| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Aug-28 16:59:32 |
| Detected languages |
English - United States
|
| Debug artifacts |
quark.pdb
|
| ProductVersion | 0.1.1 |
| ProductName | Quark |
| FileVersion | 0.1.1 |
| FileDescription | Quark - operator console |
| CompanyName | Quark |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to security software:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to RC5 or RC6 Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/67 (Scanned on 2026-08-29 04:39:06) |
APEX:
Malicious
MaxSecure: Trojan.Malware.300983.susgen |
| MD5 | fc16f2c8345e44d2fc7861affccc61e1 🔍 |
|---|---|
| SHA1 | 523ad47421872b81ff40fc0ec2212d6bc6ebe944 🔍 |
| SHA256 | 4f15471a1966dd5144bbfd3ee5d7f07cea2f5778f1f4a3372a7045c619aba966 🔍 |
| SHA3 | 6938c21f3a79bcc54689268113f420426662075ef24d20fbb1fb3539fd0ec929 🔍 |
| SSDeep | 49152:RFUADFnjsSe/eb93pNpXuO6ZTvHQqkgbL/g92c8IOoO6+OOi7b9bbKJelrm0g51:RiG7DMTvN8aCbQ 🔍 |
| Imports Hash | 8703ced74ee90cb683ea66cfa99e0fab 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Aug-28 16:59:32 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x25ac00 |
| SizeOfInitializedData | 0x2c7a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000251770 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x526000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | f471fef6c8e159ce3854009ba40c69fc 🔍 |
|---|---|
| SHA1 | 58faf87b0c21a780a4897837a94a31efbf18b6a1 🔍 |
| SHA256 | a9389225d05f69dc5891b735a2fb6d2af04b0604bcd573c9283bb6ed7a7937f3 🔍 |
| SHA3 | 2befbb1e1996f7d17893552ed0f4292c7949ccd7c176644ae5e9f1b5d1138d02 🔍 |
| VirtualSize | 0x25aa38 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x25ac00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.47277 |
| MD5 | e9d5ed0c782e27c181f5c75310e341ab 🔍 |
|---|---|
| SHA1 | 47b42ab50707e37778c9aa988d1dfa070151130d 🔍 |
| SHA256 | 08ef5a4621c3bedeafc4df73f3727401a5d52c23ff614cb6fc12d2eeb5259231 🔍 |
| SHA3 | f12332621e6cc79aa499ada81b6d964ff6dbf8ee2d9c04f0bcbbbdbc6a8c07cd 🔍 |
| VirtualSize | 0x29d9ca |
| VirtualAddress | 0x25c000 |
| SizeOfRawData | 0x29da00 |
| PointerToRawData | 0x25b000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.53601 |
| MD5 | 63637c26a4680c344b887bca9a48fd33 🔍 |
|---|---|
| SHA1 | d3408276c1a20632f3339fd20b1bc250a61a42c4 🔍 |
| SHA256 | 01361f38b1d69b30447ab6e5257bec2503b6fd0934576fb89881da7a3fe78222 🔍 |
| SHA3 | 75e840b611e1d417a797c44eb3b54d1e1df3014fdf9d9b623012434d630f0eea 🔍 |
| VirtualSize | 0x6b00 |
| VirtualAddress | 0x4fa000 |
| SizeOfRawData | 0x6600 |
| PointerToRawData | 0x4f8a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.62225 |
| MD5 | 0af0b95935bf4bc8f94b543452836fc5 🔍 |
|---|---|
| SHA1 | 9548ce9c9899a5b90fbafd66b1ecccec8a24dea7 🔍 |
| SHA256 | 0dc72ba1a5065b3a8d7a4090f9c43b42b2ea8386c820b3c689a117eb0c7eccf9 🔍 |
| SHA3 | a23fb73820bec2d2695eca97d31467eb2eb740b377a02ac6c2f78a060506d453 🔍 |
| VirtualSize | 0x1158c |
| VirtualAddress | 0x501000 |
| SizeOfRawData | 0x11600 |
| PointerToRawData | 0x4ff000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.27607 |
