| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Aug-09 14:11:12 |
| Detected languages |
English - United States
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 19/70 (Scanned on 2026-08-16 10:33:26) |
APEX:
Malicious
Bkav: W32.Malware.2D879D86 CTX: exe.trojan.generic CrowdStrike: win/malicious_confidence_70% (W) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS Elastic: malicious (high confidence) Fortinet: W32/PossibleThreat Google: Detected Lionic: Trojan.Win32.Generic.4!c McAfeeD: ti!6CA509EA2F98 Microsoft: Trojan:Win32/Wacatac.B!ml Paloalto: generic.ml Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Suspicious PE Symantec: ML.Attribute.HighConfidence TrellixENS: Artemis!0E5F0E34F4EE TrendMicro-HouseCall: Trojan.Win64.Gen.TL0101HC26ZH |
| MD5 | 0e5f0e34f4ee9e432caf200e9fd90732 🔍 |
|---|---|
| SHA1 | 9d80010d8b891ac295ff76a60e90bf5ec4b9e600 🔍 |
| SHA256 | 6ca509ea2f9857bb5944acbef6677982d902bb6eabad32d908522214123479bd 🔍 |
| SHA3 | 7300469f35bca4ce12d9548b16b1df05226632fcb1825150491cb4dfbee35252 🔍 |
| SSDeep | 12288:CvUyNPyiMdECJkrUGDFa5yG/5E3uyoRXnZwnjolZZ37aZBYb:Cvud5JwFaY6ZRZwnjWZZ37a3Y 🔍 |
| Imports Hash | 399bafd098465fcd2f1f2ba5aeced475 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Aug-09 14:11:12 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x8e600 |
| SizeOfInitializedData | 0x31800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000005B420 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xc5000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | c804d11bba11300874faac14f2ee811b 🔍 |
|---|---|
| SHA1 | 0546a3e8b9ea31bd72caf6ecf3e558843375c6e3 🔍 |
| SHA256 | cd59a3e4f42e53e55187a498a3710a3d2976b8bd13f91279726f6f14d5916f83 🔍 |
| SHA3 | a5a3266bd2195c593372bc8f0f85a74429d3e82775d1eeee01bf5bf9c40162ed 🔍 |
| VirtualSize | 0x8e4ec |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x8e600 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.55623 |
| MD5 | 07ebe7a295ab7b7bbf02948f702c1fba 🔍 |
|---|---|
| SHA1 | 8e38edd93acfa64cab77e755ea981872ed260076 🔍 |
| SHA256 | 7b820bd26eb097094161fdac2befec9fa3ef28bb7eb7fc9f1b393db12b8327be 🔍 |
| SHA3 | 8bdb879e877ecddee6cfee3c23e882e34a718a1491bcc75feddb9e4bc198c168 🔍 |
| VirtualSize | 0x268ce |
| VirtualAddress | 0x90000 |
| SizeOfRawData | 0x26a00 |
| PointerToRawData | 0x8ea00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.87822 |
| MD5 | 850a7abcf4d1c473a8309e90d549fb67 🔍 |
|---|---|
| SHA1 | 7ce9c4e002cceb8cdaecdd260cdcd601ca59fbca 🔍 |
| SHA256 | 1669f9bf9f0de7bc2f041a2586cba60ed9c650f42655739ab6615e6341dc2d1f 🔍 |
| SHA3 | bfa38e48f6ab5f4a3ea403b6c8844a9dd4c57aacca4838bbef786d6f146fed9a 🔍 |
| VirtualSize | 0x34e8 |
| VirtualAddress | 0xb7000 |
| SizeOfRawData | 0x1e00 |
| PointerToRawData | 0xb5400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.21903 |
| MD5 | 53da036f6f8757865cd5d7304eb5a11e 🔍 |
|---|---|
| SHA1 | 6da4ca418a61567abca96a59e1f85e6e560b5479 🔍 |
| SHA256 | 13f95e0864998f24e645f54d77da7a567da94bb974d791d12e60942a26737228 🔍 |
| SHA3 | a7ff5fcda9b42f25d4bc912cad979d62e863d862aaf67cdff5440348597430ac 🔍 |
| VirtualSize | 0x6498 |
| VirtualAddress | 0xbb000 |
| SizeOfRawData | 0x6600 |
| PointerToRawData | 0xb7200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.92029 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x100 |
| VirtualAddress | 0xc2000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0xbd800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 4ddcbab8aaae10a6872e1399bdcd4e5f 🔍 |
|---|---|
| SHA1 | 108100719ee8cd8c65d52c8485d9445e37325708 🔍 |
| SHA256 | 3ae662bbba823a188d05fff1ecd3cd4497849105925efe73578bf92891633d02 🔍 |
| SHA3 | f29d6001d38ea1e0eb08e6bb861c3b22649508c0b2c9b0e2c13759e5ac7e84e2 🔍 |
| VirtualSize | 0x1e8 |
| VirtualAddress | 0xc3000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0xbda00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.7657 |
| MD5 | 776e1a28b46b64e4fe6451906cb436b3 🔍 |
|---|---|
| SHA1 | 4d957c530fcdebafeaa1d5fa6abd2d09680de99c 🔍 |
| SHA256 | b01dcc50652d11ceca999d6440792cbd029a94337bf5d49795bdc27bf18ece50 🔍 |
| SHA3 | bc41ecda7f5b8ed473a60149360fd4f789e271ffdc4867eac42bf89ce376c3ec 🔍 |
