| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Apr-21 17:19:38 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
disactivity.pdb
|
| CompanyName | holasoyender |
| FileDescription | Disactivity |
| FileVersion | 0.1.0 |
| LegalCopyright | Copyright © 2026 holasoyender |
| ProductName | Disactivity |
| ProductVersion | 0.1.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to RC5 or RC6 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .taubndl |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/57 (Scanned on 2026-05-10 04:29:14) | Trapmine: malicious.moderate.ml.score |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Apr-21 17:19:38 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x8f0400 |
| SizeOfInitializedData | 0x546600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000008C53EC (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xe3c000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
LoadLibraryA
GetCurrentThreadId ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW LoadLibraryW GetSystemTimeAsFileTime FlsAlloc GetModuleHandleW FlsGetValue FlsSetValue FlsFree FindNextFileW GetTempPathW SetWaitableTimer CreateWaitableTimerExW GetConsoleOutputCP WriteConsoleW MultiByteToWideChar SetEnvironmentVariableW DeleteFileW DeviceIoControl CreateSymbolicLinkW GetFinalPathNameByHandleW ReleaseMutex CreateMutexA WaitForSingleObjectEx WideCharToMultiByte SwitchToThread GetSystemInfo ExitProcess FindClose FindFirstFileExW GetCommandLineW GetCurrentDirectoryW GetCurrentThread SetThreadStackGuarantee AddVectoredExceptionHandler CreateDirectoryW GetStdHandle TerminateProcess GetExitCodeProcess CreateProcessW GetWindowsDirectoryW GetSystemDirectoryW GetEnvironmentStringsW GetFileInformationByHandleEx RtlPcToFileHeader RaiseException GetSystemTimePreciseAsFileTime CreateFileW GetCurrentProcess DuplicateHandle RtlLookupFunctionEntry RtlCaptureContext ReadFileEx GetCurrentProcessId CreateThread QueryPerformanceCounter QueryPerformanceFrequency HeapReAlloc SetFileTime SetFileInformationByHandle GetFullPathNameW SetLastError SetHandleInformation SleepEx WriteFileEx WaitForSingleObject FreeEnvironmentStringsW CompareStringOrdinal PostQueuedCompletionStatus ReadFile GetOverlappedResult WriteFile CreateIoCompletionPort CancelIoEx GetConsoleMode GetQueuedCompletionStatusEx GetFileInformationByHandle GetEnvironmentVariableW EncodePointer SetFileCompletionNotificationModes FormatMessageW LoadLibraryExA SetNamedPipeHandleState GetLastError InitializeSListHead SetUnhandledExceptionFilter DeleteCriticalSection RtlUnwindEx GetFileAttributesW Sleep GetModuleHandleA RtlVirtualUnwind GetUserDefaultUILanguage LCIDToLocaleName HeapAlloc FreeLibrary InitializeCriticalSectionEx LoadLibraryExW GetModuleFileNameW OutputDebugStringW OutputDebugStringA GetProcAddress HeapFree GetProcessHeap CloseHandle lstrlenW |
|---|---|
| advapi32.dll |
RegCreateKeyTransactedW
RegCreateKeyExW RegOpenKeyTransactedW RegOpenKeyExW RegQueryValueExW SystemFunction036 RegGetValueW EventUnregister EventWriteTransfer RegCloseKey EventSetInformation EventRegister |
| oleaut32.dll |
SysStringLen
SysFreeString SetErrorInfo GetErrorInfo |
| bcryptprimitives.dll |
ProcessPrng
|
| ntdll.dll |
NtCancelIoFileEx
NtReadFile NtCreateFile RtlNtStatusToDosError NtDeviceIoControlFile NtOpenFile RtlGetVersion NtWriteFile NtCreateNamedPipeFile |
| api-ms-win-core-synch-l1-2-0.dll |
WaitOnAddress
WakeByAddressAll WakeByAddressSingle |
| user32.dll |
GetRawInputData
AdjustWindowRect RedrawWindow RegisterClassExW CreateWindowExW SetWindowPos GetMessageA TranslateMessage DispatchMessageA EnumChildWindows IsIconic AdjustWindowRectEx IsWindow GetSystemMetrics DestroyWindow PostMessageW ClientToScreen InvalidateRgn DrawTextW RegisterTouchWindow GetWindowDC OffsetRect GetMenuBarInfo DestroyMenu TrackPopupMenu PostQuitMessage SetMenu SendInput AppendMenuW InsertMenuW DrawIconEx CheckMenuItem SetMenuItemInfoW CreateAcceleratorTableW DestroyAcceleratorTable DrawMenuBar GetMenuItemInfoW ReleaseCapture CreateMenu SetCursorPos InvalidateRect CreateIcon SystemParametersInfoA SetCapture GetMenu IsWindowVisible ClipCursor GetClipCursor ShowCursor SetWindowLongW EnableMenuItem GetSystemMenu SetForegroundWindow EnumDisplayMonitors MonitorFromPoint RemoveMenu SetWindowTextW GetWindowTextW GetWindowTextLengthW SetWindowDisplayAffinity DestroyIcon MsgWaitForMultipleObjectsEx RegisterRawInputDevices RegisterWindowMessageA GetWindow SetParent MapWindowPoints UpdateWindow