| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Dec-18 01:48:47 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): |
Microsoft Visual C++ 8.0
MASM/TASM - sig1(h) |
| Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
| Suspicious | The PE contains functions most legitimate programs don't use. |
Functions which can be used for anti-debugging purposes:
|
| Malicious | VirusTotal score: 3/71 (Scanned on 2026-03-05 05:41:03) |
CrowdStrike:
win/malicious_confidence_70% (D)
Cynet: Malicious (score: 100) Paloalto: generic.ml |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2025-Dec-18 01:48:47 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xe600 |
| SizeOfInitializedData | 0x8600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000000E944 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1b000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| gdiplus.dll |
GdiplusStartup
GdipCreateBitmapFromHBITMAP GdipDisposeImage GdipFree GdiplusShutdown GdipCloneImage GdipAlloc GdipSaveImageToStream |
|---|---|
| CRYPT32.dll |
CryptBinaryToStringA
|
| KERNEL32.dll |
GetFileAttributesA
VirtualQuery GetModuleFileNameA GetModuleHandleA CloseHandle WaitForSingleObject Sleep CreateThread GlobalUnlock GlobalLock WideCharToMultiByte GetUserDefaultLocaleName GetModuleHandleW GetSystemInfo HeapCreate HeapDestroy HeapAlloc HeapReAlloc HeapFree GetCurrentProcess GetCurrentProcessId GetCurrentThreadId OpenThread SuspendThread ResumeThread GetThreadContext SetThreadContext FlushInstructionCache VirtualProtect CreateToolhelp32Snapshot Thread32First Thread32Next VirtualAlloc VirtualFree QueryPerformanceCounter GetSystemTimeAsFileTime GetLastError InitializeSListHead |
| USER32.dll |
GetSystemMetrics
ReleaseDC GetDC |
| GDI32.dll |
CreateCompatibleDC
BitBlt CreateDIBSection SelectObject DeleteObject DeleteDC |
| ole32.dll |
GetHGlobalFromStream
CLSIDFromString CreateStreamOnHGlobal |
| ADVAPI32.dll |
GetUserNameW
|
| MSVCP140.dll |
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?_Id_cnt@id@locale@std@@0HA ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?_Xbad_alloc@std@@YAXXZ ??0_Lockit@std@@QEAA@H@Z ??1_Lockit@std@@QEAA@XZ ?uncaught_exceptions@std@@YAHXZ ?_Xlength_error@std@@YAXPEBD@Z ?_Xout_of_range@std@@YAXPEBD@Z ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?always_noconv@codecvt_base@std@@QEBA_NXZ ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ??Bios_base@std@@QEBA_NXZ ?good@ios_base@std@@QEBA_NXZ ?flags@ios_base@std@@QEBAHXZ ?width@ios_base@std@@QEBA_JXZ ?width@ios_base@std@@QEAA_J_J@Z ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Gnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ ?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Pnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ |
| WININET.dll |
InternetConnectW
InternetOpenW InternetCrackUrlW HttpOpenRequestW HttpSendRequestW InternetCloseHandle |
| VCRUNTIME140.dll |
memmove
memcmp __C_specific_handler __std_type_info_destroy_list memset _CxxThrowException __std_exception_destroy __std_terminate __std_exception_copy memcpy |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
_callnewh free |
| api-ms-win-crt-string-l1-1-0.dll |
strnlen
wcslen strlen toupper isspace |
| api-ms-win-crt-stdio-l1-1-0.dll |
ungetc
fwrite _fseeki64 fsetpos fread fputc fgetpos fflush fclose _get_stream_buffer_pointers setvbuf fgetc |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_lock_file
_unlock_file |
| api-ms-win-crt-utility-l1-1-0.dll |
rand
srand |
| api-ms-win-crt-time-l1-1-0.dll |
_time64
|
| api-ms-win-crt-runtime-l1-1-0.dll |
_crt_atexit
_cexit _invoke_watson _execute_onexit_table _seh_filter_dll _configure_narrow_argv _initialize_narrow_environment _initialize_onexit_table _register_onexit_function _initterm_e _initterm |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-18 01:48:47 |
| Version | 0.0 |
| SizeofData | 740 |
| AddressOfRawData | 0x13560 |
| PointerToRawData | 0x11f60 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x180017240 |
| XOR Key | 0x3e29233b |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 14 |
| ASM objects (35403) | 3 |
| C objects (35403) | 8 |
| C++ objects (35403) | 20 |
| Imports (35403) | 8 |
| Imports (33145) | 17 |
| Total imports | 193 |
| C objects (35214) | 4 |
| C++ objects (35217) | 8 |
| C++ objects (35720) | 3 |
| Resource objects (35720) | 1 |
| Linker (35720) | 1 |
No comments yet.