1852cbfd8c678e2038de2019a31803b550aacc3bc97ae98f9989dc3c36eae33b

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jun-21 00:41:02
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Accesses the WMI:
  • ROOT\CIMV2
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • example.com
  • github.com
  • https://curl.se
  • https://github.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Uses constants related to Blowfish
Uses known Diffie-Helman primes
Uses known Mersenne Twister constants
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • CheckRemoteDebuggerPresent
  • SwitchToThread
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegOpenKeyExA
  • RegQueryValueExA
  • RegGetValueA
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
  • CreateProcessAsUserA
Uses Microsoft's cryptographic API:
  • CryptDestroyHash
  • CryptAcquireContextW
  • CryptReleaseContext
  • CryptGetHashParam
  • CryptCreateHash
  • CryptHashData
  • CryptEnumProvidersW
  • CryptSignHashW
  • CryptDecrypt
  • CryptExportKey
  • CryptGetUserKey
  • CryptGetProvParam
  • CryptSetHashParam
  • CryptDestroyKey
  • CryptGenRandom
  • CryptQueryObject
  • CryptDecodeObjectEx
  • CryptStringToBinaryW
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Functions related to the privilege level:
  • DuplicateTokenEx
  • OpenProcessToken
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • Process32Next
  • OpenProcess
  • Process32First
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertOpenSystemStoreW
  • CertOpenSystemStoreA
  • CertAddCertificateContextToStore
  • CertOpenStore
Malicious VirusTotal score: 10/67 (Scanned on 2026-08-27 06:22:45) APEX: Malicious
Bkav: W32.Malware.7145E189
CrowdStrike: win/malicious_confidence_60% (D)
Elastic: malicious (high confidence)
Google: Detected
McAfeeD: ti!1852CBFD8C67
Microsoft: Trojan:Win32/Wacatac.B!ml
Symantec: ML.Attribute.HighConfidence
TrendMicro-HouseCall: Trojan.Win64.Gen.TL0101G826YT
Varist: W64/ABTrojan.HPBE-7740

Hashes

MD5 86934c9fc2321969876ff490c8487bac 🔍
SHA1 a4925728661a4a4416c3314436c4d6d743290952 🔍
SHA256 1852cbfd8c678e2038de2019a31803b550aacc3bc97ae98f9989dc3c36eae33b 🔍
SHA3 6205300641b19dcdd474d2e04519e8b9106798abdb28b29583a572815418751e 🔍
SSDeep 98304:DzYxKQgHpCU356dtfhojLOed53Q54L5Y7b5fiNMY+zhT:DzY0RpCU356dtfhdO5g54L5Y35ud0 🔍
Imports Hash d63cb3aaad07f79a3d6f7c9cc8687bb1 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Jun-21 00:41:02
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x4fe400
SizeOfInitializedData 0x224a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000004BEB00 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x728000
SizeOfHeaders 0x400
Checksum 0x7247d2
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 0df860053e61eaa0c7f46a2fb03bf4fc 🔍
SHA1 fbd4c4757cb1250fb8eea0e6a76df9a53af79087 🔍
SHA256 da913da522715b4bfaaaf7b00be09e1f1f060d35e76811ecff42efa80e0fa2bf 🔍
SHA3 4998b7e79e0290588dd230bb67dea2282ca00dbf6e8418ef4db03bc1fe9d67d8 🔍
VirtualSize 0x4fe268
VirtualAddress 0x1000
SizeOfRawData 0x4fe400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.69065

.rdata

MD5 44bfe0e4ea3b536307d2b51e78bfeb67 🔍
SHA1 a594f6c377aae2592a67e0a3784be8e1a8b8c2c4 🔍
SHA256 e141459929765e91c44392e28940ca39d4441b0622e52c0a29575d1f276be17c 🔍
SHA3 daf09ff57242ecfadb256cfda8511beaa15fe1d8f4e9a4cbe5d472c1710b9073 🔍
VirtualSize 0x1a6fde
VirtualAddress 0x500000
SizeOfRawData 0x1a7000
PointerToRawData 0x4fe800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.95428

