| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Oct-07 14:04:13 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
discord_quest_completer.pdb
|
| FileVersion | 25.10.7 |
| ProductVersion | 25.10.7 |
| FileDescription | Discord Quest Completer |
| ProductName | Discord Quest Completer |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA256
Uses constants related to SHA512 Uses constants related to RC5 or RC6 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/71 (Scanned on 2026-05-23 10:46:38) | Trapmine: malicious.moderate.ml.score |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2025-Oct-07 14:04:13 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xab0600 |
| SizeOfInitializedData | 0x5c8200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000A7D470 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x107c000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
RtlVirtualUnwind
DeleteCriticalSection InitializeCriticalSectionAndSpinCount CreateFileW SetNamedPipeHandleState lstrlenW LoadLibraryA HeapAlloc IsProcessorFeaturePresent GetProcessHeap RtlUnwindEx RtlPcToFileHeader RaiseException SetUnhandledExceptionFilter UnhandledExceptionFilter IsDebuggerPresent HeapFree InitializeSListHead GetProcAddress SleepConditionVariableSRW WakeAllConditionVariable CreateMutexA WaitForSingleObjectEx LoadLibraryW AcquireSRWLockExclusive WideCharToMultiByte ReleaseSRWLockExclusive MultiByteToWideChar GetConsoleOutputCP CreateProcessW GetWindowsDirectoryW GetSystemDirectoryW GetFinalPathNameByHandleW DeviceIoControl CreateDirectoryW GetFileInformationByHandleEx FindNextFileW SetEnvironmentVariableW GetTempPathW GetFullPathNameW SetWaitableTimer CreateWaitableTimerExW CreateThread WaitForMultipleObjects ReadFileEx ExitProcess CancelIo LCIDToLocaleName GetSystemTimeAsFileTime GetCurrentThreadId ReleaseMutex HeapReAlloc CopyFileExW FindClose FindFirstFileExW GetFileAttributesW OutputDebugStringA OutputDebugStringW GetModuleFileNameW GetLastError EncodePointer TlsAlloc TlsGetValue TlsSetValue LoadLibraryExW GetModuleHandleW FreeLibrary GetEnvironmentVariableW GetSystemTimePreciseAsFileTime QueryPerformanceFrequency TerminateProcess GetUserDefaultUILanguage WriteConsoleW GetExitCodeProcess SleepEx WriteFileEx TlsFree GetCurrentProcessId GetStdHandle SetFilePointerEx DuplicateHandle GetCurrentProcess SetFileInformationByHandle GetCommandLineW GetEnvironmentStringsW GetCurrentDirectoryW SetLastError RtlLookupFunctionEntry RtlCaptureContext GetSystemInfo QueryPerformanceCounter SwitchToThread SetHandleInformation GetCurrentThread SetThreadStackGuarantee AddVectoredExceptionHandler CompareStringOrdinal FreeEnvironmentStringsW GetModuleHandleA Sleep GetConsoleMode CreateIoCompletionPort CancelIoEx ReadFile GetOverlappedResult WriteFile PostQueuedCompletionStatus GetQueuedCompletionStatusEx GetFileInformationByHandle CloseHandle FormatMessageW WaitForSingleObject SetFileCompletionNotificationModes CreateEventW LoadLibraryExA |
|---|---|
| advapi32.dll |
RegCreateKeyExW
RegSetValueExW RegQueryValueExW RegOpenKeyExW SystemFunction036 EventRegister EventSetInformation EventWriteTransfer EventUnregister RegGetValueW RegCloseKey |
| api-ms-win-core-synch-l1-2-0.dll |
WakeByAddressAll
WaitOnAddress WakeByAddressSingle |
| bcryptprimitives.dll |
ProcessPrng
|
| SHELL32.dll |
#190
#155 ShellExecuteExW SHCreateItemFromParsingName SHGetKnownFolderPath DragQueryFileW DragFinish SHOpenFolderAndSelectItems SHAppBarMessage |
| ole32.dll |
CoCreateInstance
CoTaskMemFree CoUninitialize CoInitializeEx RevokeDragDrop RegisterDragDrop CoTaskMemAlloc CoInitialize OleInitialize |
| user32.dll |
DestroyAcceleratorTable
