| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Sep-18 21:27:47 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | PEiD Signature: | PeStubOEP v1.x |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 6/70 (Scanned on 2026-09-19 19:14:17) |
CrowdStrike:
win/malicious_confidence_60% (D)
Cynet: Malicious (score: 100) Elastic: malicious (moderate confidence) McAfeeD: ti!153527D438C4 Microsoft: Trojan:Win32/Wacatac.C!ml Symantec: ML.Attribute.HighConfidence |
| MD5 | c72a44d520e85f1038698538344936bf 🔍 |
|---|---|
| SHA1 | 05049fd0168b4b3fb7f6f8ed7b927799de00d67b 🔍 |
| SHA256 | 153527d438c472b14e3123820ed5c4544a65b0ab00ce028393ab568fe052d247 🔍 |
| SHA3 | 188bd713ce65e679d5a8a40ee7567566342cae93ee166d27b52215f2d80f3b52 🔍 |
| SSDeep | 12288:Qt30349Wei/hwGJHAi2aFAaJGcpzfisJ4dhRu1IRTGe/:a0o9Ri/hVAQAabpt4KIRSe 🔍 |
| Imports Hash | 168aed4b609f72c9370255e374c12d65 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2026-Sep-18 21:27:47 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x5a000 |
| SizeOfInitializedData | 0x3dd000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00048D1F (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x5b000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x43a000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 35f25b7f2ce721d715d73c47d0982c92 🔍 |
|---|---|
| SHA1 | 409f59c29eaf323cbe538dab60daa0a1a4f7011e 🔍 |
| SHA256 | b46061cf6c8a34fc52cb866c8d0149d6625965b8586d4978071503fffa6e7c4e 🔍 |
| SHA3 | 9cb2a3264d77d72cd4a8a96227a64e67ab063c05637a25d0f82367d933e379f7 🔍 |
| VirtualSize | 0x59e3d |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x5a000 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.59683 |
| MD5 | 09bfca4c151a036e260b1675c0e8f43a 🔍 |
|---|---|
| SHA1 | 9cb462f6e5369879c930264cda737ee9464305b5 🔍 |
| SHA256 | 4ebdde8cd5487931066e22a4aafa4cf1c11bf94934439a7500cadb8f8c8bb5a2 🔍 |
| SHA3 | 1062618c4ba42cc03758d4d5eea062248a142911dfd6705cff06b1cd180b56c9 🔍 |
| VirtualSize | 0x5fc90 |
| VirtualAddress | 0x5b000 |
| SizeOfRawData | 0x5fe00 |
| PointerToRawData | 0x5a400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.57733 |
| MD5 | 6edddf557d19739bb23a8698fa36350f 🔍 |
|---|---|
| SHA1 | 504adc4344a74cf6d08518d1186f327f2b29ae90 🔍 |
| SHA256 | c180eef6a66f3ca2ee2eda59ae9ba68d177d94e8f54b75be14e868a98df1b9f0 🔍 |
| SHA3 | 33142f48959dd85bc57f8bf0155c39e0e3c17a9f95769aec8c0009afc9383ce5 🔍 |
| VirtualSize | 0x371cd8 |
| VirtualAddress | 0xbb000 |
| SizeOfRawData | 0xc00 |
| PointerToRawData | 0xba200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 2.02138 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x80 |
| VirtualAddress | 0x42d000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0xbae00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 847dafdc7ddfd21d81dd0a29cb3ba556 🔍 |
|---|---|
| SHA1 | 55da0df2deac35d204b8d32e0a1b2238c9ae2775 🔍 |
| SHA256 | 52088e61f838ce75d44bf7c1fab43bc9d2f8fd84dba49505f465664bc061ae3e 🔍 |
| SHA3 | 7abcc4fec7d3915848dfaa5a7ab107dcead8af49d6278a9c1990fe565afb2cc3 🔍 |
| VirtualSize | 0xb0d8 |
| VirtualAddress | 0x42e000 |
| SizeOfRawData | 0xb200 |
| PointerToRawData | 0xbb000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.81842 |
| KERNEL32.dll |
WriteFile
