| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jun-09 19:26:55 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\777\Desktop\folder\manet\attempt2\ParamExtender\bin\x64\Release\MA3NodeEmulation.pdb
|
| CompanyName | u8nit |
| FileDescription | MA3 Parameters Extender |
| FileVersion | 1.0.0.0 |
| InternalName | MA3NodeEmulation |
| OriginalFilename | MA3NodeEmulation.exe |
| ProductName | GMA3 Node Emulationr |
| ProductVersion | 1.0.0.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to AES |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 4/65 (Scanned on 2026-07-22 02:31:46) |
APEX:
Malicious
Bkav: W32.Malware.2DC08C01 Elastic: malicious (high confidence) Symantec: ML.Attribute.HighConfidence |
| MD5 | 5352f1944dcc5dfde8ff4870ed2e4b84 🔍 |
|---|---|
| SHA1 | f2afaae20670e2bd499ee657265cd769ccfc97e5 🔍 |
| SHA256 | 0edab561db9e95d2255dffb08d1e700a936bc0a14bdb9059c6d375794484c649 🔍 |
| SHA3 | 3e7164a33973f83ba9e785701817555fea516cd0ce335e40ff9191c92ce16e89 🔍 |
| SSDeep | 12288:FLsRNuDgs5QL7QMfBQt0SkqJv6D7Wqvw1rTR+bYiXnl1P:FLNDTdugZJvqWqveziXnPP 🔍 |
| Imports Hash | d0a28aa4077a53ef6b548e92aefc31e3 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Jun-09 19:26:55 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x90400 |
| SizeOfInitializedData | 0x31400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000648A0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xc6000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 4b607de1a86dbea95d7d24c447f6a65c 🔍 |
|---|---|
| SHA1 | 3a3536d79aec0bb829dce7008ac9e150c21e6394 🔍 |
| SHA256 | bdd8f21ddab6a5de5f72dbb45831d9d709be348b71b21297941070a1e87e56dc 🔍 |
| SHA3 | c4822cbfca59663c89133143afcec7bd6c856745ab7c0a10049a7f7a82ad60a2 🔍 |
| VirtualSize | 0x902b0 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x90400 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.55112 |
| MD5 | 1b349a4781e8312e9f7b0253dc2a6eab 🔍 |
|---|---|
| SHA1 | 5f576c7ca6b39ab9355da85fcb1e43484bd9d822 🔍 |
| SHA256 | 9918587f28e836fceb8582e2d8f47eaf47842819f04ac635200f75e1778fa80d 🔍 |
| SHA3 | ee69743658972e21789f6c3bc05cd75536fa18868316d53032de3d2c41b79f9b 🔍 |
| VirtualSize | 0x262c8 |
| VirtualAddress | 0x92000 |
| SizeOfRawData | 0x26400 |
| PointerToRawData | 0x90800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.88821 |
| MD5 | 32d71466a4e3703d88a9ddc5326a82b4 🔍 |
|---|---|
| SHA1 | eae4b059507606d0ca4db82008e1be640cb1935a 🔍 |
| SHA256 | 217fef8f0c712961efb4ea8d5e01711f3272b9eb3f3272e8cab20b9faa34d94e 🔍 |
| SHA3 | 4f2278388ee7e079a0a1e3f42a529a6366637e03291b1f207e2f535fbc21a7c7 🔍 |
| VirtualSize | 0x2e44 |
| VirtualAddress | 0xb9000 |
| SizeOfRawData | 0x1400 |
| PointerToRawData | 0xb6c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 2.83846 |
| MD5 | 5d6f431e532c42770e7b21c4f83aaae2 🔍 |
|---|---|
| SHA1 | d29e4c8dc7d89ffd2ad6928611daf782b90318ad 🔍 |
| SHA256 | ad46d324f34eab81aed69538e5e6ed93885f88c55f60f848f41f58e14afcb283 🔍 |
| SHA3 | 387e75111e6f6f8310bc28aeccb473857e5c78c90f287127bb8d047942539614 🔍 |
| VirtualSize | 0x6a5c |
| VirtualAddress | 0xbc000 |
| SizeOfRawData | 0x6c00 |
| PointerToRawData | 0xb8000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.92676 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x100 |
| VirtualAddress | 0xc3000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0xbec00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 7d697e5483d53d0786ccfec9482eb05c 🔍 |
|---|---|
| SHA1 | a3a25f4e82fa312a0e0461864a4144495265df1e 🔍 |
| SHA256 | e62b379f99acb24e35e3dbd67750f447d6f0e0b6a6ad1f82e6f01d1122162884 🔍 |
| SHA3 | 8c6aa78c26124a48270d0b00bc4e4b16b8bd834e402b0bb4422951697cc612f0 🔍 |
| VirtualSize | 0x4c8 |
| VirtualAddress | 0xc4000 |
| SizeOfRawData | 0x600 |
| PointerToRawData | 0xbee00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 3.56332 |
| MD5 | 8597fe2ba916e5f3ae1a46675878d014 🔍 |
|---|---|
| SHA1 | fa439064e1de7134261e60820e0355cfa835e242 🔍 |
| SHA256 | 0e288dc9b6cda9965232a817c028c99151f66700af8a5572917e0b1de49287c1 🔍 |
| SHA3 | f706f8ab6ab4707ebbb64dbba99819f3e20ee0db03d1b03fc62b95b8f413d324 🔍 |
| VirtualSize | 0xb7c |
| VirtualAddress | 0xc5000 |
| SizeOfRawData | 0xc00 |
| PointerToRawData | 0xbf400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.34947 |
| WS2_32.dll |
inet_pton
WSAGetLastError setsockopt ioctlsocket htons getsockopt recv connect socket send WSAStartup select closesocket bind __WSAFDIsSet WSACleanup inet_ntop |
|---|---|
| bcrypt.dll |
BCryptOpenAlgorithmProvider