.data

MD5 4bcfebf6bf39ecf108515d04319ee73c 🔍
SHA1 8c9a723abcb3cddbf2dfc588cbea99a7429565da 🔍
SHA256 c2ae73fc25b019af2622f411cfb8f058e5b0b2a5f41da85d0d3722dfd76f387b 🔍
SHA3 65b821dfa2f62e7d7e1fc886e2fd4afd10675afb14333a7956a0b3fb1ac6cd38 🔍
VirtualSize 0x337b4
VirtualAddress 0x6a7000
SizeOfRawData 0x29400
PointerToRawData 0x6a5800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.44104

.pdata

MD5 9365f3ab402e55b6ecd6cf01789a09c4 🔍
SHA1 293b5be58802f8e63bde50b54df79b76ca9ec00e 🔍
SHA256 f965be1bd1594261ca869f6b7bb778ad8ff9f21d3c1d4763e2dabb6151245909 🔍
SHA3 a3c421b4219e954fab53676f16ffaa9223f6c8b20980de2179fb4e70372de15e 🔍
VirtualSize 0x387c0
VirtualAddress 0x6db000
SizeOfRawData 0x38800
PointerToRawData 0x6cec00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.41296

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x714000
SizeOfRawData 0x200
PointerToRawData 0x707400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 95863f199bfa51c00a03cfb5515507c4 🔍
SHA1 8f3830bf989b0680b9e9d79463a45d4fc3741128 🔍
SHA256 1ad195c2cd371a665654321684a7ebfe46d6ead793c914e9840fab06db0da074 🔍
SHA3 afb37661e25411da10e95854f93d61a1709ffbc055a41cd596dd661b86ae8a8a 🔍
VirtualSize 0x1e8
VirtualAddress 0x715000
SizeOfRawData 0x200
PointerToRawData 0x707600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.75961

.reloc

MD5 4241071616c4d6d696cb54c42c0b6c70 🔍
SHA1 4ccae6a30016ecd823681ffc2b2ca3af0c319fb2 🔍
SHA256 2d5a34f56e03af12d22c61e1940b83379ccd55462ba313034c8136b24f4a757f 🔍
SHA3 a5307434b6b6b2e1ea27255236691d4531e4de04d1685ffdf0d8688d3e153c41 🔍
VirtualSize 0x11464
VirtualAddress 0x716000
SizeOfRawData 0x11600
PointerToRawData 0x707800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.45304

