| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Mar-06 12:03:06 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\atlas\Downloads\Fang Source Fixed\Build\Addition.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 43/70 (Scanned on 2026-08-25 03:47:32) |
ALYac:
Gen:Variant.Tedy.924155
APEX: Malicious AVG: Win64:MalwareX-gen [Misc] AhnLab-V3: Trojan/Win.Generic.R780802 Alibaba: Trojan:Win64/GenKryptik.b9a44e33 Antiy-AVL: Trojan/Win32.Convagent Arcabit: Trojan.Tedy.DE19FB Avast: Win64:MalwareX-gen [Misc] Avira: TR/W64.Agent BitDefender: Gen:Variant.Tedy.924155 Bkav: W32.Malware.DDD5BF78 CTX: exe.trojan.convagent CrowdStrike: win/malicious_confidence_70% (W) Cylance: Unsafe Cynet: Malicious (score: 99) DeepInstinct: MALICIOUS ESET-NOD32: Win64/GenKryptik_AGen.CLY trojan Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Tedy.924155 (B) F-Secure: Trojan.TR/W64.Agent Fortinet: W64/MALD2.DB13!tr GData: Gen:Variant.Tedy.924155 Google: Detected Gridinsoft: Trojan.Win64.Agent.oa!s1 Lionic: Trojan.Win32.Convagent.4!c Malwarebytes: Malware.AI.3883692123 MaxSecure: Trojan.Malware.338148470.susgen McAfeeD: ti!86A52DCA75C2 MicroWorld-eScan: Gen:Variant.Tedy.924155 Microsoft: Trojan:Win32/Wacatac.B!ml Paloalto: generic.ml Rising: Trojan.Convagent!8.12323 (CLOUD) SentinelOne: Static AI - Malicious PE Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence Tencent: Malware.Win32.Gencirc.14ab5b02 Trapmine: suspicious.low.ml.score TrellixENS: Artemis!201702C37D30 VBA32: Trojan.Convagent VIPRE: Gen:Variant.Tedy.924155 Varist: W64/ABTrojan.VPPY-8167 ViRobot: Trojan.Win.Z.Lazy.1502720 alibabacloud: Trojan:Win/Sabsik.ET |
| MD5 | 201702c37d308767e4fa3c4c103970f9 🔍 |
|---|---|
| SHA1 | 12019663ab5a4461f87ad85c23f3cebf9cb08745 🔍 |
| SHA256 | 86a52dca75c2b349fc7db2cc7371b4060f1df21e406ac38fd72b1f605d4d9665 🔍 |
| SHA3 | 73869f149e68d7372caef4381ef4774985f483bef2b49eed32257fca6c7ac7af 🔍 |
| SSDeep | 24576:OGeXdNW8sBw698zXRYHT2XPuMcf2SUF4parIfIaBQjK9/CaZ+iZnbZNLOk1nqMJ:OGeqNYjZPuMc/LMaqK95ZnHLOkNNtUs 🔍 |
| Imports Hash | 0fbf2117258fef2d70248b31c3ef3313 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Mar-06 12:03:06 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xe5e00 |
| SizeOfInitializedData | 0x89400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000E45D0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x172000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 362d0eeeee436f2c61c54350e87e2ecb 🔍 |
|---|---|
| SHA1 | 4cdc60f89519564ed3cc0d84c27be03debbb96bc 🔍 |
| SHA256 | 87899d96a92a0a04a933a9c68cc3d1c939263fd79ddb20c1c55ff8ce9bebbeaa 🔍 |
| SHA3 | eb97fc5ac08086ac2dd070548752169973cf8f58f753a1d949a353cd7a9a614b 🔍 |
| VirtualSize | 0xe5d62 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0xe5e00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.50553 |
| MD5 | c4c0bb6e78e3364e004b12f136853ef7 🔍 |
|---|---|
| SHA1 | c73c1174aed84563bcb0c3da59543746e26219fc 🔍 |
| SHA256 | 5f8e0072fed71726a369ebd17aedc2792516a50d86a5286bda9f1bdf3780d7ac 🔍 |
| SHA3 | 460a18eb58a473be669269455f0f68ae1c06739eea07531f37261e38c7fb60a3 🔍 |
| VirtualSize | 0x38f48 |
| VirtualAddress | 0xe7000 |
| SizeOfRawData | 0x39000 |
| PointerToRawData | 0xe6200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.25283 |
| MD5 | 61469d75da3ce7bd0c974289dfdb5e03 🔍 |
|---|---|
| SHA1 | 843f0f21a2e467e1d9274d6182c0a7941c071bb2 🔍 |
