| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2024-Apr-13 18:02:51 |
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to RC5 or RC6
Uses known Mersenne Twister constants |
| Malicious | VirusTotal score: 44/69 (Scanned on 2026-08-22 11:00:58) |
ALYac:
Gen:Variant.Lazy.729925
APEX: Malicious AVG: Win64:MalwareX-gen [Misc] Alibaba: Trojan:Win64/GenKryptik.c9ddc5e3 Antiy-AVL: Trojan/Win64.GenKryptik Arcabit: Trojan.Lazy.DB2345 Avast: Win64:MalwareX-gen [Misc] Avira: TR/W64.Agent BitDefender: Gen:Variant.Lazy.729925 Bkav: W32.Malware.B3C72A4B CTX: exe.trojan.genkryptik CrowdStrike: win/malicious_confidence_90% (D) Cylance: Unsafe Cynet: Malicious (score: 99) DeepInstinct: MALICIOUS ESET-NOD32: Win64/GenKryptik_AGen.ELW trojan Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Lazy.729925 (B) F-Secure: Trojan.TR/W64.Agent Fortinet: W64/GenKryptik_AGen.ELW!tr GData: Gen:Variant.Lazy.729925 Google: Detected Gridinsoft: Trojan.Win64.Kryptik.sa K7AntiVirus: Trojan ( 006e2af61 ) K7GW: Trojan ( 006e2af61 ) Lionic: Trojan.Win32.Generic.4!c MaxSecure: Trojan.Malware.693930620.susgen McAfeeD: ti!3406999E2030 MicroWorld-eScan: Gen:Variant.Lazy.729925 Microsoft: Trojan:Win32/Wacatac.B!ml Paloalto: generic.ml Rising: Trojan.Kryptik@AI.97 (RDML:goWl3GM8+/wmYjjMt2vCLw) Sangfor: Trojan.Win64.Kryptik.Viw6 Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence Tencent: Malware.Win32.Gencirc.14b36d2f Trapmine: malicious.moderate.ml.score TrellixENS: Artemis!2B55447A8684 TrendMicro: Trojan.Win32.WACATAC.USBLH826 TrendMicro-HouseCall: Trojan.Win32.WACATAC.USBLH826 VIPRE: Gen:Variant.Lazy.729925 Varist: W64/ABTrojan.LXVV-5406 Zillya: Trojan.GenKryptikAGen.Win64.24674 alibabacloud: Trojan:Win/GenKryptik_AGen.EEL |
| MD5 | 2b55447a868426627e98ecc7650c7e7c 🔍 |
|---|---|
| SHA1 | 3b6da2dce56d2f3075355b67be50921bf1ef57f3 🔍 |
| SHA256 | 3406999e2030249ea2c68e906f5f8d55dd10f361c0b07f93095fd50775465e17 🔍 |
| SHA3 | 7a3013e62bf0046d152023e69dfb7ef492a346164dc42e191067c87a30c886d8 🔍 |
| SSDeep | 393216:SFTzFbDL1fHvyIiWR+7ihUqzG8Ep0DxCzZs/UriNf2xmd5gQnLQR4i:SFtbD1H+EgMUqzGvpixCtsMritdvW4i 🔍 |
| Imports Hash | f1097440ad591dc6511b5f4213b3d28e 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x78 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x78 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 5 |
| TimeDateStamp | 2024-Apr-13 18:02:51 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x33a00 |
| SizeOfInitializedData | 0x1733e00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000003354 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x176b000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 95cf2e4c290636a9babe83b10869eed3 🔍 |
|---|---|
| SHA1 | a5775a94dc2242291a461f1a2d3124540c3ba394 🔍 |
| SHA256 | f11a2709c785f47abbafe1ff304d8a30c3ae55ec52481338e9e3c119a4b8a2d2 🔍 |
| SHA3 | 5b3f91303d033a735b85acce01b702fd5e229fb9574f7a93cef230cd43f6c77c 🔍 |
| VirtualSize | 0x339b3 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x33a00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.34621 |
| MD5 | 6f7550f159845eefffcde81e2387d9f5 🔍 |
|---|---|
| SHA1 | d2f2c26906d372e78fedee2b98e7a83f6078cbd1 🔍 |
