| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Apr-13 02:24:07 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 3/70 (Scanned on 2026-04-25 10:37:40) |
APEX:
Malicious
Bkav: W64.AIDetectMalware CrowdStrike: win/malicious_confidence_60% (D) |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Apr-13 02:24:07 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x37c00 |
| SizeOfInitializedData | 0x1b600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000012B14 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x57000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| USER32.dll |
TranslateMessage
DispatchMessageA SendMessageA LoadCursorA EnumChildWindows FillRect AdjustWindowRect GetClientRect SetWindowTextA InvalidateRect EndPaint BeginPaint DrawTextA GetAsyncKeyState ShowWindow DestroyWindow CreateWindowExA RegisterClassA PostQuitMessage DefWindowProcA PostMessageA GetMessageA |
|---|---|
| GDI32.dll |
MoveToEx
SetTextColor SetBkMode SelectObject RoundRect LineTo DeleteObject CreateSolidBrush CreatePen CreateFontA |
| COMCTL32.dll |
InitCommonControlsEx
|
| d3d11.dll |
D3D11CreateDevice
|
| KERNEL32.dll |
GetOEMCP
GetACP IsValidCodePage FindNextFileW GetCommandLineA FindClose HeapReAlloc ReadConsoleW GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW GetProcessHeap SetStdHandle CreateFileW HeapSize SetEndOfFile WriteConsoleW FindFirstFileExW SetFilePointerEx GetFileSizeEx Sleep GetModuleFileNameA FreeLibrary GetProcAddress LoadLibraryA CloseHandle WaitForSingleObjectEx GetCurrentThreadId GetExitCodeThread WideCharToMultiByte EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection QueryPerformanceCounter ReleaseSRWLockExclusive AcquireSRWLockExclusive TryAcquireSRWLockExclusive WakeAllConditionVariable EncodePointer DecodePointer MultiByteToWideChar LCMapStringEx GetSystemTimeAsFileTime GetModuleHandleW RtlUnwind GetStringTypeW GetCPInfo RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent GetCurrentProcess TerminateProcess GetCurrentProcessId InitializeSListHead ReadFile RtlPcToFileHeader RaiseException RtlUnwindEx GetLastError SetLastError InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree LoadLibraryExW CreateThread ExitThread FreeLibraryAndExitThread GetModuleHandleExW ExitProcess GetModuleFileNameW GetStdHandle WriteFile HeapAlloc HeapFree FlsAlloc FlsGetValue FlsSetValue FlsFree VirtualProtect LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetFileType FlushFileBuffers GetConsoleOutputCP GetConsoleMode |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-13 02:24:07 |
| Version | 0.0 |
| SizeofData | 900 |
| AddressOfRawData | 0x48ad4 |
| PointerToRawData | 0x47ad4 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14004e2c0 |
| XOR Key | 0x3a63a30c |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 175 |
| C objects (33145) | 18 |
| ASM objects (33145) | 8 |
| ASM objects (35207) | 10 |
| C objects (35207) | 16 |
| C++ objects (35207) | 91 |
| Imports (33145) | 11 |
| Total imports | 169 |
| C++ objects (35225) | 3 |
| Linker (35225) | 1 |
No comments yet.