| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 1970-Jan-01 00:00:00 |
| TLS Callbacks | 3 callback(s) detected. |
| Suspicious | The PE is possibly packed. | Unusual section name found: .xdata |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/68 (Scanned on 2026-07-23 04:39:12) | Bkav: W32.Malware.3BD10B76 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 10 |
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x74200 |
| SizeOfInitializedData | 0x2e400 |
| SizeOfUninitializedData | 0x1e00 |
| AddressOfEntryPoint | 0x00000000000011AD (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x3bd7b0000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xac000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xa4b19 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
CloseHandle
CreateEventA CreateSemaphoreA DeleteCriticalSection DuplicateHandle EnterCriticalSection FormatMessageA GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetHandleInformation GetLastError GetLocalTime GetModuleHandleA GetProcAddress GetProcessAffinityMask GetSystemTimeAsFileTime GetThreadContext GetThreadPriority GetTickCount GetVolumeInformationA InitializeCriticalSection IsDBCSLeadByteEx IsDebuggerPresent LeaveCriticalSection LoadLibraryW LocalFree MultiByteToWideChar OpenProcess OutputDebugStringA QueryPerformanceCounter QueryPerformanceFrequency RaiseException ReleaseSemaphore ResetEvent ResumeThread RtlCaptureContext RtlLookupFunctionEntry RtlUnwindEx RtlVirtualUnwind SetEvent SetLastError SetProcessAffinityMask SetThreadContext SetThreadPriority Sleep SuspendThread TlsAlloc TlsGetValue TlsSetValue TryEnterCriticalSection VirtualProtect VirtualQuery WaitForMultipleObjects WaitForSingleObject WideCharToMultiByte |
|---|---|
| msvcrt.dll |
___lc_codepage_func
___mb_cur_max_func __iob_func _amsg_exit _assert _beginthreadex _endthreadex _errno _initterm _lock _setjmp _unlock _vscprintf _vsnprintf _vsnwprintf abort calloc fclose fflush fgets fgetwc fopen fprintf fputc fputs free getc getenv iswctype localeconv longjmp malloc memchr memcmp memcpy memmove memset realloc setlocale strchr strcmp strcoll strcpy strerror strftime strlen strncmp strtoul strxfrm towlower towupper vfprintf wcscoll wcsftime wcslen wcsxfrm _strdup _read |
| WS2_32.dll |
WSAGetLastError
WSAStartup htons inet_pton recv sendto socket |
| Ordinal | 1 |
|---|---|
| Address | 0x1d70 |
| Ordinal | 2 |
|---|---|
| Address | 0x1d80 |
| StartAddressOfRawData | 0x3bd859000 |
|---|---|
| EndAddressOfRawData | 0x3bd859008 |
| AddressOfIndex | 0x3bd85514c |
| AddressOfCallbacks | 0x3bd838520 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x00000003BD7B75BF
0x00000003BD7B75B0 0x00000003BD7C13BA |
No comments yet.