| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jan-24 22:26:59 |
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
nfa_fix.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | PEiD Signature: | UPolyX V0.1 -> Delikon |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to RC5 or RC6 Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/67 (Scanned on 2026-03-30 07:02:32) | APEX: Malicious |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 5 |
| TimeDateStamp | 2026-Jan-24 22:26:59 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x38c600 |
| SizeOfInitializedData | 0x2d4800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000036F9A8 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x663000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
CloseHandle
LocalFree SetUnhandledExceptionFilter UnhandledExceptionFilter IsDebuggerPresent InitializeSListHead GetSystemTimeAsFileTime IsProcessorFeaturePresent |
|---|---|
| kernel32.dll |
SetLastError
WaitForSingleObject WideCharToMultiByte MultiByteToWideChar CreateEventW GetCurrentThread FormatMessageW LoadLibraryExW GetLastError FreeLibrary GetProcAddress HeapFree HeapAlloc GlobalLock GetProcessHeap LoadLibraryExA GlobalSize GetModuleHandleA Sleep LoadLibraryA CreateMutexA WaitForSingleObjectEx CreateThread WriteConsoleW GlobalUnlock GetFileAttributesW CreateProcessW GetWindowsDirectoryW GetSystemDirectoryW GetFullPathNameW WaitForMultipleObjects ReadFileEx CreateNamedPipeW ExitProcess GetModuleHandleW GetConsoleMode CancelIo ReadFile DeleteFileW FindFirstFileExW CreateDirectoryW GetFileInformationByHandleEx GetFileInformationByHandle GetOverlappedResult CreateFileW FindClose GlobalAlloc GlobalFree LoadLibraryW GetConsoleOutputCP GetCurrentThreadId ReleaseMutex lstrlenW HeapReAlloc GetSystemTimePreciseAsFileTime QueryPerformanceFrequency SetThreadErrorMode GetExitCodeProcess SleepEx FreeEnvironmentStringsW GetModuleFileNameW AddVectoredExceptionHandler SetThreadStackGuarantee SwitchToThread CreateWaitableTimerExW SetWaitableTimer QueryPerformanceCounter GetSystemInfo RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind GetCurrentDirectoryW GetEnvironmentStringsW GetEnvironmentVariableW WriteFileEx SetFileInformationByHandle GetCurrentProcess DuplicateHandle GetCurrentProcessId GetStdHandle CompareStringOrdinal |
| api-ms-win-core-synch-l1-2-0.dll |
WakeByAddressSingle
WaitOnAddress WakeByAddressAll |
| bcryptprimitives.dll |
ProcessPrng
|
| advapi32.dll |
RegCloseKey
RegQueryValueExW RevertToSelf RegSetValueExW RegOpenKeyExW ImpersonateAnonymousToken |
| crypt32.dll |
CryptProtectData
|
| oleaut32.dll |
SysFreeString
SafeArrayCreateVector SetErrorInfo GetErrorInfo SysAllocStringLen SysStringLen SafeArrayPutElement |
| ole32.dll |
CoInitializeEx
RevokeDragDrop CoUninitialize OleInitialize RegisterDragDrop CoCreateInstance |
| user32.dll |
GetWindowLongW
GetKeyboardLayout SetForegroundWindow SendInput AdjustWindowRectEx MapVirtualKeyW OpenClipboard GetClipboardData EmptyClipboard GetWindowTextW GetWindowTextLengthW EnableMenuItem GetSystemMenu SetWindowTextW MonitorFromPoint EnumDisplayMonitors CreateIcon DestroyIcon ShowCursor SetClipboardData ReleaseCapture SetCapture RegisterWindowMessageA KillTimer ReleaseDC SetTimer GetMessageW GetClipCursor ClipCursor RegisterRawInputDevices GetRawInputData GetDC GetKeyboardState GetAsyncKeyState GetKeyState CloseClipboard MapVirtualKeyExW IsIconic GetWindowRect PostMessageW ShowWindow GetMenu ScreenToClient IsProcessDPIAware SystemParametersInfoA RemovePropW SetPropW