5fc1251e474eae9253362a08095e989edc2b63de21d76052a2c849efc6792c3f

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Mar-11 02:57:57
TLS Callbacks 1 callback(s) detected.
Debug artifacts voice_2.pdb

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • 0www.entrust.net
  • GoDaddy.com
  • entrust.net
  • githubusercontent.com
  • http://lame.sf.net
  • https://docs.rs
  • https://raw.githubusercontent.com
  • https://raw.githubusercontent.com/3moises/tauri/refs/heads/dev/packages/cli/array11.json
  • https://servrwindow.com
  • lame.sf.net
  • openssl.org
  • raw.githubusercontent.com
  • servrwindow.com
  • www.entrust.net
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to Blowfish
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExA
  • LoadLibraryExW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegCloseKey
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegOpenKeyTransactedW
  • RegCreateKeyExW
  • RegCreateKeyTransactedW
Possibly launches other programs:
  • CreateProcessW
Uses Windows's Native API:
  • NtReadFile
  • NtOpenFile
  • NtCreateNamedPipeFile
  • NtDeviceIoControlFile
  • NtCancelIoFileEx
  • NtCreateFile
  • NtWriteFile
Leverages the raw socket API to access the Internet:
  • ws2_32.dll
Interacts with the certificate store:
  • CertAddCertificateContextToStore
  • CertOpenStore
Malicious VirusTotal score: 35/71 (Scanned on 2026-08-14 06:03:27) ALYac: Trojan.GenericKD.79762549
AVG: Win64:MalwareX-gen [Misc]
Antiy-AVL: Trojan/Win32.Agent
Arcabit: Trojan.Generic.D4C11475
Avast: Win64:MalwareX-gen [Misc]
Avira: TR/W64.Agent
BitDefender: Trojan.GenericKD.79762549
CTX: exe.trojan.wacatac
DeepInstinct: MALICIOUS
DrWeb: BackDoor.Siggen2.5978
ESET-NOD32: Win64/Agent.IQV trojan
Emsisoft: Trojan.GenericKD.79762549 (B)
F-Secure: Trojan.TR/W64.Agent
Fortinet: W64/Agent.IQV!tr
GData: Trojan.GenericKD.79762549
Google: Detected
Ikarus: Trojan.Win64.Agent
Kaspersky: HEUR:Backdoor.Win32.Generic
Lionic: Trojan.Win32.Generic.m!c
MaxSecure: Trojan.Malware.324995110.susgen
McAfeeD: ti!5FC1251E474E
MicroWorld-eScan: Trojan.GenericKD.79762549
Microsoft: Trojan:Win32/Wacatac.B!ml
Paloalto: generic.ml
Rising: Backdoor.Generic!8.CE (TFE:5:TV9vigrEb1O)
Sophos: Mal/Generic-S
Symantec: Trojan Horse
Tencent: Malware.Win32.Gencirc.14ab3f23
TrellixENS: Artemis!439255736797
TrendMicro: Trojan.Win32.WACATAC.USBLHD26
TrendMicro-HouseCall: Trojan.Win32.WACATAC.USBLHD26
VIPRE: Trojan.GenericKD.79762549
Varist: W64/ABTrojan.PGCS-2812
ViRobot: Trojan.Win.Z.Agent.8958976
alibabacloud: Backdoor:Win/Wacatac.B9nj

Hashes

MD5 439255736797bc88bd19f282449e0436 🔍
SHA1 724f6ca2ea66dbf117c7eea42c99760716ec75b9 🔍
SHA256 5fc1251e474eae9253362a08095e989edc2b63de21d76052a2c849efc6792c3f 🔍
SHA3 4a6adf2dd57fe1c079d32b784566df90642e112d5e01723ceae70134eee98eb3 🔍
SSDeep 98304:mahKD7SG0SRxW7SBaHvxkVgy3ju5LPCV+TRXsZ6:mRgWpgyzu5L2sB 🔍
Imports Hash 067f5a6aac4512b4a1c18cf8b3e7e2d7 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Mar-11 02:57:57
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x4d4000
SizeOfInitializedData 0x3b8200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000004B227C (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x88f000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 d19c8a2ebb4d05a14fff055de33ed015 🔍
SHA1 5fe1b12b7cff7b0a83f8345b3aedd3c6be7b948c 🔍
SHA256 0e37817bd2de7c9a1369f1e467a45c1539e23f64188df891e884e5c5cc896c6b 🔍
SHA3 c9e86f966702fe4edeebdaecb4819efc42caf402b7a20916b2604ad7df40701b 🔍
VirtualSize 0x4d3e80
VirtualAddress 0x1000
SizeOfRawData 0x4d4000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.28108