| SHA256 | 77d9f5b8cf8116dddd02b5a0c5e2ec4e43f7dafffdb9c77081466cf533c86b74 🔍 |
| SHA3 | bbde97e56a110831c45e55384d6f09f9f5e2869c260eab9d8963c5347b8a5448 🔍 |
| VirtualSize | 0x212c |
| VirtualAddress | 0x35000 |
| SizeOfRawData | 0x2200 |
| PointerToRawData | 0x33e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.48354 |
| MD5 | 52bd6fcf620c9b451cba0654dca9ebe6 🔍 |
|---|---|
| SHA1 | aad06f7f52dc7d262a748299114affd19a5bb088 🔍 |
| SHA256 | 8f59906bca9053b19198433279c50affec657588a292bda7afda8c8ce6e00e75 🔍 |
| SHA3 | 35d16fa4edc76db84736ef9866b5bc39d567f3366041d6f31051c6f740728667 🔍 |
| VirtualSize | 0x172fb14 |
| VirtualAddress | 0x38000 |
| SizeOfRawData | 0x172fc00 |
| PointerToRawData | 0x36000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 7.71026 |
| MD5 | 7d077a2d5ca9823bd43a639de2278429 🔍 |
|---|---|
| SHA1 | 74a6222f6a12888413c0b22834464115057f0fd1 🔍 |
| SHA256 | 3c66b166159efa5cd8f9873ceafbf28b5ad5a6534a01fedb809cb93c42b363ad 🔍 |
| SHA3 | b9dd213fd3883fa8870d096edcaf75071cbb77cfee37bd575f5172b45347bd9a 🔍 |
| VirtualSize | 0x16ec |
| VirtualAddress | 0x1768000 |
| SizeOfRawData | 0x1800 |
| PointerToRawData | 0x1765c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.13652 |
| MD5 | ebb26fe226562e381a65f572f448241a 🔍 |
|---|---|
| SHA1 | 34ae53378db437de72d583a752248bfc3f26070e 🔍 |
| SHA256 | 3d37b0d57a6bbbf7ce546df6dc1d27a0c8bad900283f7624edc2173bf07abbe8 🔍 |
| SHA3 | 28c303c33caf9eaf71e0fe8d8bd520f502db3ed39010783f2460f91ae1e69421 🔍 |
| VirtualSize | 0x60c |
| VirtualAddress | 0x176a000 |
| SizeOfRawData | 0x800 |
| PointerToRawData | 0x1767400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 4.78809 |
| api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
_set_fmode __p__commode |
|---|---|
| CRYPT32.dll |
CertFindCertificateInStore
CertEnumCRLsInStore CertFindCertificateInStore CertFindCertificateInStore |
| api-ms-win-crt-heap-l1-1-0.dll |
free
_set_new_mode _callnewh malloc free |
| VCRUNTIME140.dll |
__std_exception_destroy
memmove __current_exception_context _CxxThrowException __current_exception __std_exception_copy memset memcpy __C_specific_handler memmove __std_exception_destroy |
| api-ms-win-crt-runtime-l1-1-0.dll |
_set_app_type
_initialize_narrow_environment _initterm _get_narrow_winmain_command_line _c_exit terminate exit _cexit _initialize_onexit_table _crt_atexit _invoke_watson _register_onexit_function _configure_narrow_argv _initterm_e _seh_filter_exe _register_thread_local_exe_atexit_callback _exit |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
__setusermatherr __setusermatherr |
| KERNEL32.dll |
UnhandledExceptionFilter
GetStartupInfoW GetCurrentProcess GetSystemTimeAsFileTime InitializeSListHead SetUnhandledExceptionFilter RtlCaptureContext IsDebuggerPresent GetCurrentThreadId GetCurrentProcessId RtlVirtualUnwind QueryPerformanceCounter RtlLookupFunctionEntry TerminateProcess IsProcessorFeaturePresent GetModuleHandleW |
| MSVCP140.dll |
?_Random_device@std@@YAIXZ
?_Random_device@std@@YAIXZ ?_Random_device@std@@YAIXZ |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140238a80 |
No comments yet.