| MD5 | d66bf7ae1b4b90e7d55300f7aa1bd9e1 🔍 |
|---|---|
| SHA1 | 0d983f087f6b080c3b375132055353d3705146bf 🔍 |
| SHA256 | b0e66f85de93138474962442f34086c85500465ccec7208225f95aa910421b22 🔍 |
| SHA3 | 5e1090f7bc1f0e62aaf529416c5c2f4eab34ce75a13c04a26243974e3d5363fd 🔍 |
| VirtualSize | 0xf3d8 |
| VirtualAddress | 0x513000 |
| SizeOfRawData | 0xf400 |
| PointerToRawData | 0x510600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 7.97317 |
| MD5 | 1290a16a44407863d217c442e83e2f11 🔍 |
|---|---|
| SHA1 | d6f73005b868ee588368907f56e640dafa09c3b1 🔍 |
| SHA256 | c21fb2f3c499a08cf5eda6cb7fe1629c65594d06989686dec94a838cc23e1e77 🔍 |
| SHA3 | 33da8dc88de08a12b8f64defaedac3f2bb7cc27a87feae6f66c7b50e13201278 🔍 |
| VirtualSize | 0x2804 |
| VirtualAddress | 0x523000 |
| SizeOfRawData | 0x2a00 |
| PointerToRawData | 0x51fa00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.37896 |
| CRYPT32.dll |
CryptProtectData
CryptUnprotectData |
|---|---|
| KERNEL32.dll |
HeapFree
HeapReAlloc GetTimeZoneInformationForYear GlobalLock GlobalUnlock lstrlenW GetProcAddress GetCurrentThreadId CreateWaitableTimerExW SetWaitableTimer GlobalSize WideCharToMultiByte MultiByteToWideChar GlobalAlloc GlobalFree FormatMessageW FreeLibrary LoadLibraryW SetThreadErrorMode LoadLibraryExW Sleep GetModuleHandleA RtlCaptureContext GetCurrentProcess RtlLookupFunctionEntry WaitForSingleObjectEx LoadLibraryA GetCurrentProcessId CreateMutexA ReleaseMutex RtlVirtualUnwind SetLastError GetCurrentDirectoryW GetModuleHandleW GetStdHandle GetConsoleMode GetConsoleOutputCP GetCurrentThread FlsAlloc GetModuleHandleExW FlsFree FlsSetValue HeapAlloc IsThreadAFiber GetEnvironmentVariableW ReadFileEx SleepEx WriteFileEx QueryPerformanceFrequency QueryPerformanceCounter CreateThread GetFullPathNameW CreateFileW SetFileTime FindFirstFileExW FindClose GetFileInformationByHandle GetFileInformationByHandleEx GetSystemTimePreciseAsFileTime CreateDirectoryW ExitProcess GetExitCodeProcess WaitForMultipleObjects GetOverlappedResult CreateEventW CancelIo ReadFile CompareStringOrdinal GetEnvironmentStringsW FreeEnvironmentStringsW GetSystemDirectoryW GetWindowsDirectoryW CreateProcessW GetFileAttributesW GetModuleFileNameW DuplicateHandle SetUnhandledExceptionFilter InitializeSListHead GetProcessHeap SetThreadStackGuarantee AddVectoredExceptionHandler CreateMutexW SwitchToThread LocalFree CopyFileExW MoveFileExW SetFileInformationByHandle GetLastError DeleteFileW WaitForSingleObject CloseHandle WriteConsoleW |
| kernel32.dll |
SystemTimeToFileTime
FlushFileBuffers GetTickCount MapViewOfFile FormatMessageA GetSystemTime GetSystemTimeAsFileTime GetFileSize LockFileEx UnlockFile HeapDestroy UnlockFileEx HeapCompact GetSystemInfo DeleteCriticalSection TryEnterCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection RaiseException AreFileApisANSI HeapCreate WriteFile GetDiskFreeSpaceW OutputDebugStringA LockFile SetFilePointer GetFullPathNameA SetEndOfFile CreateFileMappingW GetTempPathW UnmapViewOfFile HeapValidate HeapSize GetTempPathA GetDiskFreeSpaceA GetFileAttributesA GetFileAttributesExW OutputDebugStringW FlushViewOfFile CreateFileA DeleteFileA |
