| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2025-Mar-12 00:29:36 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\robwe\source\repos\SteepFunny\x64\Release\SteepFunny.pdb
|
| Suspicious | The PE contains functions most legitimate programs don't use. |
Functions which can be used for anti-debugging purposes:
|
| Malicious | VirusTotal score: 31/71 (Scanned on 2026-03-19 19:23:03) |
ALYac:
Trojan.GenericKD.76450102
APEX: Malicious AVG: Win64:MalwareX-gen [Misc] Arcabit: Trojan.Generic.D48E8936 Avast: Win64:MalwareX-gen [Misc] BitDefender: Trojan.GenericKD.76450102 Bkav: W64.AIDetectMalware CTX: exe.trojan.generic Cylance: Unsafe Cynet: Malicious (score: 99) DeepInstinct: MALICIOUS Emsisoft: Trojan.GenericKD.76450102 (B) Fortinet: W32/PossibleThreat GData: Trojan.GenericKD.76450102 Google: Detected Lionic: Trojan.Win32.Generic.4!c Malwarebytes: Generic.Malware/Suspicious MaxSecure: Trojan.Malware.512204294.susgen McAfeeD: ti!0F8142350164 MicroWorld-eScan: Trojan.GenericKD.76450102 Microsoft: Trojan:Win32/Wacatac.B!ml Paloalto: generic.ml Panda: Trj/Chgt.AD Sangfor: Trojan.Win32.Agent.Vbsh Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence TrellixENS: Artemis!E38036F3C988 TrendMicro-HouseCall: TROJ_GEN.R002H09BM26 Varist: W64/ABTrojan.CMSP-5623 ViRobot: Trojan.Win.Z.Agent.29696.UQ alibabacloud: Trojan:Win/Sabsik.FE |
| MD5 | e38036f3c9887053154b692a90177c8d 🔍 |
|---|---|
| SHA1 | d70bbe930c60b923cf4def4e8b214b7fff35310f 🔍 |
| SHA256 | 0f8142350164233c4a17fed70b31861f002bc6e5740a495954f75411b6fe6e32 🔍 |
| SHA3 | a83fe6840f67b26d16078e1df48d6702e63a949e258be044375237033a404beb 🔍 |
| SSDeep | 384:RIqgAAPj49NsrD6REMlWsOZ0V338FRhZsmb/CFU+305sJ:aqgAAr+NS9MvVn+Zb/wN3ss 🔍 |
| Imports Hash | 5f33bd227ae51ae68d3d76d588f1c52f 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2025-Mar-12 00:29:36 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x3200 |
| SizeOfInitializedData | 0x4400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000003300 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xd000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 35e51d10046cbebfd47d0a15f88a0c6d 🔍 |
|---|---|
| SHA1 | 82a38cf09e53fc3dfc6a06be8f6548ba43258551 🔍 |
| SHA256 | 2cbf1e0fa1afa76b1309d39bd0b45b5fcb04c14c0052b8828b4973c3f0bd7b01 🔍 |
| SHA3 | 79203a90c3bf89762bbdb75ba3c8b319adb744aeec05b7a5101c4a6712482916 🔍 |
| VirtualSize | 0x30e9 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x3200 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.0283 |
| MD5 | 7c54c76fa3946d5ecba49818eea858dc 🔍 |
|---|---|
| SHA1 | 094854d903fa757907de917357c71a85f4593aed 🔍 |
| SHA256 | 4a5a3c63a42148251c088bebef610bacec3b87c48a75a97da90df886574c2c2f 🔍 |
| SHA3 | 1a3d55b5c5c9c6078d9362149b99959ae1909a30d20110e46fa8135912a5eaa0 🔍 |
| VirtualSize | 0x311e |
| VirtualAddress | 0x5000 |
| SizeOfRawData | 0x3200 |
| PointerToRawData | 0x3600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.62475 |
| MD5 | 95c4769c60a454bb8aff5096ddc34bd0 🔍 |
|---|---|
| SHA1 | 4019c0981ccea15ac9120c11f5ce318e9ab78dd6 🔍 |
| SHA256 | f04a568669bb509ab3e8cbb14fe19d8e98946510a96bef26cc97b99a8839a767 🔍 |
| SHA3 | 1f06219db334bb729fed20756983bcb66999d5b7040ac350f13c07f0ce1fed07 🔍 |
| VirtualSize | 0x9d0 |
| VirtualAddress | 0x9000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x6800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.68657 |
| MD5 | 2d778db06c8b3f823388c9c90faa7dda 🔍 |
|---|---|
| SHA1 | a4941028f315bd7128e85790918099ceb7ed5de5 🔍 |
| SHA256 | 71dd5785f3f0b5bb686312928ef653c47a3d13dc7af2e2b7cc5fd6b65ed1283f 🔍 |
| SHA3 | 843ba782e9e74f376b73c8623549d36b89d3fbf91ef8d09fc362fc0d989a0f7a 🔍 |
| VirtualSize | 0x318 |
| VirtualAddress | 0xa000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x6c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 3.29526 |
