| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jul-20 13:55:25 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 16/69 (Scanned on 2026-07-22 04:29:05) |
APEX:
Malicious
CTX: exe.trojan.generic CrowdStrike: win/malicious_confidence_70% (W) Cylance: Unsafe ESET-NOD32: Win32/GameHack_AGen.APZ potentially unsafe application Elastic: malicious (high confidence) Google: Detected Malwarebytes: Malware.AI.4027825286 McAfeeD: Real Protect-LS!71F48003C053 Microsoft: Trojan:Win32/Kepavll!rfn Paloalto: generic.ml Sophos: Generic Reputation PUA (PUA) Symantec: ML.Attribute.HighConfidence Trapmine: malicious.high.ml.score TrendMicro-HouseCall: Trojan.Win32.VSX.PE04CA5 Varist: W32/ABApplication.VRXR-7202 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x120 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2026-Jul-20 13:55:25 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x90200 |
| SizeOfInitializedData | 0x39000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0008EFFA (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x92000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xcd000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
CryptReleaseContext
OpenServiceA QueryServiceStatusEx CryptGetHashParam RegOpenKeyExA CryptDestroyHash CryptHashData CryptCreateHash OpenSCManagerA RegQueryValueExA CloseServiceHandle RegCloseKey CryptAcquireContextA CryptEncrypt CryptImportKey CryptDestroyKey CryptGenRandom |
|---|---|
| WS2_32.dll |
getsockname
WSASetLastError getsockopt closesocket __WSAFDIsSet htons ntohs setsockopt WSAIoctl bind freeaddrinfo send accept listen recvfrom sendto ioctlsocket gethostname htonl ntohl select recv getaddrinfo socket connect getpeername WSAGetLastError WSACleanup WSAStartup |
| CRYPT32.dll |
CertFreeCertificateContext
|
| WLDAP32.dll |
#50
#60 #211 #46 #143 #301 #200 #30 #79 #35 #41 #33 #32 #27 #26 #22 |
| Normaliz.dll |
IdnToAscii
|
| d3d9.dll |
Direct3DCreate9
|
| KERNEL32.dll |
IsProcessorFeaturePresent
SetUnhandledExceptionFilter UnhandledExceptionFilter ExpandEnvironmentStringsA IsDebuggerPresent AcquireSRWLockExclusive ReadFile GetStartupInfoW GetModuleHandleW GetFileType GetStdHandle WaitForSingleObjectEx FormatMessageA VerifyVersionInfoA GetSystemDirectoryA SleepEx DeleteCriticalSection ReleaseSRWLockExclusive WakeAllConditionVariable PeekNamedPipe SleepConditionVariableSRW InitializeCriticalSectionEx LeaveCriticalSection EnterCriticalSection SetLastError GetLastError GetTickCount64 QueryPerformanceCounter FreeLibrary VerSetConditionMask IsDBCSLeadByte QueryPerformanceFrequency GetCurrentProcessId GetCurrentThreadId InitializeSListHead LoadLibraryA WaitForMultipleObjects OutputDebugStringA GetLocaleInfoA GlobalUnlock WideCharToMultiByte GlobalLock GlobalFree GetSystemFirmwareTable GetModuleFileNameA Process32First GetFileAttributesExA WriteProcessMemory GetCurrentProcess TerminateProcess GetEnvironmentVariableA WaitForSingleObject GetModuleHandleA OpenProcess CreateToolhelp32Snapshot MultiByteToWideChar GetExitCodeThread Sleep GetTempPathA DeleteFileA Process32Next CloseHandle GetProcAddress VirtualAllocEx CreateRemoteThread CreateProcessA GetSystemTimeAsFileTime CreateDirectoryA VirtualFreeEx GetTickCount GlobalAlloc |
| USER32.dll |
GetKeyState