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
USER32.dll SetCursor
SetCapture
GetForegroundWindow
GetKeyboardLayout
TrackMouseEvent
ClientToScreen
GetClientRect
ScreenToClient
LoadCursorA
GetMessageExtraInfo
GetKeyState
UpdateWindow
GetCapture
PostQuitMessage
PeekMessageA
TranslateMessage
DefWindowProcA
GetAsyncKeyState
ShowWindow
RegisterClassExW
UnregisterClassW
GetSystemMetrics
CreateWindowExW
DestroyWindow
DispatchMessageA
ReleaseCapture
SetCursorPos
GetCursorPos
OpenClipboard
MessageBoxW
GetUserObjectInformationW
GetProcessWindowStation
CloseClipboard
SetClipboardData
EmptyClipboard
GetClipboardData
MessageBoxA
IsWindowUnicode
KERNEL32.dll TerminateProcess
SetFileTime
RtlAddFunctionTable
InitializeCriticalSectionEx
WaitForSingleObject
FreeLibraryAndExitThread
GetCurrentThreadId
ExitThread
RtlCaptureStackBackTrace
GetExitCodeThread
GetTickCount64
CreateFileA
CreateThread
HeapAlloc
GetLocalTime
DecodePointer
AddVectoredExceptionHandler
DeleteCriticalSection
SetEnvironmentVariableA
GetProcessHeap
SystemTimeToFileTime
GlobalMemoryStatusEx
GetModuleHandleW
FlushInstructionCache
RtlDeleteFunctionTable
CreateDirectoryA
IsDebuggerPresent
CheckRemoteDebuggerPresent
SetUnhandledExceptionFilter
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
Sleep
GetSystemInfo
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
FormatMessageA
SleepEx
WaitForSingleObjectEx
CreateFileW
GetFullPathNameW
MoveFileExW
GetEnvironmentVariableA
CompareFileTime
GetSystemTimeAsFileTime
GetStdHandle
GetFileType
ReadFile
PeekNamedPipe
WaitForMultipleObjects
VerifyVersionInfoW
GetFileSizeEx
LocalFree
GetCurrentProcessId
GetEnvironmentVariableW
GetConsoleMode
SetConsoleMode
ReadConsoleA
ReadConsoleW
InitializeSRWLock
ReleaseSRWLockShared
AcquireSRWLockShared
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
SwitchToFiber
DeleteFiber
GetLocaleInfoA
GetSystemTime
FindClose
FindFirstFileW
FindNextFileW
GetModuleHandleExW
GetSystemDirectoryA
VirtualAlloc
CreateSemaphoreA
GetACP
WriteFile
RtlVirtualUnwind
ConvertFiberToThread
ConvertThreadToFiberEx
LoadLibraryW
GetCurrentThreadStackLimits
GetCurrentThread
GetNativeSystemInfo
QueryPerformanceCounter
CreateSemaphoreExA
SetEvent
CreateEventExA
SwitchToThread
lstrcmpA
CreateEventExW
ResumeThread
IsThreadAFiber
CreateFiber
RtlUnwindEx
LoadLibraryA
FreeLibrary
VerSetConditionMask
DeviceIoControl
GetModuleHandleA
GlobalUnlock
WideCharToMultiByte
GlobalLock
GlobalFree
GlobalAlloc
MultiByteToWideChar
GetStartupInfoA
CloseHandle
Process32Next
GetLastError
CreateToolhelp32Snapshot
GetCommandLineA
OpenProcess
GetCurrentProcess
Process32First
ExitProcess
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
RtlUnwind
IsProcessorFeaturePresent
GetDriveTypeW
SystemTimeToTzSpecificLocalTime
FileTimeToSystemTime
GetConsoleOutputCP
SetFilePointerEx
SetConsoleCtrlHandler
GetModuleFileNameW
RtlCaptureContext
UnhandledExceptionFilter
LoadLibraryExW
GetDateFormatW
GetTimeFormatW
RtlLookupFunctionEntry
OutputDebugStringW
GetStartupInfoW
InitializeSListHead
GetCPInfo
GetStringTypeW
LCMapStringEx
EncodePointer
InitOnceComplete
InitOnceBeginInitialize
OutputDebugStringA
VirtualFree
SetLastError
HeapFree
VirtualProtect
GetProcAddress
QueryPerformanceFrequency
WakeAllConditionVariable
SleepConditionVariableSRW
GetModuleFileNameA
ReleaseSemaphore
K32EnumDeviceDrivers
GetSystemTimePreciseAsFileTime
GetFileInformationByHandleEx
AreFileApisANSI
CreateFile2
GetFileInformationByHandle
GetFileAttributesExW