| MD5 | ae46018e2eb1721187fc1aeee8663872 🔍 |
|---|---|
| SHA1 | bed55c6c4e207dfc859421b181d7e2e87adee5e7 🔍 |
| SHA256 | 52107afac0fedd9b1320a4a153a8f9aea34925aa43b039839dedcf44e55843f6 🔍 |
| SHA3 | 30588b77ae212fba5738bbf96aa465ab6e30cbb5c1aa0453ec285f01bb07ca46 🔍 |
| VirtualSize | 0x1e0 |
| VirtualAddress | 0xb000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x7000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.7015 |
| MD5 | 9c530cf92eb0b1a0906458e161af87db 🔍 |
|---|---|
| SHA1 | f78492eef95bf6e868ba8633f8dd4ba21f782dfe 🔍 |
| SHA256 | 4eaea74bb723a6f6049faf4af7fc5ac2b37b2c46d1a2496d8e9b4a1ecd6ad613 🔍 |
| SHA3 | 24ae045bb532970fb6ab799374d47a8353d3c9477e51aeecd6620ee01f8b7457 🔍 |
| VirtualSize | 0x90 |
| VirtualAddress | 0xc000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x7200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 1.95367 |
| KERNEL32.dll |
Process32First
WriteProcessMemory SetConsoleTitleA Module32Next Module32First OpenProcess CreateToolhelp32Snapshot Sleep GetLastError Process32Next CloseHandle ReadProcessMemory GetTickCount RtlLookupFunctionEntry GetModuleHandleW RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent RtlCaptureContext |
|---|---|
| USER32.dll |
GetAsyncKeyState
|
| MSVCP140.dll |
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@M@Z ?get@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAHXZ ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?good@ios_base@std@@QEBA_NXZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?_Xlength_error@std@@YAXPEBD@Z ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z ?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A ?uncaught_exception@std@@YA_NXZ ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ |
| XINPUT1_4.dll |
#2
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
memcpy
memmove __std_exception_destroy __std_exception_copy __std_terminate __C_specific_handler _CxxThrowException __current_exception __current_exception_context memset |
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
malloc free _set_new_mode |
| api-ms-win-crt-string-l1-1-0.dll |
_stricmp
|
| api-ms-win-crt-runtime-l1-1-0.dll |
_crt_atexit
exit _initialize_onexit_table _invalid_parameter_noinfo_noreturn _exit _register_thread_local_exe_atexit_callback _c_exit _cexit _initterm_e _initterm _get_initial_narrow_environment _initialize_narrow_environment _configure_narrow_argv __p___argv _set_app_type _seh_filter_exe __p___argc terminate _register_onexit_function |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
| api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
_set_fmode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Mar-12 00:29:36 |
| Version | 0.0 |
| SizeofData | 90 |
| AddressOfRawData | 0x6620 |
| PointerToRawData | 0x4c20 |
| Referenced File | C:\Users\robwe\source\repos\SteepFunny\x64\Release\SteepFunny.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Mar-12 00:29:36 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x667c |
| PointerToRawData | 0x4c7c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Mar-12 00:29:36 |
| Version | 0.0 |
| SizeofData | 720 |
| AddressOfRawData | 0x6690 |
| PointerToRawData | 0x4c90 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Mar-12 00:29:36 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140009000 |
| XOR Key | 0xe63d1fa0 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 12 |
| ASM objects (34321) | 3 |
| C objects (34321) | 10 |
| C++ objects (34321) | 26 |
| Imports (34321) | 6 |
| Imports (30795) | 7 |
| Total imports | 136 |
| C++ objects (LTCG) (34435) | 1 |
| Resource objects (34435) | 1 |
| Linker (34435) | 1 |
No comments yet.