.rdata

MD5 9fd473d9b154df34485eada710f4100b 🔍
SHA1 28570fd8ab8e80ecfa2d4e31817fb3f1a98d89ea 🔍
SHA256 16358754cea664adec997b7f4dcc785e99af6602488ba3f998a0527c1dce3d05 🔍
SHA3 9fb6c72c3f6b5254ecc4856d2fb073267ff3aa4fd64c39e2bd26b60b248a82e2 🔍
VirtualSize 0x36c846
VirtualAddress 0x4d5000
SizeOfRawData 0x36ca00
PointerToRawData 0x4d4400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.01693

.data

MD5 ad4357f355a728bb67c482ca36e4f8cd 🔍
SHA1 43606a7eb9b10484d4c1a31580bc232b1dc63fad 🔍
SHA256 3c4a5dde358482824b78dfd3b125673d84a13cde32a5302f711e4dc75f426324 🔍
SHA3 43f02a2ebd491295ceed7e45be8fa43de1178c13c17bc62bfd87141f50c9881b 🔍
VirtualSize 0x4788
VirtualAddress 0x842000
SizeOfRawData 0x3600
PointerToRawData 0x840e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.37964

.pdata

MD5 e509247fed5ba2a1b9861b28837bf3d3 🔍
SHA1 71874fd868ae8484333cf481f715fb91b84bb040 🔍
SHA256 764285af64e29fb773d4d6990fa34d8452d4cc3ddce2f7e51bbdc9575bbcc1c3 🔍
SHA3 ac980254b0dfd225dc0aab5b106e8103d16abfd5532bb439524abd7f7efec01e 🔍
VirtualSize 0x39fc0
VirtualAddress 0x847000
SizeOfRawData 0x3a000
PointerToRawData 0x844400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.50715

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x881000
SizeOfRawData 0x200
PointerToRawData 0x87e400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.reloc

MD5 28a13be1a7fa676eb9a6f1443b371532 🔍
SHA1 4003a2427f09126cac2ea73e9ccb17534375bf51 🔍
SHA256 ed4255a6813336d4735e736f32dff8a5710f645dae46e234bd44bb254045979a 🔍
SHA3 f63ea21ef70a0638c4383676fdcd3cc6b743f910a449e8b66f397cddf28be045 🔍
VirtualSize 0xccb4
VirtualAddress 0x882000
SizeOfRawData 0xce00
PointerToRawData 0x87e600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.4673