GetMessageExtraInfo TrackMouseEvent ClientToScreen GetCapture GetKeyboardLayout GetForegroundWindow SetCursor SetProcessDPIAware GetDC IsWindowUnicode LoadCursorA ReleaseCapture SetCapture UpdateWindow PostQuitMessage PeekMessageA GetClientRect LoadIconA TranslateMessage SetLayeredWindowAttributes MessageBoxA ShowWindow GetActiveWindow RegisterClassExW UnregisterClassW GetSystemMetrics ScreenToClient CreateWindowExW PostMessageA SetWindowPos DestroyWindow GetWindowRect DispatchMessageA MonitorFromPoint DefWindowProcW SetClipboardData GetClipboardData EmptyClipboard CloseClipboard OpenClipboard GetCursorPos ReleaseDC SetCursorPos |
| GDI32.dll |
GetDeviceCaps
|
| SHELL32.dll |
ShellExecuteW
|
| MSVCP140.dll |
_Mtx_unlock
_Thrd_join _Thrd_detach _Thrd_id _Cnd_do_broadcast_at_thread_exit _Mtx_lock ?_Xlength_error@std@@YAXPBD@Z ?_Xout_of_range@std@@YAXPBD@Z ?_Throw_Cpp_error@std@@YAXH@Z |
| IMM32.dll |
ImmSetCompositionWindow
ImmReleaseContext ImmGetContext ImmSetCandidateWindow |
| VCRUNTIME140.dll |
_except_handler4_common
__current_exception_context __current_exception _CxxThrowException memchr strstr memmove memcpy memset strrchr __std_terminate _set_se_translator __std_exception_copy strchr __std_exception_destroy __CxxFrameHandler3 |
| api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vfprintf
fwrite ferror feof __stdio_common_vsprintf __stdio_common_vfscanf _lseeki64 fputc fread __acrt_iob_func fflush _set_fmode _wfopen __stdio_common_vsscanf fclose fgets __p__commode fopen fputs ftell _read _write _close _open fseek |
| api-ms-win-crt-runtime-l1-1-0.dll |
_controlfp_s
_invoke_watson _register_thread_local_exe_atexit_callback _c_exit _exit exit _initterm_e _initterm strerror __sys_nerr _getpid _get_narrow_winmain_command_line _beginthreadex _set_app_type _seh_filter_exe _cexit _errno terminate system _crt_atexit _configure_narrow_argv _initialize_narrow_environment _initialize_onexit_table _register_onexit_function |
| api-ms-win-crt-string-l1-1-0.dll |
tolower
_strdup wcscat_s isgraph _stricmp isprint islower isupper isalnum strncpy isspace isdigit strpbrk isxdigit isalpha strncmp |
| api-ms-win-crt-convert-l1-1-0.dll |
atol
strtoll strtoul strtol atoi |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-heap-l1-1-0.dll |
realloc
_callnewh free calloc _set_new_mode malloc |
| api-ms-win-crt-time-l1-1-0.dll |
_gmtime64
_time64 |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_stat64
_fstat64 |
| api-ms-win-crt-environment-l1-1-0.dll |
getenv
|
| api-ms-win-crt-math-l1-1-0.dll |
ceil
_libm_sse2_cos_precise _libm_sse2_sin_precise _CIfmod __setusermatherr _libm_sse2_sqrt_precise _libm_sse2_acos_precise |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-20 13:55:25 |
| Version | 0.0 |
| SizeofData | 864 |
| AddressOfRawData | 0xb8a68 |
| PointerToRawData | 0xb7068 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-20 13:55:25 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x4b8dd8 |
|---|---|
| EndAddressOfRawData | 0x4b8de0 |
| AddressOfIndex | 0x4bc6c8 |
| AddressOfCallbacks | 0x492564 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x4bc080 |
| SEHandlerTable | 0x4b8944 |
| SEHandlerCount | 44 |
| XOR Key | 0x1fbcdbb1 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 22 |
| 253 (35207) | 5 |
| ASM objects (35207) | 9 |
| C objects (35207) | 12 |
| C++ objects (35207) | 30 |
| Imports (35207) | 4 |
| Imports (33145) | 14 |
| Total imports | 315 |
| Imports (VS2015 v14.0.? compiler 24610) | 11 |
| C objects (VS2017 v15.2 compiler 25019) | 93 |
| C++ objects (LTCG) (35228) | 7 |
| Resource objects (35228) | 1 |
| 151 | 1 |
| Linker (35228) | 1 |
No comments yet.