| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-May-20 16:19:29 |
| Detected languages |
English - United States
|
| TLS Callbacks | 3 callback(s) detected. |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses known Mersenne Twister constants |
| Suspicious | The PE is possibly packed. | Unusual section name found: .xdata |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/71 (Scanned on 2026-05-23 06:01:36) |
Bkav:
W32.Malware.AAA53986
Microsoft: Trojan:Win32/Wacatac.B!ml |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 11 |
| TimeDateStamp | 2026-May-20 16:19:29 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x4fd800 |
| SizeOfInitializedData | 0x10ec000 |
| SizeOfUninitializedData | 0x7200 |
| AddressOfEntryPoint | 0x0000000000001420 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x15f8000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x15f1a5a |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
RegCloseKey
RegOpenKeyExW RegQueryValueExW |
|---|---|
| GDI32.dll |
BitBlt
ChoosePixelFormat CombineRgn CreateBitmap CreateCompatibleBitmap CreateCompatibleDC CreateDCW CreateDIBSection CreateFontIndirectW CreateFontW CreatePen CreateRectRgn CreateSolidBrush DeleteDC DeleteObject DescribePixelFormat ExtTextOutW GetDIBits GetDeviceCaps GetDeviceGammaRamp GetICMProfileW GetPixelFormat GetTextExtentPoint32A GetTextExtentPoint32W GetTextMetricsW Rectangle SelectObject SetBkMode SetDeviceGammaRamp SetPixelFormat SetTextColor SwapBuffers |
| IMM32.dll |
ImmAssociateContext
ImmGetCandidateListW ImmGetCompositionStringW ImmGetContext ImmGetIMEFileNameA ImmNotifyIME ImmReleaseContext ImmSetCandidateWindow ImmSetCompositionStringW ImmSetCompositionWindow |
| KERNEL32.dll |
CancelIo
CloseHandle CompareStringA CreateDirectoryW CreateEventA CreateEventW CreateFileA CreateFileMappingA CreateFileW CreateHardLinkW CreateSemaphoreA CreateSemaphoreW CreateThread DeleteCriticalSection DeleteFileW DeviceIoControl DuplicateHandle EnterCriticalSection EnumResourceNamesW ExitProcess FileTimeToSystemTime FormatMessageA FormatMessageW FreeLibrary GetCommandLineW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetDiskFreeSpaceExW GetEnvironmentVariableA GetFileAttributesA GetFileAttributesW GetFileInformationByHandle GetFileSizeEx GetFileTime GetFullPathNameW GetLastError GetLocaleInfoA GetModuleFileNameA GetModuleFileNameW GetModuleHandleA GetModuleHandleExW GetModuleHandleW GetOverlappedResult GetProcAddress GetProcessAffinityMask GetProcessHeap GetProcessTimes GetStartupInfoA GetSystemInfo GetSystemPowerStatus GetSystemTimeAdjustment GetSystemTimeAsFileTime GetTempPathW GetThreadContext GetThreadPriority GetThreadTimes GetTickCount GlobalAlloc GlobalLock GlobalMemoryStatusEx GlobalUnlock HeapAlloc HeapFree HeapReAlloc InitializeCriticalSection InitializeCriticalSectionAndSpinCount IsDBCSLeadByte IsDebuggerPresent LeaveCriticalSection LoadLibraryA LoadLibraryExA LoadLibraryExW LoadLibraryW LocalFree MapViewOfFile MoveFileExW MulDiv OpenProcess OutputDebugStringA OutputDebugStringW QueryPerformanceCounter QueryPerformanceFrequency RaiseException ReadFile ReleaseSemaphore RemoveDirectoryW ResetEvent ResumeThread RtlCaptureContext RtlLookupFunctionEntry RtlUnwindEx RtlVirtualUnwind SetEnvironmentVariableA SetErrorMode SetEvent SetFilePointer SetFilePointerEx SetLastError SetProcessAffinityMask SetSystemTime SetThreadContext SetThreadExecutionState SetThreadPriority SetUnhandledExceptionFilter Sleep SuspendThread TerminateProcess TlsAlloc TlsFree TlsGetValue TlsSetValue TryEnterCriticalSection UnmapViewOfFile VerSetConditionMask VerifyVersionInfoW VirtualProtect VirtualQuery WaitForMultipleObjects WaitForSingleObject WaitForSingleObjectEx WideCharToMultiByte WriteFile __C_specific_handler |
| api-ms-win-crt-convert-l1-1-0.dll |
_i64toa
_ltoa _ui64toa _ultoa atof atoi mbrtowc mbsrtowcs strtol strtoll strtoul strtoull wcrtomb _itoa |
| api-ms-win-crt-environment-l1-1-0.dll |
__p__environ
_wgetcwd getenv |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_findclose
_findfirst64i32 _findnext64i32 _fullpath _lock_file _unlock_file _wchdir _wchmod _wfindfirst64i32 _wfindnext64i32 _wfullpath _wmkdir _wstat64 remove rename _stat64i32 _fstat64 |
| api-ms-win-crt-heap-l1-1-0.dll |
_set_new_mode
calloc free malloc realloc |
| api-ms-win-crt-locale-l1-1-0.dll |
___mb_cur_max_func
_configthreadlocale localeconv setlocale |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
acos acosf asin asinf atan atan2 atan2f atanf ceil ceilf cos cosf exp expf floor floorf fmod fmodf frexp llround log log10 log10f logf lround lroundf pow powf round roundf sin sinf sqrt sqrtf tan tanf trunc truncf _fdopen |