Imports

bcryptprimitives.dll ProcessPrng
kernel32.dll TlsSetValue
TlsGetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
EncodePointer
RaiseException
RtlPcToFileHeader
RtlUnwindEx
IsProcessorFeaturePresent
GetStartupInfoW
SetUnhandledExceptionFilter
UnhandledExceptionFilter
IsDebuggerPresent
InitializeSListHead
GetSystemTimeAsFileTime
HeapFree
FindNextFileW
RtlLookupFunctionEntry
RtlCaptureContext
GetProcAddress
TerminateProcess
LoadLibraryExA
FreeLibrary
GetProcessHeap
IsValidCodePage
GetOEMCP
QueryPerformanceCounter
GetSystemTimePreciseAsFileTime
GetCPInfo
WriteFileEx
CreateProcessW
GetWindowsDirectoryW
GetLastError
GetSystemDirectoryW
CompareStringOrdinal
FormatMessageW
GetStringTypeW
FreeEnvironmentStringsW
CreateThread
Sleep
SetWaitableTimer
TlsFree
GetExitCodeProcess
CreateFileW
GetCommandLineA
HeapAlloc
SetStdHandle
CreateWaitableTimerExW
GetACP
GetModuleHandleExW
LoadLibraryExW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
GetConsoleOutputCP
InitializeCriticalSectionEx
VirtualProtect
GetModuleHandleW
GetStdHandle
WriteConsoleW
HeapSize
GetSystemInfo
MultiByteToWideChar
GetConsoleMode
SetConsoleMode
CancelIo
QueryPerformanceFrequency
SleepEx
ReadFileEx
WaitForMultipleObjects
SetHandleInformation
ExitProcess
GetModuleFileNameW
GetModuleHandleA
GetFullPathNameW
SetEnvironmentVariableW
GetFileType
FindClose
FindFirstFileExW
GetFinalPathNameByHandleW
DeleteFileW
GetFileInformationByHandle
SwitchToThread
GetFileInformationByHandleEx
SetConsoleCtrlHandler
PostQueuedCompletionStatus
CreateIoCompletionPort
GetQueuedCompletionStatusEx
GetOverlappedResult
ReadFile
WriteFile
CreateDirectoryW
MoveFileExW
SetFileCompletionNotificationModes
GetTimeZoneInformationForYear
GetCurrentProcessId
CreateEventA
SetEvent
CompareStringW
CloseHandle
LCMapStringW
GetComputerNameExW
VirtualQuery
RtlVirtualUnwind
GetCurrentThreadId
SetThreadPriority
WaitForMultipleObjectsEx
GetCommandLineW
GetEnvironmentVariableW
GetEnvironmentStringsW
CreateEventW
WaitForSingleObject
GetCurrentDirectoryW
SetLastError
GetCurrentThread
SetThreadStackGuarantee
AddVectoredExceptionHandler
DuplicateHandle
FlushFileBuffers
GetFileAttributesW
SetFileInformationByHandle
HeapReAlloc
lstrlenW
GetCurrentProcess
WideCharToMultiByte
WaitForSingleObjectEx
LoadLibraryA
CreateMutexA
ReleaseMutex
SetFilePointerEx
api-ms-win-core-synch-l1-2-0.dll WakeByAddressSingle
WaitOnAddress
WakeByAddressAll
ws2_32.dll getaddrinfo
freeaddrinfo
shutdown
bind
WSASocketW
WSAIoctl
WSAStartup
WSACleanup
recv
connect
WSASend
send
getsockname
getpeername
getsockopt
setsockopt
WSAGetLastError
closesocket
ioctlsocket
secur32.dll EncryptMessage
ApplyControlToken
DecryptMessage
FreeContextBuffer
InitializeSecurityContextW
FreeCredentialsHandle
AcquireCredentialsHandleA
DeleteSecurityContext
QueryContextAttributesW
AcceptSecurityContext
advapi32.dll SetServiceStatus
RegisterServiceCtrlHandlerExW
StartServiceCtrlDispatcherW
SystemFunction036
RegCloseKey
RegOpenKeyExW
RegQueryValueExW
RegOpenKeyTransactedW
RegCreateKeyExW
RegCreateKeyTransactedW
ntdll.dll NtReadFile
NtOpenFile
NtCreateNamedPipeFile
NtDeviceIoControlFile
RtlNtStatusToDosError
NtCancelIoFileEx
NtCreateFile
NtWriteFile
ole32.dll CoCreateInstance
CoTaskMemFree
PropVariantClear
CoUninitialize
CoInitializeEx
oleaut32.dll SysStringLen
GetErrorInfo
SysFreeString
crypt32.dll CertAddCertificateContextToStore
CertOpenStore
CertEnumCertificatesInStore
CertFreeCertificateChain
CertDuplicateCertificateChain
CertCloseStore
CertDuplicateStore
CertFreeCertificateContext
CertDuplicateCertificateContext
CertVerifyCertificateChainPolicy
CertGetCertificateChain
bcrypt.dll BCryptGenRandom
libmp3lame.DLL (delay-loaded) #139
#22
#6
#41
#4
#1
#148
#164

Delayed Imports

Attributes 0x1
Name libmp3lame.DLL
ModuleHandle 0x846740
DelayImportAddressTable 0x8454e0
DelayImportNameTable 0x83fcf0
BoundDelayImportTable 0x83fd38
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Mar-11 02:57:57
Version 0.0
SizeofData 36
AddressOfRawData 0x77a444
PointerToRawData 0x779844
Referenced File voice_2.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Mar-11 02:57:57
Version 0.0
SizeofData 20
AddressOfRawData 0x77a468
PointerToRawData 0x779868

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Mar-11 02:57:57
Version 0.0
SizeofData 1072
AddressOfRawData 0x77a47c
PointerToRawData 0x77987c

TLS Callbacks

StartAddressOfRawData 0x14077a8f8
EndAddressOfRawData 0x14077aac0
AddressOfIndex 0x1408456a8
AddressOfCallbacks 0x1404d5758
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x000000014046E5C0

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140844a40

RICH Header

XOR Key 0x9906a2de
Unmarked objects 0
C++ objects (33145) 142
C objects (33145) 18
ASM objects (33145) 11
ASM objects (35207) 9
C objects (35207) 16
C objects (35222) 12
C++ objects (35207) 45
Total imports 393
Unmarked objects (#2) 632
Linker (35222) 1

Errors

Leave a comment

No comments yet.