| SHA256 | 4e8e175d3cded3304afee25624c15d0cf55d587cf80d8f3bb94e758c24936e3b 🔍 |
| SHA3 | 4330a35ae13d13215dd46f4dccb0f2152a01af920f6cf23f51925543407ce06f 🔍 |
| VirtualSize | 0x449e0 |
| VirtualAddress | 0x120000 |
| SizeOfRawData | 0x44200 |
| PointerToRawData | 0x11f200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 6.81868 |
| MD5 | 43b857785d0e71834ef7ac58ac695089 🔍 |
|---|---|
| SHA1 | 461427bb14d00303cc2fe2f37cfadb26c067e7e7 🔍 |
| SHA256 | 05e448e30593f8da3c9947595ae0bb2201a08a58fe6f4929ef27d62e818cef04 🔍 |
| SHA3 | c9573591d99300fbff606ce32bf93f477221a07a7d69c030e5b63a4d2edb2603 🔍 |
| VirtualSize | 0xa938 |
| VirtualAddress | 0x165000 |
| SizeOfRawData | 0xaa00 |
| PointerToRawData | 0x163400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.08859 |
| MD5 | c1b18cca1fb89dbfcb908da8e42f27d5 🔍 |
|---|---|
| SHA1 | 3e330e173459666cb4bb4e61a56ef28537e7b51e 🔍 |
| SHA256 | 0d30844e784c626f4653aed41713c0b4af39ec49ce6a12965992a3e83c214650 🔍 |
| SHA3 | ec77fe459d24003b65fa5215be946d6f4ac71f4106013793d4640509139fecb8 🔍 |
| VirtualSize | 0x1e8 |
| VirtualAddress | 0x170000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x16de00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.75615 |
| MD5 | 06f9604de75b3daa70545e660b239b78 🔍 |
|---|---|
| SHA1 | b61dd753bd00b4439f07e69c960ee48bc065cf94 🔍 |
| SHA256 | d8d3ac652474ff25aff2d12d4eb63fdaeb95620a03ca70d06e7fe2931a16c1e8 🔍 |
| SHA3 | 71bc49612a169274d5a9ac66d0167eeaa9fad14c21caa5ab2f44c9403bfcae80 🔍 |
| VirtualSize | 0xd1c |
| VirtualAddress | 0x171000 |
| SizeOfRawData | 0xe00 |
| PointerToRawData | 0x16e000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.30402 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| D3DCOMPILER_47.dll |
D3DCompile
|
| MSVCP140.dll |
_Query_perf_frequency
?_Throw_Cpp_error@std@@YAXH@Z _Mtx_lock _Cnd_do_broadcast_at_thread_exit _Query_perf_counter _Thrd_detach ?_Xout_of_range@std@@YAXPEBD@Z _Mtx_unlock ?_Xlength_error@std@@YAXPEBD@Z |
| GDI32.dll |
GetDeviceCaps
|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| USER32.dll |
PostQuitMessage
RegisterClassExA UpdateWindow IsIconic mouse_event GetAsyncKeyState FindWindowA SendInput OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData GetKeyState GetMessageExtraInfo LoadCursorA SetLayeredWindowAttributes PeekMessageA ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow SetCapture SetCursor GetClientRect IsWindowUnicode ReleaseCapture SetCursorPos ReleaseDC GetCursorPos CreateWindowExA DefWindowProcA MoveWindow UnregisterClassA MessageBoxA TranslateMessage SetWindowDisplayAffinity MonitorFromPoint SetWindowLongA ShowWindow GetSystemMetrics IsWindowVisible DestroyWindow GetWindowRect DispatchMessageA GetDC |
| KERNEL32.dll |
GetCurrentProcessId
GetSystemTimeAsFileTime IsProcessorFeaturePresent TerminateProcess GetCurrentProcess SetUnhandledExceptionFilter UnhandledExceptionFilter InitializeSListHead IsDebuggerPresent GetModuleHandleW GetCurrentThreadId RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext WakeAllConditionVariable SleepConditionVariableSRW AcquireSRWLockExclusive ReleaseSRWLockExclusive CreateFileMappingA UnmapViewOfFile MapViewOfFile HeapFree HeapAlloc ReadFile GetFileSizeEx CreateFileA SetConsoleTitleA VirtualAllocEx CloseHandle Process32Next CreateToolhelp32Snapshot OpenProcess Module32First GetProcessId Module32Next Process32First GetCurrentThread SetThreadPriority WriteProcessMemory Sleep ReadProcessMemory GetConsoleMode SetConsoleMode GetStdHandle GlobalUnlock WideCharToMultiByte GlobalLock GlobalFree GlobalAlloc QueryPerformanceCounter FreeLibrary VerSetConditionMask GetProcAddress QueryPerformanceFrequency LoadLibraryA MultiByteToWideChar GetLocaleInfoA GetModuleHandleA |