FindFirstFileExW
CreateDirectoryW
GetCurrentDirectoryW
GetLocaleInfoEx
GetLogicalProcessorInformationEx
RaiseException
RtlPcToFileHeader
GetProcessAffinityMask
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
FlushFileBuffers
GetExitCodeProcess
CreateProcessW
HeapReAlloc
DeleteFileW
SetStdHandle
SetEndOfFile
HeapSize
HeapQueryInformation
IsValidCodePage
GetOEMCP
GetTimeZoneInformation
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
WriteConsoleW
CreateFiberEx
ADVAPI32.dll CryptDestroyHash
DuplicateTokenEx
SetThreadToken
OpenProcessToken
LookupPrivilegeValueA
SetTokenInformation
PrivilegeCheck
CreateProcessAsUserA
RevertToSelf
RegOpenKeyExA
CredReadA
CredDeleteA
CredWriteA
CredFree
RegQueryValueExA
RegGetValueA
RegCloseKey
SystemFunction036
CryptAcquireContextW
CryptReleaseContext
CryptGetHashParam
CryptCreateHash
CryptHashData
DeregisterEventSource
RegisterEventSourceW
CryptEnumProvidersW
CryptSignHashW
CryptDecrypt
CryptExportKey
CryptGetUserKey
CryptGetProvParam
CryptSetHashParam
CryptDestroyKey
CryptGenRandom
ReportEventW
GetTokenInformation
ole32.dll CoUninitialize
CoInitializeSecurity
CoInitializeEx
CoSetProxyBlanket
CoCreateInstance
OLEAUT32.dll VariantInit
VariantClear
SysAllocString
SysFreeString
IMM32.dll ImmSetCompositionWindow
ImmGetContext
ImmReleaseContext
ImmSetCandidateWindow
D3DCOMPILER_47.dll D3DCompile
IPHLPAPI.DLL GetAdaptersAddresses
if_nametoindex
dxgi.dll CreateDXGIFactory
bcrypt.dll BCryptGenRandom
WS2_32.dll inet_ntoa
inet_addr
ioctlsocket
gethostbyname
getservbyport
getservbyname
WSASocketA
getsockopt
send
WSACloseEvent
WSACreateEvent
WSAEnumNetworkEvents
shutdown
gethostbyaddr
WSAEventSelect
WSAResetEvent
WSAWaitForMultipleEvents
WSAGetLastError
closesocket
htons
socket
ntohs
WSAStartup
WSACleanup
accept
bind
connect
getpeername
getsockname
recv
setsockopt
WSASetLastError
WSAIoctl
__WSAFDIsSet
select
htonl
listen
getaddrinfo
freeaddrinfo
recvfrom
sendto
gethostname
CRYPT32.dll CertGetCertificateContextProperty
CertDuplicateCertificateContext
CertFreeCertificateChain
CertGetCertificateChain
CertFreeCertificateChainEngine
CertCreateCertificateChainEngine
CryptQueryObject
CertGetNameStringW
CertFindExtension
CertFreeCTLContext
CertOpenSystemStoreW
CertFreeCRLContext
CryptDecodeObjectEx
CertOpenSystemStoreA
CertGetIntendedKeyUsage
CertGetEnhancedKeyUsage
PFXImportCertStore
CryptStringToBinaryW
CertFreeCertificateContext
CertFindCertificateInStore
CertEnumCertificatesInStore
CertCloseStore
CertAddCertificateContextToStore
CertOpenStore
Secur32.dll InitSecurityInterfaceW

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b 🔍
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jun-21 00:41:02
Version 0.0
SizeofData 1148
AddressOfRawData 0x66add0
PointerToRawData 0x6695d0

TLS Callbacks

StartAddressOfRawData 0x14066b2a0
EndAddressOfRawData 0x14066b3e0
AddressOfIndex 0x1406d4ba0
AddressOfCallbacks 0x140500ce8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks 0x00000001404BF830
0x00000001404BF700

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1406cd640

RICH Header

XOR Key 0x67302731
Unmarked objects 0
ASM objects (33145) 17
C objects (33145) 26
C objects (35721) 19
ASM objects (35721) 12
C++ objects (35721) 108
C++ objects (35728) 25
Unmarked objects (#2) 42
C objects (35728) 1140
C++ objects (33145) 209
Imports (33145) 33
Total imports 393
C++ objects (LTCG) (36248) 10
Resource objects (36248) 1
Linker (36248) 1

Errors

Leave a comment

No comments yet.