| api-ms-win-crt-private-l1-1-0.dll |
longjmp
memchr memcmp memcpy memmove strchr strrchr strstr wcsstr __intrinsic_setjmp |
| api-ms-win-crt-runtime-l1-1-0.dll |
_set_app_type
_assert __p___argc __p___argv __p__acmdln _beginthreadex _cexit _configure_narrow_argv _crt_atexit _endthreadex _errno _exit _get_errno _initialize_narrow_environment _initterm _initterm_e _set_errno _set_invalid_parameter_handler abort exit perror signal strerror system |
| api-ms-win-crt-stdio-l1-1-0.dll |
__acrt_iob_func
__p__commode __p__fmode __stdio_common_vfprintf __stdio_common_vsprintf _chsize_s _close _get_osfhandle _pclose _setmode _wfopen _wopen clearerr fclose feof ferror fflush fgetc fgets fputc fputs fread fseek ftell fwrite getc getwc putc putwc setvbuf tmpfile tmpnam ungetc ungetwc freopen fopen _write _read _popen _lseeki64 _ftelli64 _fseeki64 _fileno |
| api-ms-win-crt-string-l1-1-0.dll |
_strlwr
_strrev iswctype _wcsicmp isalnum isalpha isblank iscntrl isdigit isgraph islower isprint ispunct isspace isupper isxdigit mbrlen memset strcat strcmp strcoll strcpy strlen strncmp strncpy strnlen strpbrk strspn strxfrm tolower toupper towlower towupper wcscat wcscmp wcscoll wcscpy wcslen wcsncmp wcsnlen wcsxfrm wctype _wcsnicmp _strupr _strnicmp _stricmp _strdup |
| api-ms-win-crt-time-l1-1-0.dll |
_difftime64
_gmtime64 _localtime64 _mktime64 _time64 _wutime64 clock strftime wcsftime |
| api-ms-win-crt-utility-l1-1-0.dll |
bsearch
div qsort rand rand_s |
| ole32.dll |
CLSIDFromString
CoCreateInstance CoInitializeEx CoTaskMemFree CoUninitialize PropVariantClear |
| OLEAUT32.dll |
SysFreeString
|
| SETUPAPI.dll |
CM_Get_Device_IDA
CM_Get_Parent CM_Locate_DevNodeA SetupDiDestroyDeviceInfoList SetupDiEnumDeviceInfo SetupDiEnumDeviceInterfaces SetupDiGetClassDevsA SetupDiGetDeviceInterfaceDetailA SetupDiGetDeviceRegistryPropertyA |
| SHELL32.dll |
CommandLineToArgvW
DragAcceptFiles DragFinish DragQueryFileW SHGetFolderPathW ShellExecuteW |
| USER32.dll |
AdjustWindowRectEx
AttachThreadInput CallNextHookEx CallWindowProcW ChangeDisplaySettingsExW ClientToScreen ClipCursor CloseClipboard CopyImage CreateIconFromResource CreateIconIndirect CreateWindowExA CreateWindowExW DefWindowProcW DestroyIcon DestroyWindow DialogBoxIndirectParamW DispatchMessageW DrawTextW EmptyClipboard EndDialog EnumDisplayDevicesW EnumDisplayMonitors EnumDisplaySettingsW FillRect FlashWindowEx GetAsyncKeyState GetClassInfoExW GetClientRect GetClipCursor GetClipboardData GetClipboardSequenceNumber GetCursorPos GetDC GetDesktopWindow GetDlgItem GetDoubleClickTime GetFocus GetForegroundWindow GetKeyState GetKeyboardLayout GetKeyboardState GetMenu GetMessageExtraInfo GetMessageTime GetMessageW GetMonitorInfoW GetParent GetPropW GetRawInputData GetRawInputDeviceInfoA GetRawInputDeviceList GetSystemMetrics GetUpdateRect GetWindowLongPtrW GetWindowLongW GetWindowRect GetWindowTextLengthW GetWindowTextW GetWindowThreadProcessId IntersectRect InvalidateRect IsClipboardFormatAvailable IsIconic KillTimer LoadCursorW LoadIconW MapVirtualKeyW MessageBoxA MonitorFromPoint MonitorFromRect MonitorFromWindow MsgWaitForMultipleObjects OpenClipboard PeekMessageW PostMessageW PostThreadMessageW PtInRect RegisterClassExA RegisterClassExW RegisterClassW RegisterDeviceNotificationW RegisterRawInputDevices RegisterWindowMessageA ReleaseCapture ReleaseDC RemovePropW ScreenToClient SendMessageW SetActiveWindow SetCapture SetClipboardData SetCursor SetCursorPos SetFocus SetForegroundWindow SetLayeredWindowAttributes SetPropW SetTimer SetWindowLongPtrW SetWindowLongW SetWindowPos SetWindowRgn SetWindowTextW SetWindowsHookExW ShowWindow SystemParametersInfoA SystemParametersInfoW ToUnicode TrackMouseEvent TranslateMessage UnhookWindowsHookEx UnregisterClassA UnregisterClassW UnregisterDeviceNotification ValidateRect |
| VERSION.dll |
GetFileVersionInfoA
GetFileVersionInfoSizeA VerQueryValueA |
| WINMM.dll |
timeBeginPeriod
timeEndPeriod waveInAddBuffer waveInClose waveInGetDevCapsW waveInGetNumDevs waveInOpen waveInPrepareHeader waveInReset waveInStart waveInUnprepareHeader waveOutClose waveOutGetDevCapsW waveOutGetErrorTextW waveOutGetNumDevs waveOutOpen waveOutPrepareHeader waveOutReset waveOutUnprepareHeader waveOutWrite |
| StartAddressOfRawData | 0x1415ed000 |
|---|---|
| EndAddressOfRawData | 0x1415ed008 |
| AddressOfIndex | 0x1415e55cc |
| AddressOfCallbacks | 0x141574e40 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x00000001403772E0
0x00000001403772C0 0x000000014038CAE0 |
No comments yet.