| VirtualSize | 0xd30 |
| VirtualAddress | 0xc4000 |
| SizeOfRawData | 0xe00 |
| PointerToRawData | 0xbdc00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.34165 |
| d3d9.dll |
Direct3DCreate9Ex
|
|---|---|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| KERNEL32.dll |
Sleep
GetLastError Process32NextW LoadLibraryA QueryPerformanceFrequency Process32FirstW CloseHandle CreateThread Beep GetProcAddress ExitProcess lstrcmpiW QueryPerformanceCounter MultiByteToWideChar GlobalAlloc GlobalFree GlobalLock WideCharToMultiByte GlobalUnlock FreeLibrary FreeEnvironmentStringsW GetEnvironmentStringsW HeapReAlloc GetOEMCP GetACP IsValidCodePage ReadConsoleW CreateProcessW GetExitCodeProcess WaitForSingleObject CreateToolhelp32Snapshot EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW LoadLibraryExW VirtualProtect HeapFree GetConsoleMode GetConsoleOutputCP FlushFileBuffers HeapAlloc GetFileType SetFilePointerEx GetFileSizeEx UnhandledExceptionFilter IsDebuggerPresent RtlVirtualUnwind RtlCaptureContext GetCommandLineA GetModuleFileNameW WriteFile IsProcessorFeaturePresent ReadFile FreeLibraryAndExitThread ExitThread GetModuleHandleExW TerminateProcess FlsFree OpenProcess GetModuleHandleA CreateFileW DeviceIoControl GetStdHandle GetCurrentProcess SetConsoleTitleA GetCommandLineW SetConsoleTextAttribute SetLastError GetStartupInfoW SetEnvironmentVariableW SetStdHandle GetProcessHeap HeapSize WriteConsoleW SetEndOfFile DeleteFileW FindClose LocalFree FormatMessageA GetLocaleInfoEx CreateDirectoryW RtlUnwind FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesExW SetFileInformationByHandle CreateFile2 AreFileApisANSI GetModuleHandleW GetFileInformationByHandleEx GetCurrentThreadId EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection EncodePointer DecodePointer LCMapStringEx ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW GetStringTypeW GetCPInfo GetCurrentProcessId GetSystemTimeAsFileTime InitializeSListHead SetUnhandledExceptionFilter RtlLookupFunctionEntry RtlUnwindEx RtlPcToFileHeader RaiseException FlsAlloc FlsGetValue FlsSetValue |
| USER32.dll |
ScreenToClient
ClientToScreen GetForegroundWindow SetCursor GetClientRect SetCursorPos OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData GetWindowThreadProcessId GetKeyState GetWindowRect DestroyWindow SetWindowPos CallNextHookEx GetCursorPos ShowWindow IsWindow GetAsyncKeyState DispatchMessageW SetWindowsHookExA PeekMessageW MessageBoxA UnhookWindowsHookEx EnumWindows DefWindowProcA SetLayeredWindowAttributes TranslateMessage LoadIconW LoadCursorW ToUnicode SetWindowLongW RegisterClassExA UpdateWindow GetSystemMetrics |
| ADVAPI32.dll |
OpenProcessToken
CreateProcessAsUserW SetThreadToken GetTokenInformation SetTokenInformation LookupPrivilegeValueW RevertToSelf PrivilegeCheck DuplicateTokenEx |
| IMM32.dll |
ImmSetCompositionWindow
ImmReleaseContext ImmGetContext ImmSetCandidateWindow |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x188 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.89623 |
| MD5 | b8e76ddb52d0eb41e972599ff3ca431b 🔍 |
| SHA1 | fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍 |
| SHA256 | 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍 |
| SHA3 | 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-09 14:11:12 |
| Version | 0.0 |
| SizeofData | 1052 |
| AddressOfRawData | 0xabc18 |
| PointerToRawData | 0xaa618 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-09 14:11:12 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1400ac090 |
|---|---|
| EndAddressOfRawData | 0x1400ac098 |
| AddressOfIndex | 0x1400b9614 |
| AddressOfCallbacks | 0x1400906e8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400b7200 |
| XOR Key | 0xb11695ac |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 189 |
| C objects (33145) | 36 |
| ASM objects (33145) | 25 |
| ASM objects (35721) | 10 |
| C objects (35721) | 18 |
| C++ objects (35721) | 95 |
| Imports (33145) | 15 |
| Total imports | 221 |
| C++ objects (LTCG) (36252) | 7 |
| Resource objects (36252) | 1 |
| Linker (36252) | 1 |
No comments yet.