GetForegroundWindow SetFocus CreatePopupMenu GetMessageW ShowWindow ReleaseDC IsProcessDPIAware DispatchMessageW GetActiveWindow GetDC GetWindowRect SetWindowLongPtrW GetParent GetWindowLongPtrW FindWindowExW SetWindowRgn IsWindowEnabled MapVirtualKeyW TrackMouseEvent GetTouchInputInfo CloseTouchInputHandle ToUnicodeEx MapVirtualKeyExW GetKeyState GetAsyncKeyState GetKeyboardState GetKeyboardLayout FlashWindowEx SetPropW SystemParametersInfoW FillRect GetMonitorInfoW MonitorFromRect MonitorFromWindow GetCursorPos GetClientRect GetWindowLongW ScreenToClient SendMessageW GetUpdateRect ValidateRect TranslateAcceleratorW SetCursor LoadCursorW GetWindowPlacement SetWindowPlacement PeekMessageW ChangeDisplaySettingsExW DefWindowProcW PostThreadMessageW EnableWindow |
| gdi32.dll |
SelectObject
CreateDIBSection CreateCompatibleDC SetBkMode CombineRgn BitBlt GetDeviceCaps CreateSolidBrush CreateRectRgn DeleteObject SetTextColor DeleteDC |
| comctl32.dll |
DefSubclassProc
RemoveWindowSubclass TaskDialogIndirect SetWindowSubclass |
| shell32.dll |
DragQueryFileW
ShellExecuteExW SHOpenFolderAndSelectItems SHGetKnownFolderPath DragFinish SHAppBarMessage ShellExecuteW ILFree ILCreateFromPathW |
| ws2_32.dll |
WSAStartup
WSACleanup getpeername getsockname getsockopt WSASend freeaddrinfo connect recv send getaddrinfo WSASocketW bind shutdown setsockopt WSAIoctl ioctlsocket closesocket WSAGetLastError |
| secur32.dll |
FreeContextBuffer
InitializeSecurityContextW AcceptSecurityContext ApplyControlToken EncryptMessage DecryptMessage QueryContextAttributesW DeleteSecurityContext AcquireCredentialsHandleA FreeCredentialsHandle |
| crypt32.dll |
CertAddCertificateContextToStore
CertOpenStore CertCloseStore CertGetCertificateChain CertVerifyCertificateChainPolicy CertEnumCertificatesInStore CertDuplicateCertificateChain CertFreeCertificateChain CertDuplicateStore CertFreeCertificateContext CertDuplicateCertificateContext |
| bcrypt.dll |
BCryptGenRandom
|
| ole32.dll |
OleInitialize
RegisterDragDrop CoCreateFreeThreadedMarshaler CoTaskMemFree CoTaskMemAlloc CoInitializeEx RevokeDragDrop CoInitialize CoUninitialize CoCreateInstance |
| dwmapi.dll |
DwmGetWindowAttribute
DwmSetWindowAttribute DwmEnableBlurBehindWindow |
| shlwapi.dll |
SHCreateMemStream
|
| api-ms-win-crt-math-l1-1-0.dll |
roundf
trunc __setusermatherr pow floor round |
| api-ms-win-crt-string-l1-1-0.dll |
strcpy_s
wcscmp _wcsicmp wcslen |
| api-ms-win-crt-convert-l1-1-0.dll |
wcstol
_ultow_s _wtoi |
| api-ms-win-crt-runtime-l1-1-0.dll |
_exit
_initialize_narrow_environment _c_exit __p___argv __p___argc _register_thread_local_exe_atexit_callback _configure_narrow_argv exit _initterm_e _seh_filter_exe _initterm abort _cexit _get_initial_narrow_environment _set_app_type _initialize_onexit_table _register_onexit_function terminate _crt_atexit |
| api-ms-win-crt-stdio-l1-1-0.dll |
_set_fmode
__p__commode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-heap-l1-1-0.dll |
_set_new_mode
free malloc _callnewh calloc |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.1.0.0 |
| ProductVersion | 0.1.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | holasoyender |
| FileDescription | Disactivity |
| FileVersion (#2) | 0.1.0 |
| LegalCopyright | Copyright © 2026 holasoyender |
| ProductName | Disactivity |
| ProductVersion (#2) | 0.1.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-21 17:19:38 |
| Version | 0.0 |
| SizeofData | 40 |
| AddressOfRawData | 0xbb7acc |
| PointerToRawData | 0xbb62cc |
| Referenced File | disactivity.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-21 17:19:38 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xbb7af4 |
| PointerToRawData | 0xbb62f4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-21 17:19:38 |
| Version | 0.0 |
| SizeofData | 1068 |
| AddressOfRawData | 0xbb7b08 |
| PointerToRawData | 0xbb6308 |
| StartAddressOfRawData | 0x140bb7f80 |
|---|---|
| EndAddressOfRawData | 0x140bb8194 |
| AddressOfIndex | 0x140dac130 |
| AddressOfCallbacks | 0x1408f2d18 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x000000014089B1E0
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140da9bc0 |
| XOR Key | 0xadff5978 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 14 |
| ASM objects (35403) | 9 |
| C objects (35403) | 13 |
| C++ objects (35403) | 46 |
| Total imports | 503 |
| C objects (35728) | 12 |
| Unmarked objects (#2) | 741 |
| Resource objects (35728) | 1 |
| Linker (35728) | 1 |
No comments yet.