| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1989-Dec-20 13:11:20 |
| Detected languages |
English - United States
|
| CompanyName | Microsoft Corporation |
| FileDescription | Windows System Utility |
| FileVersion | 10.0.26200.8460 |
| InternalName | WinDefCtl.exe |
| LegalCopyright | (c) Microsoft Corporation. All rights reserved. |
| OriginalFilename | WinDefCtl.exe |
| ProductName | Microsoft Windows Operating System |
| ProductVersion | 10.0.28000.8460 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to security software:
|
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 43/70 (Scanned on 2026-10-01 05:58:14) |
ALYac:
Trojan.GenericKD.81198833
AVG: Win64:Malware-gen AhnLab-V3: Malware/Win.Dh.R791731 Alibaba: HackTool:Win32/WarsawPM.c47ad936 Antiy-AVL: Trojan/Win32.Agent Arcabit: Trojan.Generic.D4D6FEF1 Avast: Win64:Malware-gen Avira: TR/W64.Malware BitDefender: Trojan.GenericKD.81198833 CAT-QuickHeal: HackTool.DropperCiR CTX: exe.trojan.warsawpm CrowdStrike: win/malicious_confidence_90% (W) Cynet: Malicious (score: 99) DeepInstinct: MALICIOUS DrWeb: Tool.VulnDriver.26 ESET-NOD32: Win64/KillAV.FV trojan Elastic: malicious (high confidence) Emsisoft: Trojan.GenericKD.81198833 (B) F-Secure: Trojan.TR/W64.Malware Fortinet: Riskware/Application GData: Trojan.GenericKD.81198833 Ikarus: PUA.Win64.WarsawPM Kaspersky: Trojan.Win64.Agentb.lmge Lionic: Trojan.Win32.WarsawPM.4!c Malwarebytes: GameHack.Riskware.Agent.DDS MaxSecure: Trojan.Malware.338148470.susgen McAfeeD: ti!46F65F7089E8 MicroWorld-eScan: Trojan.GenericKD.81198833 Microsoft: Trojan:Win32/Malgent!MSR Paloalto: generic.ml Rising: Trojan.KillAV!8.98 (CLOUD) Skyhigh: BehavesLike.Win64.Ransomware.fh Sophos: Mal/Generic-S Symantec: Trojan.Gen.MBT Tencent: Malware.Win32.Gencirc.14b42d09 Trapmine: suspicious.low.ml.score TrellixENS: Hacktool-WarsawPM TrendMicro: Trojan.Win32.WACATAC.USBLHQ26 TrendMicro-HouseCall: Trojan.Win32.WACATAC.USBLHQ26 VIPRE: Trojan.GenericKD.81198833 Varist: W64/ABApplication.WBLI-3466 Webroot: Win.Hacktool.Gen alibabacloud: Trojan:Win/Wacatac.B9nj |
| MD5 | 89733460266ebe94928157c96023e27c 🔍 |
|---|---|
| SHA1 | 3fc81d75655b2cdc929edb64a3593571a9efb6bb 🔍 |
| SHA256 | 46f65f7089e8bf0468a096247243d513f4667a964c239ea00334431122f1a544 🔍 |
| SHA3 | 2834245a0e66dda74e66296be76ea58f7072f2cc3669858a095587fb66f62ea0 🔍 |
| SSDeep | 6144:kfC59veo09bgmIdule2lkoDigaJQ8qrwnSJmdS7BELHgJ8jAm:b5ibV65OZ6QJrKSw87C 🔍 |
| Imports Hash | d0b6da87baef7cfed3d59417c91d2f1a 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 1989-Dec-20 13:11:20 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x32600 |
| SizeOfInitializedData | 0x26000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000000F960 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x5c000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 0eda6ef0d40717ac3dd52df812e7f31c 🔍 |
|---|---|
| SHA1 | a9998e9a573956fb3c9c62043420cd4b3fed093f 🔍 |
| SHA256 | 190b2d0ab55c718f860587fb744dabaad2495cb14bef492cdd13f470410b4dd3 🔍 |
| SHA3 | 882fadb488777e8f20d5596b5ce44732644307b19684b002fdbe8f053414fa84 🔍 |
| VirtualSize | 0x325dc |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x32600 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.46126 |
| MD5 | db82760bc7953a1026858cc9364e43c2 🔍 |
|---|---|
| SHA1 | 149e62146003d6894fd5212706c910bd06e83a31 🔍 |
| SHA256 | 7391c30d421433afcac819c59b3d48962c393edc0cdbf8d0018cee5e847fad0b 🔍 |
| SHA3 | 03e6a863b17ae369f4e0af98e909231f5a35a7a074e11f1f38da8b0c690a9347 🔍 |
