc199864fc41442ffcafa5543ad065cf03c616c9ed1784d6bf1acecaf887ac43 🔍
SHA3 162b9ae9375fa6bd2a1c14bea4a0e5dd95306ab88136655b3e04d1de24ff973b 🔍

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName u8nit
FileDescription MA3 Parameters Extender
FileVersion (#2) 1.0.0.0
InternalName MA3NodeEmulation
OriginalFilename MA3NodeEmulation.exe
ProductName GMA3 Node Emulationr
ProductVersion (#2) 1.0.0.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jun-09 19:26:55
Version 0.0
SizeofData 118
AddressOfRawData 0xacafc
PointerToRawData 0xab2fc
Referenced File C:\Users\777\Desktop\folder\manet\attempt2\ParamExtender\bin\x64\Release\MA3NodeEmulation.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jun-09 19:26:55
Version 0.0
SizeofData 20
AddressOfRawData 0xacb74
PointerToRawData 0xab374

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jun-09 19:26:55
Version 0.0
SizeofData 1052
AddressOfRawData 0xacb88
PointerToRawData 0xab388

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jun-09 19:26:55
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1400acff0
EndAddressOfRawData 0x1400acff8
AddressOfIndex 0x1400ba928
AddressOfCallbacks 0x1400926c8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1400b9040

RICH Header

XOR Key 0xf6cf4e71
Unmarked objects 0
C++ objects (33145) 176
C objects (33145) 24
ASM objects (33145) 16
ASM objects (35207) 10
C objects (35207) 16
C++ objects (35207) 90
Total imports 232
Imports (33145) 21
C++ objects (LTCG) (35226) 8
Resource objects (35226) 1
151 1
Linker (35226) 1

Errors

Leave a comment

No comments yet.