| SHELL32.dll |
ShellExecuteW
|
| IMM32.dll |
ImmSetCandidateWindow
ImmGetContext ImmReleaseContext ImmSetCompositionWindow |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__C_specific_handler
memcmp memchr __current_exception _CxxThrowException __intrinsic_setjmp memset __std_exception_destroy __std_exception_copy __std_terminate strstr strrchr longjmp memcpy memmove __current_exception_context |
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
_set_new_mode malloc free |
| api-ms-win-crt-runtime-l1-1-0.dll |
system
terminate _invoke_watson _beginthreadex _register_thread_local_exe_atexit_callback _c_exit __p___argv __p___argc _exit exit _initterm_e _initterm _get_initial_narrow_environment _configure_narrow_argv _initialize_narrow_environment _initialize_onexit_table _register_onexit_function _crt_atexit _cexit _seh_filter_exe _set_app_type |
| api-ms-win-crt-math-l1-1-0.dll |
acosf
atan2f sinf ceilf nearbyint cosf logf log __setusermatherr fmodf sqrtf pow _fdclass powf roundf |
| api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vsscanf
ftell __acrt_iob_func fflush fclose _set_fmode fseek fread fwrite __p__commode __stdio_common_vsprintf _wfopen __stdio_common_vfprintf |
| api-ms-win-crt-utility-l1-1-0.dll |
rand
qsort |
| api-ms-win-crt-string-l1-1-0.dll |
_stricmp
tolower strcmp strncmp strncpy |
| api-ms-win-crt-convert-l1-1-0.dll |
strtol
atof |
| api-ms-win-crt-time-l1-1-0.dll |
strftime
_localtime64_s _time64 |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x188 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.89623 |
| MD5 | b8e76ddb52d0eb41e972599ff3ca431b 🔍 |
| SHA1 | fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍 |
| SHA256 | 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍 |
| SHA3 | 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-06 12:03:06 |
| Version | 0.0 |
| SizeofData | 86 |
| AddressOfRawData | 0x10dc10 |
| PointerToRawData | 0x10ce10 |
| Referenced File | C:\Users\atlas\Downloads\Fang Source Fixed\Build\Addition.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-06 12:03:06 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x10dc68 |
| PointerToRawData | 0x10ce68 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-06 12:03:06 |
| Version | 0.0 |
| SizeofData | 892 |
| AddressOfRawData | 0x10dc7c |
| PointerToRawData | 0x10ce7c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-06 12:03:06 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x14010e018 |
|---|---|
| EndAddressOfRawData | 0x14010e020 |
| AddressOfIndex | 0x1401645f8 |
| AddressOfCallbacks | 0x1400e77f0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140120040 |
| XOR Key | 0x40be4759 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 20 |
| 253 (35207) | 1 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 37 |
| Imports (35207) | 6 |
| C objects (VS2022 Update 4 (17.4.5) compiler 31942) | 26 |
| Imports (33145) | 17 |
| Total imports | 236 |
| C++ objects (LTCG) (35222) | 30 |
| ASM objects (35222) | 1 |
| Resource objects (35222) | 1 |
| 151 | 1 |
| Linker (35222) | 1 |
No comments yet.