| VirtualSize | 0x14f32 |
| VirtualAddress | 0x34000 |
| SizeOfRawData | 0x15000 |
| PointerToRawData | 0x32a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.07049 |
| MD5 | 5476eae5b760852b4cb1c21cf7d20b4f 🔍 |
|---|---|
| SHA1 | e1b3c25f6d6617b96a512b3fd07a6a2805b2496e 🔍 |
| SHA256 | bfb6da4aa89136a2584cd32a51469b55e6ab2e248603bee036203093239af04f 🔍 |
| SHA3 | a348cccc4894a2099d61137eba4e80ad312969ad773e7eda71aafdc9ab32d676 🔍 |
| VirtualSize | 0x2798 |
| VirtualAddress | 0x49000 |
| SizeOfRawData | 0x1400 |
| PointerToRawData | 0x47a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 2.99472 |
| MD5 | 7cefe44f064f2c0cbb4c09f0b70cf948 🔍 |
|---|---|
| SHA1 | f31cf2c5e2f2a23506545a4fe1f2ebd53c65f3c0 🔍 |
| SHA256 | e9207ebb47f64af3cb159c5402ca6fc8dc2b31117cd12d59bef772ec7537c818 🔍 |
| SHA3 | 99397853da819e51246bdefc91c3b0ec78f70eeda059fc1463530f854d23a7f2 🔍 |
| VirtualSize | 0x2c94 |
| VirtualAddress | 0x4c000 |
| SizeOfRawData | 0x2e00 |
| PointerToRawData | 0x48e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.42236 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x100 |
| VirtualAddress | 0x4f000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x4bc00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 48c2bc5df5c52d09a3f2fd6c9946a353 🔍 |
|---|---|
| SHA1 | 3492e01c7cda7c7f6b0e7a64a0e9690949096e83 🔍 |
| SHA256 | 0d8355831bc1d8099564d784a30b5976a1b5b305733c97dd6ba3e8d7c0ed1144 🔍 |
| SHA3 | bdd14fa8b3c621b70076f8c3f00ab595a141df5739c0a09290e5178e5560f9b8 🔍 |
| VirtualSize | 0xaa80 |
| VirtualAddress | 0x50000 |
| SizeOfRawData | 0xac00 |
| PointerToRawData | 0x4be00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.43086 |
| MD5 | d8181b01cee8cb7ef3533824eedd9b56 🔍 |
|---|---|
| SHA1 | 82da913800710c4b5e6139b96a3decfe625af527 🔍 |
| SHA256 | 4839d682a2374fde90e17bdb9d0c4386f18436bf52cacc5af186bc39d5af2120 🔍 |
| SHA3 | a3e7c438dad09cc019ad8f72f1e54ae7edde1fd0682ef6ec5f8989418523876c 🔍 |
| VirtualSize | 0xa10 |
| VirtualAddress | 0x5b000 |
| SizeOfRawData | 0xc00 |
| PointerToRawData | 0x56a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.0495 |
| Cabinet.dll |
#23
#22 #20 |
|---|---|
| KERNEL32.dll |
GetProcessHeap
GetModuleHandleW ReadConsoleW SetStdHandle FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA HeapFree HeapAlloc GetOEMCP GetACP IsValidCodePage ReadFile GetConsoleMode GetConsoleOutputCP FlushFileBuffers LockResource GetFileSizeEx EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW FindResourceW HeapReAlloc SizeofResource GetSystemWindowsDirectoryW Sleep GetFileAttributesW CreateFileW DeviceIoControl CloseHandle Process32FirstW DeleteFileW Process32NextW GetLastError CreateToolhelp32Snapshot GetTempPathW GetCurrentProcess GetStdHandle SetConsoleTextAttribute GetConsoleScreenBufferInfo LoadResource SetFilePointerEx HeapSize WriteConsoleW WriteFile LoadLibraryExW VirtualProtect GetFileType FormatMessageA QueryPerformanceCounter GetCurrentThreadId MultiByteToWideChar LocalFree GetLocaleInfoEx GetStringTypeW FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesExW CreateFile2 AreFileApisANSI GetProcAddress GetFileInformationByHandleEx WideCharToMultiByte EncodePointer DecodePointer EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection LCMapStringEx GetCPInfo GetCurrentProcessId GetSystemTimeAsFileTime InitializeSListHead SetUnhandledExceptionFilter GetStartupInfoW RtlLookupFunctionEntry RtlUnwindEx RtlPcToFileHeader RaiseException SetLastError FlsAlloc FlsGetValue FlsSetValue FlsFree IsProcessorFeaturePresent GetModuleFileNameW ExitProcess TerminateProcess FreeLibrary GetModuleHandleExW RtlCaptureContext RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter RtlUnwind |