| api-ms-win-core-synch-l1-2-0.dll |
WaitOnAddress
WakeByAddressAll WakeByAddressSingle |
| bcryptprimitives.dll |
ProcessPrng
|
| ADVAPI32.dll |
RegCloseKey
RegQueryValueExW ImpersonateAnonymousToken RevertToSelf RegOpenKeyExW |
| OPENGL32.dll |
wglCreateContext
wglGetCurrentDC wglShareLists wglGetCurrentContext wglMakeCurrent wglDeleteContext wglGetProcAddress |
| SHLWAPI.dll |
AssocQueryStringW
|
| USER32.dll |
GetSystemMetrics
SendMessageW RedrawWindow CreateIconFromResourceEx SetWindowDisplayAffinity SetWindowTextW GetForegroundWindow ClientToScreen SetCursorPos DestroyWindow MsgWaitForMultipleObjectsEx PeekMessageW DispatchMessageW TranslateMessage RegisterClassExW CreateWindowExW GetActiveWindow RegisterRawInputDevices GetClientRect FlashWindowEx SetWindowPos InvalidateRgn CreateIcon GetWindowTextLengthW GetWindowTextW IsClipboardFormatAvailable GetClipboardData EmptyClipboard SetClipboardData GetWindowPlacement GetClassNameW GetClassInfoExW DefWindowProcW ShowWindow SetWindowLongPtrW EnableMenuItem SetWindowLongW EnumDisplayMonitors MonitorFromWindow DestroyIcon DestroyCursor ChangeDisplaySettingsExW SetWindowPlacement GetMonitorInfoW GetWindowLongPtrW GetWindowLongW GetMenu AdjustWindowRectEx SystemParametersInfoA GetKeyboardLayout MapVirtualKeyExW GetKeyState ToUnicodeEx GetKeyboardState TrackMouseEvent ScreenToClient GetTouchInputInfo CloseTouchInputHandle MonitorFromRect GetDC SetCursor GetCursorPos SetCapture ReleaseCapture GetWindowRect GetClipCursor ClipCursor ShowCursor RegisterTouchWindow GetAsyncKeyState IsProcessDPIAware MapVirtualKeyW SendInput SetForegroundWindow MonitorFromPoint GetRawInputData ValidateRect IsIconic ReleaseDC PostMessageW CloseClipboard RegisterWindowMessageA OpenClipboard GetSystemMenu LoadCursorW |
| SHELL32.dll |
SHGetKnownFolderPath
DragQueryFileW DragFinish |
| GDI32.dll |
DescribePixelFormat
SwapBuffers SetPixelFormat CreateRectRgn DeleteObject GetDeviceCaps ChoosePixelFormat |
| ntdll.dll |
NtReadFile
RtlNtStatusToDosError NtCreateNamedPipeFile NtWriteFile NtOpenFile |
| ole32.dll |
CoCreateInstance
CoUninitialize RevokeDragDrop CoTaskMemFree CoInitializeEx RegisterDragDrop OleInitialize |
| imm32.dll |
ImmSetCompositionWindow
ImmGetContext ImmGetCompositionStringW ImmAssociateContextEx ImmSetCandidateWindow ImmReleaseContext |
| uxtheme.dll |
SetWindowTheme
|
| dwmapi.dll |
DwmEnableBlurBehindWindow
DwmSetWindowAttribute |
| VCRUNTIME140.dll |
strchr
memmove memset __CxxFrameHandler3 memcpy __current_exception_context __current_exception __C_specific_handler strrchr memchr memcmp |
| api-ms-win-crt-math-l1-1-0.dll |
roundf
ceilf floorf sinf powf expf acosf cbrtf exp2f floor trunc round _hypotf sin cos fmod cosf ceil _dclass fabs log atan2f __setusermatherr |
| api-ms-win-crt-string-l1-1-0.dll |
strcmp
strncmp strlen strspn strcspn |
| api-ms-win-crt-runtime-l1-1-0.dll |
_initterm_e