CallWindowProcW GetPropW SetWindowLongW RegisterClipboardFormatW IsClipboardFormatAvailable ToUnicodeEx FlashWindowEx SetCursorPos GetForegroundWindow ClientToScreen DestroyWindow SetWindowLongPtrW GetClassInfoExW GetClassNameW MonitorFromRect GetTouchInputInfo CloseTouchInputHandle CreateIconFromResourceEx SendMessageW GetActiveWindow GetClientRect SetWindowDisplayAffinity TrackMouseEvent GetCursorPos RegisterTouchWindow GetSystemMetrics CreateWindowExW RegisterClassExW MonitorFromWindow InvalidateRgn SetWindowPlacement GetWindowPlacement ChangeDisplaySettingsExW DispatchMessageW TranslateMessage PeekMessageW GetWindowLongPtrW ValidateRect RedrawWindow DefWindowProcW SetCursor LoadCursorW SetWindowPos GetMonitorInfoW |
| shell32.dll |
DragFinish
DragQueryFileW |
| gdi32.dll |
SetPixelFormat
ChoosePixelFormat DescribePixelFormat GetDeviceCaps DeleteObject SwapBuffers CreateRectRgn |
| opengl32.dll |
wglGetCurrentDC
wglGetCurrentContext wglDeleteContext wglGetProcAddress wglMakeCurrent wglCreateContext wglShareLists |
| dwmapi.dll |
DwmEnableBlurBehindWindow
|
| shlwapi.dll |
AssocQueryStringW
|
| uiautomationcore.dll |
UiaReturnRawElementProvider
UiaRaiseAutomationPropertyChangedEvent UiaRaiseAutomationEvent UiaHostProviderFromHwnd UiaGetReservedNotSupportedValue UiaLookupId |
| uxtheme.dll |
SetWindowTheme
|
| imm32.dll |
ImmSetCompositionWindow
ImmGetCompositionStringW ImmGetContext ImmAssociateContextEx ImmSetCandidateWindow ImmReleaseContext |
| ntdll.dll |
NtOpenFile
NtReadFile RtlNtStatusToDosError NtWriteFile |
| VCRUNTIME140.dll |
memset
__current_exception __current_exception_context memmove memcmp __C_specific_handler __CxxFrameHandler3 memcpy _CxxThrowException |
| api-ms-win-crt-string-l1-1-0.dll |
strlen
wcslen |
| api-ms-win-crt-math-l1-1-0.dll |
expf
truncf powf cos sin exp2f ceil _hypotf cosf floor round ceilf floorf atan2f acosf trunc cbrtf roundf sinf __setusermatherr |
| api-ms-win-crt-runtime-l1-1-0.dll |
__p___argc
__p___argv _cexit _exit exit _initterm_e _initterm _get_initial_narrow_environment _initialize_narrow_environment _configure_narrow_argv _c_exit _set_app_type _seh_filter_exe _register_thread_local_exe_atexit_callback terminate _initialize_onexit_table _register_onexit_function strerror _crt_atexit |
| api-ms-win-crt-stdio-l1-1-0.dll |
_set_fmode
__p__commode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-heap-l1-1-0.dll |
_set_new_mode
free |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-24 22:26:59 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0x5c86f4 |
| PointerToRawData | 0x5c70f4 |
| Referenced File | nfa_fix.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-24 22:26:59 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x5c8718 |
| PointerToRawData | 0x5c7118 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-24 22:26:59 |
| Version | 0.0 |
| SizeofData | 836 |
| AddressOfRawData | 0x5c872c |
| PointerToRawData | 0x5c712c |
| StartAddressOfRawData | 0x1405c8a90 |
|---|---|
| EndAddressOfRawData | 0x1405c8c38 |
| AddressOfIndex | 0x14063dec8 |
| AddressOfCallbacks | 0x14038ea78 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x00000001403576C0
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14063dbc0 |
| XOR Key | 0xe78f5a45 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 12 |
| Imports (34321) | 2 |
| ASM objects (34321) | 3 |
| C objects (34321) | 9 |
| C++ objects (34321) | 23 |
| Imports (29395) | 3 |
| Total imports | 377 |
| Unmarked objects (#2) | 443 |
| Linker (34809) | 1 |
No comments yet.