CreateMenu DestroyMenu RemoveMenu DrawMenuBar SetMenu DrawTextW GetWindowDC OffsetRect GetMenuBarInfo GetMenuItemInfoW TranslateAcceleratorW DestroyWindow ToUnicodeEx InsertMenuW GetKeyState GetAsyncKeyState GetKeyboardState SendInput SetForegroundWindow GetWindowTextW AppendMenuW GetWindowTextLengthW SetWindowTextW SetMenuItemInfoW MonitorFromPoint EnumDisplayMonitors SystemParametersInfoA SetPropW IsWindowVisible GetMenu GetKeyboardLayout GetRawInputData CreateIcon SetWindowDisplayAffinity ClipCursor GetClipCursor ShowCursor SetWindowLongW EnableMenuItem GetSystemMenu ScreenToClient GetWindowLongW ClientToScreen DestroyIcon SystemParametersInfoW ReleaseCapture SetCapture SetWindowLongPtrW MsgWaitForMultipleObjectsEx RegisterRawInputDevices IsProcessDPIAware SetParent MapWindowPoints MonitorFromRect RegisterWindowMessageA ShowWindow CreateAcceleratorTableW TrackMouseEvent ReleaseDC GetDC CheckMenuItem DrawIconEx TrackPopupMenu IsWindowEnabled RedrawWindow PostQuitMessage EnableWindow GetWindowLongPtrW GetParent SetWindowRgn FindWindowExW GetTouchInputInfo AdjustWindowRect MapVirtualKeyExW GetForegroundWindow RegisterTouchWindow IsWindow AdjustWindowRectEx FlashWindowEx GetActiveWindow UpdateWindow InvalidateRect SetCursorPos InvalidateRgn GetWindowPlacement SetWindowPlacement ChangeDisplaySettingsExW DefWindowProcW GetMessageW MapVirtualKeyW IsIconic EnumChildWindows DispatchMessageA GetMessageA CreateWindowExW RegisterClassExW GetWindowRect GetClientRect SetWindowPos PostMessageW LoadCursorW DispatchMessageW TranslateMessage SendMessageW GetUpdateRect PeekMessageW PostThreadMessageW ValidateRect GetMonitorInfoW MonitorFromWindow GetCursorPos SetCursor FillRect GetSystemMetrics CloseTouchInputHandle CreatePopupMenu |
| comctl32.dll |
SetWindowSubclass
DefSubclassProc TaskDialogIndirect RemoveWindowSubclass |
| gdi32.dll |
DeleteObject
CombineRgn SetBkMode GetDeviceCaps SetTextColor CreateRectRgn CreateSolidBrush CreateCompatibleDC DeleteDC SelectObject CreateDIBSection BitBlt |
| dwmapi.dll |
DwmGetWindowAttribute
DwmSetWindowAttribute DwmEnableBlurBehindWindow |
| shlwapi.dll |
SHCreateMemStream
|
| ws2_32.dll |
WSACleanup
getaddrinfo freeaddrinfo getsockopt WSAStartup getpeername getsockname WSASocketW bind connect ioctlsocket shutdown recv send WSASend setsockopt WSAIoctl WSAGetLastError closesocket |
| bcrypt.dll |
BCryptGenRandom
|
| ntdll.dll |
NtWriteFile
NtCreateFile NtReadFile RtlGetVersion NtCreateNamedPipeFile NtOpenFile NtCancelIoFileEx NtDeviceIoControlFile RtlNtStatusToDosError |
| oleaut32.dll |
SysFreeString
SetErrorInfo SysStringLen GetErrorInfo |
| api-ms-win-crt-math-l1-1-0.dll |
trunc
round __setusermatherr floor pow |
| api-ms-win-crt-string-l1-1-0.dll |
strcpy_s
wcsncmp strcmp wcslen _wcsicmp strlen wcscmp |
| api-ms-win-crt-convert-l1-1-0.dll |
wcstol
_wtoi _ultow_s |
| api-ms-win-crt-heap-l1-1-0.dll |
free
_set_new_mode _callnewh malloc calloc |
| api-ms-win-crt-runtime-l1-1-0.dll |
_set_app_type
_configure_narrow_argv _initialize_narrow_environment _seh_filter_exe _initterm _initterm_e exit _exit _get_initial_narrow_environment __p___argc __p___argv _cexit _c_exit _register_thread_local_exe_atexit_callback abort _initialize_onexit_table terminate _register_onexit_function _crt_atexit |
| api-ms-win-crt-stdio-l1-1-0.dll |
_set_fmode
__p__commode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 25.4.18.0 |
| ProductVersion | 25.4.18.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| FileVersion (#2) | 25.10.7 |
| ProductVersion (#2) | 25.10.7 |
| FileDescription | Discord Quest Completer |
| ProductName | Discord Quest Completer |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Oct-07 14:04:13 |
| Version | 0.0 |
| SizeofData | 52 |
| AddressOfRawData | 0xd7f974 |
| PointerToRawData | 0xd7e374 |
| Referenced File | discord_quest_completer.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Oct-07 14:04:13 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xd7f9a8 |
| PointerToRawData | 0xd7e3a8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Oct-07 14:04:13 |
| Version | 0.0 |
| SizeofData | 1048 |
| AddressOfRawData | 0xd7f9bc |
| PointerToRawData | 0xd7e3bc |
| StartAddressOfRawData | 0x140d7fe20 |
|---|---|
| EndAddressOfRawData | 0x140d7ffec |
| AddressOfIndex | 0x140fce3d0 |
| AddressOfCallbacks | 0x140ab2c78 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x0000000140A59990
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140fcbd40 |
| XOR Key | 0x302687bd |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 14 |
| ASM objects (35207) | 9 |
| C objects (35207) | 13 |
| C++ objects (35207) | 47 |
| Imports (33140) | 5 |
| C objects (35217) | 12 |
| Total imports | 478 |
| Unmarked objects (#2) | 888 |
| Resource objects (35217) | 1 |
| Linker (35217) | 1 |
No comments yet.