| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Mar-31 22:55:30 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses known Mersenne Twister constants |
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The PE is possibly a dropper. | Resources amount for 77.9253% of the executable. |
| Malicious | VirusTotal score: 12/72 (Scanned on 2026-04-10 14:39:58) |
APEX:
Malicious
CrowdStrike: win/malicious_confidence_70% (D) Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS Elastic: malicious (high confidence) MaxSecure: Trojan.Malware.300983.susgen McAfeeD: ti!69A651493B27 Sangfor: Trojan.Win32.Save.a Skyhigh: BehavesLike.Win32.Spyware.vc Sophos: Generic ML PUA (PUA) Symantec: ML.Attribute.HighConfidence Trapmine: malicious.moderate.ml.score |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Mar-31 22:55:30 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x76400 |
| SizeOfInitializedData | 0x225800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0005707B (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x78000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x2a0000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
FreeLibrary
QueryPerformanceCounter SizeofResource VirtualProtect GetModuleFileNameW FindResourceA Sleep GetTickCount64 DisableThreadLibraryCalls LockResource LoadResource ExitProcess VirtualFree VirtualAlloc VirtualQuery HeapCreate HeapFree GetCurrentProcess Thread32Next Thread32First GetCurrentThreadId SuspendThread ResumeThread CreateToolhelp32Snapshot GetLastError HeapReAlloc CloseHandle HeapAlloc GetThreadContext GetCurrentProcessId GetModuleHandleW GetProcAddress SetThreadContext OpenThread GetSystemDirectoryA SetEndOfFile WriteConsoleW HeapSize CreateFileW GetStringTypeW SetStdHandle GetProcessHeap FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetCPInfo GetOEMCP GetACP IsValidCodePage FindNextFileW FindFirstFileExW FindClose GetFileSizeEx GetConsoleOutputCP WriteFile FlushFileBuffers LCMapStringW QueryPerformanceFrequency LoadLibraryA GetModuleHandleA GlobalUnlock WideCharToMultiByte GlobalLock GlobalFree MultiByteToWideChar GlobalAlloc FlushInstructionCache InitializeCriticalSectionEx FlsFree ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW GetSystemTimeAsFileTime InitializeSListHead RtlUnwind RaiseException InterlockedFlushSList SetLastError EncodePointer EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree LoadLibraryExW ReadFile GetModuleHandleExW SetFilePointerEx GetConsoleMode ReadConsoleW GetStdHandle GetFileType FlsAlloc FlsGetValue FlsSetValue DecodePointer |
|---|---|
| USER32.dll |
SetClipboardData
GetClipboardData EmptyClipboard CloseClipboard OpenClipboard CallWindowProcW GetActiveWindow GetAsyncKeyState MessageBoxA SetWindowLongW GetKeyState ScreenToClient GetCapture ClientToScreen IsChild TrackMouseEvent GetForegroundWindow LoadCursorW SetCapture SetCursor GetClientRect ReleaseCapture SetCursorPos GetCursorPos |
| IMM32.dll |
ImmGetContext
ImmSetCompositionWindow ImmReleaseContext |
| D3DCOMPILER_47.dll |
D3DCompile
|
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
| Ordinal | 1 |
|---|---|
| Address | 0x565a0 |
| Ordinal | 2 |
|---|---|
| Address | 0x565b0 |
| Ordinal | 3 |
|---|---|
| Address | 0x565d0 |
| Ordinal | 4 |
|---|---|
| Address | 0x565c0 |
| Ordinal | 5 |
|---|---|
| Address | 0x565e0 |
| Ordinal | 6 |
|---|---|
| Address | 0x565f0 |
| Ordinal | 7 |
|---|---|
| Address | 0x56600 |
| Ordinal | 8 |
|---|---|
| Address | 0x56610 |
| Ordinal | 9 |
|---|---|
| Address | 0x56620 |
| Ordinal | 10 |
|---|---|
| Address | 0x56630 |
| Ordinal | 11 |
|---|---|
| Address | 0x56640 |
| Ordinal | 12 |
|---|---|
| Address | 0x56650 |
| Ordinal | 13 |
|---|---|
| Address | 0x56660 |
| Ordinal | 14 |
|---|---|
| Address | 0x56670 |
| Ordinal | 15 |
|---|---|
| Address | 0x56680 |
| Ordinal | 16 |
|---|---|
| Address | 0x56690 |
| Ordinal | 17 |
|---|---|
| Address | 0x42070 |
| Ordinal | 18 |
|---|---|
| Address | 0x42070 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-31 22:55:30 |
| Version | 0.0 |
| SizeofData | 900 |
| AddressOfRawData | 0x8d6b4 |
| PointerToRawData | 0x8beb4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-31 22:55:30 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1008da48 |
|---|---|
| EndAddressOfRawData | 0x1008da6c |
| AddressOfIndex | 0x10091154 |
| AddressOfCallbacks | 0x10078270 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x10090040 |
| SEHandlerTable | 0x1008d53c |
| SEHandlerCount | 40 |
| XOR Key | 0xb8745507 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (33145) | 32 |
| C++ objects (33145) | 164 |
| C objects (33145) | 23 |
| ASM objects (35207) | 25 |
| C objects (35207) | 15 |
| C++ objects (35207) | 39 |
| Imports (33145) | 15 |
| Total imports | 162 |
| C++ objects (LTCG) (35222) | 15 |
| Exports (35222) | 1 |
| Resource objects (35222) | 1 |
| 151 | 1 |
| Linker (35222) | 1 |
No comments yet.