| ADVAPI32.dll |
RegSaveKeyExW
RegOpenKeyExW CreateServiceW DeleteService ControlService QueryServiceConfigW LookupPrivilegeValueW AdjustTokenPrivileges QueryServiceStatus CloseServiceHandle OpenSCManagerW OpenProcessToken StartServiceW RegUnLoadKeyW RegLoadKeyW RegRestoreKeyW OpenServiceW RegCloseKey RegCreateKeyExW RegSetValueExW |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x25a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.28108 |
| MD5 | da79b877e048c160864ebefe228df91f 🔍 |
| SHA1 | f4351b675efd8def00bc836d31a664bcb606eb41 🔍 |
| SHA256 | c0358790e1e75f7bbd0bc2fe14d3535f5ca54673fdee0818534ab748d0695912 🔍 |
| SHA3 | 83de7ac12db6c5d0675a6a4c60b22b1a5eb676665ff8f85d207e169d0176467f 🔍 |
| Type |
RT_RCDATA
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x801a |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 7.18743 |
| Detected Filetype | Icon file |
| MD5 | 49e9d34e544faf596dae824e20a07510 🔍 |
| SHA1 | 1d940d7067171d847f6edcf8e6fb1c53d0c540fe 🔍 |
| SHA256 | 027cbdb822a15f7248623ca17ccde4eb21957bfff3abad043684316b1bab47b9 🔍 |
| SHA3 | a611f3bb1095e06ee7697085b50bf14bcdf214b99916be63afb56c0ef3741fa3 🔍 |
| Type |
RT_GROUP_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x14 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 1.91924 |
| Detected Filetype | Icon file |
| MD5 | 6da8e7d5ae1d5d15e0230a67a7c16c6d 🔍 |
| SHA1 | 678db52cbe5d617c33c6269bfd4b6d8d1a17f956 🔍 |
| SHA256 | 6eb54801f91b6d8effccbfaefe6b2d7705a274a75940e6226e24e0d4ec58c396 🔍 |
| SHA3 | 994fc217c7b8bc8008ac262ff58044403206de6eceafd424d4640ecad395eb2f 🔍 |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x370 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.49285 |
| MD5 | 68b465cdb39da73e477e7488e45274cc 🔍 |
| SHA1 | 53439a3319a4c2cd0612099a475c242872aef17d 🔍 |
| SHA256 | 0cb31777b1e8fc0da2faa490511abb7d708d9f2b8f2c116b0260a9ee0bf156ec 🔍 |
| SHA3 | eaafbd8bf947933f83779050f9b4a77746853f59c6df8efc29576fb11c3abd4f 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 10.0.26200.8460 |
| ProductVersion | 10.0.26200.8460 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Windows System Utility |
| FileVersion (#2) | 10.0.26200.8460 |
| InternalName | WinDefCtl.exe |
| LegalCopyright | (c) Microsoft Corporation. All rights reserved. |
| OriginalFilename | WinDefCtl.exe |
| ProductName | Microsoft Windows Operating System |
| ProductVersion (#2) | 10.0.28000.8460 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 1989-Dec-20 13:11:20 |
| Version | 0.0 |
| SizeofData | 920 |
| AddressOfRawData | 0x44178 |
| PointerToRawData | 0x42b78 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 1989-Dec-20 13:11:20 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 1989-Dec-20 13:11:20 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0x44538 |
| PointerToRawData | 0x42f38 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140049040 |
| XOR Key | 0x338f093c |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 169 |
| ASM objects (33145) | 11 |
| ASM objects (35721) | 10 |
| C objects (35721) | 16 |
| C++ objects (35721) | 84 |
| C objects (33145) | 20 |
| Imports (33145) | 19 |
| Total imports | 200 |
| C++ objects (LTCG) (36247) | 8 |
| Resource objects (36247) | 1 |
| Linker (36247) | 1 |
No comments yet.