BCryptGenRandom BCryptFinishHash BCryptCloseAlgorithmProvider BCryptDestroyHash BCryptHashData BCryptCreateHash BCryptGetProperty |
| IPHLPAPI.DLL |
FreeMibTable
GetAdaptersAddresses GetUnicastIpAddressTable |
| dwmapi.dll |
DwmSetWindowAttribute
|
| d3d9.dll |
Direct3DCreate9
|
| KERNEL32.dll |
GetCommandLineA
GetOEMCP GetACP IsValidCodePage FindNextFileW FindFirstFileExW GetEnvironmentStringsW GetFileSizeEx GetConsoleOutputCP FlushFileBuffers EnumSystemLocalesW GetUserDefaultLCID IsValidLocale FreeEnvironmentStringsW FindClose GetProcessHeap GetLocaleInfoW LCMapStringW VirtualProtect GetLocaleInfoA MultiByteToWideChar LoadLibraryA QueryPerformanceFrequency IsDBCSLeadByte GetProcAddress FreeLibrary QueryPerformanceCounter OutputDebugStringA GlobalAlloc GlobalFree GlobalLock WideCharToMultiByte GlobalUnlock Sleep GetWindowsDirectoryA GetCommandLineW FlsFree FlsSetValue FlsGetValue FlsAlloc HeapFree HeapAlloc GetFileType ReadConsoleW GetConsoleMode SetFilePointerEx WriteFile GetStdHandle GetModuleFileNameW ExitProcess GetModuleHandleExW FreeLibraryAndExitThread ExitThread CreateThread ReadFile LoadLibraryExW TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount SetLastError GetLastError RaiseException RtlPcToFileHeader RtlUnwindEx GetCPInfo GetStringTypeW LCMapStringEx DecodePointer EncodePointer DeleteCriticalSection LeaveCriticalSection EnterCriticalSection SetStdHandle HeapReAlloc CreateFileW HeapSize WriteConsoleW SetEndOfFile LocalFree RtlVirtualUnwind ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW RtlCaptureContext RtlLookupFunctionEntry UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW GetModuleHandleW GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead CloseHandle WaitForSingleObjectEx GetExitCodeThread TryAcquireSRWLockExclusive InitializeCriticalSectionEx |
| USER32.dll |
AdjustWindowRectEx
SetProcessDpiAwarenessContext DispatchMessageA PostMessageA GetSystemMetrics ShowWindow GetWindowLongA MessageBoxA DefWindowProcA CreateWindowExA TranslateMessage SystemParametersInfoA PeekMessageA PostQuitMessage RegisterClassExA UpdateWindow OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData DefWindowProcW GetKeyState GetMessageExtraInfo LoadCursorA ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow SetCapture SetCursor GetClientRect IsWindowUnicode ReleaseCapture SetCursorPos GetCursorPos |
| GDI32.dll |
GetStockObject
|
| SHELL32.dll |
ShellExecuteW
CommandLineToArgvW |
| IMM32.dll |
ImmSetCompositionWindow
ImmReleaseContext ImmGetContext ImmSetCandidateWindow |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x2a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.30358 |
| MD5 | 413761ac02dbdb7691260fe7a83656da 🔍 |
| SHA1 | 22fb5c348d91d53df2d7919f2ae9fff137214557 🔍 |
| SHA256 | dc199864fc41442ffcafa5543ad065cf03c616c9ed1784d6bf1acecaf887ac43 🔍 |
| SHA3 | 162b9ae9375fa6bd2a1c14bea4a0e5dd95306ab88136655b3e04d1de24ff973b 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | u8nit |
| FileDescription | MA3 Parameters Extender |
| FileVersion (#2) | 1.0.0.0 |
| InternalName | MA3NodeEmulation |
| OriginalFilename | MA3NodeEmulation.exe |
| ProductName | GMA3 Node Emulationr |
| ProductVersion (#2) | 1.0.0.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-09 19:26:55 |
| Version | 0.0 |
| SizeofData | 118 |
| AddressOfRawData | 0xacafc |
| PointerToRawData | 0xab2fc |
| Referenced File | C:\Users\777\Desktop\folder\manet\attempt2\ParamExtender\bin\x64\Release\MA3NodeEmulation.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-09 19:26:55 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xacb74 |
| PointerToRawData | 0xab374 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-09 19:26:55 |
| Version | 0.0 |
| SizeofData | 1052 |
| AddressOfRawData | 0xacb88 |
| PointerToRawData | 0xab388 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-09 19:26:55 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1400acff0 |
|---|---|
| EndAddressOfRawData | 0x1400acff8 |
| AddressOfIndex | 0x1400ba928 |
| AddressOfCallbacks | 0x1400926c8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400b9040 |
| XOR Key | 0xf6cf4e71 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 176 |
| C objects (33145) | 24 |
| ASM objects (33145) | 16 |
| ASM objects (35207) | 10 |
| C objects (35207) | 16 |
| C++ objects (35207) | 90 |
| Total imports | 232 |
| Imports (33145) | 21 |
| C++ objects (LTCG) (35226) | 8 |
| Resource objects (35226) | 1 |
| 151 | 1 |
| Linker (35226) | 1 |
No comments yet.