_initterm _get_initial_narrow_environment _initialize_narrow_environment _configure_narrow_argv exit _exit _set_app_type __p___argc _endthreadex _beginthreadex __p___argv _cexit _c_exit terminate strerror _crt_atexit _register_onexit_function _register_thread_local_exe_atexit_callback _initialize_onexit_table _seh_filter_exe |
| api-ms-win-crt-heap-l1-1-0.dll |
_set_new_mode
_msize malloc free realloc |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-time-l1-1-0.dll |
_localtime64_s
|
| api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
_set_fmode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0xf0dd |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 7.98371 |
| Detected Filetype | PNG graphic file |
| MD5 | 1a0b2d9a8709e960f176174d63d12ad3 🔍 |
| SHA1 | a800cf84c87d8745b2668dd9600da6a8f97bdde8 🔍 |
| SHA256 | c20c9833c93f8b763e93df91fc10c64531030f0b1d46f7def106f0480893e543 🔍 |
| SHA3 | 4d99b6afb38f795fd164cd9f5aad7c2dea5cbd5dead5cd3e4ca258b011c70621 🔍 |
| Type |
RT_GROUP_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x14 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 1.51664 |
| Detected Filetype | Icon file |
| MD5 | 44b47e8b2a25978586064ab727d210c2 🔍 |
| SHA1 | 84210ed478ed9ea0f6fdcb9fda8b2633e49373ba 🔍 |
| SHA256 | 30be2461b5452f90fd3789398024ff39c9bd5924155ad76d8298a69963e752da 🔍 |
| SHA3 | 07c8169d1712f7011357049c5a58e2943bf3767d2da4dfc78f3eaddc17eced31 🔍 |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x1ec |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.18882 |
| MD5 | 3cadbe47f7a7f624c5d64590402d2d3e 🔍 |
| SHA1 | 903a09ce2f3b016f03d9c21827ba4dda6e91f5d5 🔍 |
| SHA256 | 0a71bbf6b664c7353db2eb5e6eab1773af67f81d4cb306ec58c0430c4dc42ac5 🔍 |
| SHA3 | 04c1909c85cc921c4a5f5a027b852a45dc20c295e5a40dbc9df5083a67aedef5 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.1.1.0 |
| ProductVersion | 0.1.1.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| ProductVersion (#2) | 0.1.1 |
| ProductName | Quark |
| FileVersion (#2) | 0.1.1 |
| FileDescription | Quark - operator console |
| CompanyName | Quark |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-28 16:59:32 |
| Version | 0.0 |
| SizeofData | 34 |
| AddressOfRawData | 0x4ea7f8 |
| PointerToRawData | 0x4e97f8 |
| Referenced File | quark.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-28 16:59:32 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x4ea81c |
| PointerToRawData | 0x4e981c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-28 16:59:32 |
| Version | 0.0 |
| SizeofData | 856 |
| AddressOfRawData | 0x4ea830 |
| PointerToRawData | 0x4e9830 |
| StartAddressOfRawData | 0x1404eaba8 |
|---|---|
| EndAddressOfRawData | 0x1404ead38 |
| AddressOfIndex | 0x140500a70 |
| AddressOfCallbacks | 0x14025cbe0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140500400 |
| XOR Key | 0xb8c599a2 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 16 |
| Imports (35721) | 2 |
| ASM objects (35721) | 4 |
| C objects (35721) | 10 |
| C++ objects (35721) | 24 |
| C objects (36252) | 1 |
| Imports (33145) | 17 |
| Total imports | 344 |
| Unmarked objects (#2) | 22 |
| Resource objects (36252) | 1 |
| Linker (36252) | 1 |
No comments yet.