CloseHandle SetLastError AddVectoredExceptionHandler QueryPerformanceCounter QueryPerformanceFrequency InitializeCriticalSection EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionAndSpinCount TryEnterCriticalSection DeleteCriticalSection SetEvent ReleaseSemaphore ReleaseMutex WaitForSingleObject CreateEventA Sleep GetProcessTimes GetCurrentProcess GetCurrentProcessId SwitchToThread CreateThread GetCurrentThread GetCurrentThreadId OpenThread SetThreadPriority SuspendThread ResumeThread GetThreadContext FlushInstructionCache GetThreadTimes GetCurrentProcessorNumber SetThreadIdealProcessor GetSystemInfo GetFileAttributesExA GetTickCount VirtualAlloc VirtualProtect VirtualFree VirtualQuery DisableThreadLibraryCalls GetModuleFileNameA GetModuleHandleA GetModuleHandleExA GetProcAddress LocalFree lstrcpynA lstrcpyA lstrlenA CreateSemaphoreA MoveFileA IsBadReadPtr WideCharToMultiByte CreateToolhelp32Snapshot Thread32First Thread32Next Module32First Module32Next GetLastError FlsAlloc FlsSetValue FlsFree GetLargePageMinimum CreateFileW GetConsoleMode GetConsoleOutputCP WriteConsoleW GetFileAttributesA CreateFileA GetLocalTime GetEnvironmentVariableA UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW GetModuleHandleW InterlockedFlushSList RtlUnwind TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW EncodePointer RaiseException ExitProcess GetModuleHandleExW GetModuleFileNameW HeapFree HeapAlloc GetStdHandle GetFileType DecodePointer FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW MultiByteToWideChar GetEnvironmentStringsW FreeEnvironmentStringsW FlsGetValue InitializeCriticalSectionEx LCMapStringW GetProcessHeap GetStringTypeW SetFilePointerEx SetStdHandle HeapSize HeapReAlloc FlushFileBuffers |
|---|---|
| USER32.dll |
PeekMessageA
wsprintfA wvsprintfA GetAsyncKeyState MsgWaitForMultipleObjects |
| ADVAPI32.dll |
AdjustTokenPrivileges
OpenProcessToken LookupPrivilegeValueA |
| Ordinal | 1 |
|---|---|
| Address | 0x45860 |
| Ordinal | 2 |
|---|---|
| Address | 0x45870 |
| Ordinal | 3 |
|---|---|
| Address | 0x458e0 |
| Ordinal | 4 |
|---|---|
| Address | 0x459b0 |
| Ordinal | 5 |
|---|---|
| Address | 0x459f0 |
| Ordinal | 6 |
|---|---|
| Address | 0x45a70 |
| Ordinal | 7 |
|---|---|
| Address | 0x45b90 |
| Ordinal | 8 |
|---|---|
| Address | 0x45e40 |
| Ordinal | 9 |
|---|---|
| Address | 0x45ed0 |
| Ordinal | 10 |
|---|---|
| Address | 0x45ef0 |
| Ordinal | 11 |
|---|---|
| Address | 0x46060 |
| Ordinal | 12 |
|---|---|
| Address | 0x46190 |
| Ordinal | 13 |
|---|---|
| Address | 0x46370 |
| Ordinal | 14 |
|---|---|
| Address | 0x465f0 |
| Ordinal | 15 |
|---|---|
| Address | 0x46610 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Sep-18 21:27:47 |
| Version | 0.0 |
| SizeofData | 800 |
| AddressOfRawData | 0xb8ee0 |
| PointerToRawData | 0xb82e0 |
| StartAddressOfRawData | 0x100b9210 |
|---|---|
| EndAddressOfRawData | 0x100b9218 |
| AddressOfIndex | 0x1042c664 |
| AddressOfCallbacks | 0x1005b238 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x100bb140 |
| SEHandlerTable | 0x100b3fb4 |
| SEHandlerCount | 12 |
| XOR Key | 0x3a5cf012 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (33145) | 14 |
| C++ objects (33145) | 138 |
| C objects (33145) | 19 |
| ASM objects (35207) | 22 |
| C objects (35207) | 15 |
| C++ objects (35207) | 31 |
| Imports (33145) | 7 |
| Total imports | 145 |
| C++ objects (35228) | 1 |
| C objects (35228) | 1 |
| Exports (35228) | 1 |
| Linker (35228) | 1 |
No comments yet.