86a52dca75c2b349fc7db2cc7371b4060f1df21e406ac38fd72b1f605d4d9665

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Mar-06 12:03:06
Detected languages English - United States
Debug artifacts C:\Users\atlas\Downloads\Fang Source Fixed\Build\Addition.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Interesting strings found in the binary: Contains domain names:
  • fontstruct.com
  • http://www.microsoft.com
  • http://www.microsoft.com/truetype/0
  • http://www.microsoft.com/typographyNormalNormaaliNormalNorm
  • https://fontstruct.com
  • https://fontstruct.comparasiticSpong
  • https://fontstruct.comparasiticSponge
  • https://www.verisign.com
  • https://www.verisign.com/CPS
  • https://www.verisign.com/repository/CPS
  • https://www.verisign.com/repository/RPA0
  • https://www.verisign.com/repository/verisignlogo.gif0
  • microsoft.com
  • verisign.com
  • www.microsoft.com
  • www.verisign.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • FindWindowA
  • CreateToolhelp32Snapshot
Code injection capabilities:
  • VirtualAllocEx
  • OpenProcess
  • WriteProcessMemory
Possibly launches other programs:
  • ShellExecuteW
  • system
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • GetForegroundWindow
Manipulates other processes:
  • Process32Next
  • OpenProcess
  • Process32First
  • WriteProcessMemory
  • ReadProcessMemory
Can take screenshots:
  • FindWindowA
  • GetDC
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 43/70 (Scanned on 2026-08-25 03:47:32) ALYac: Gen:Variant.Tedy.924155
APEX: Malicious
AVG: Win64:MalwareX-gen [Misc]
AhnLab-V3: Trojan/Win.Generic.R780802
Alibaba: Trojan:Win64/GenKryptik.b9a44e33
Antiy-AVL: Trojan/Win32.Convagent
Arcabit: Trojan.Tedy.DE19FB
Avast: Win64:MalwareX-gen [Misc]
Avira: TR/W64.Agent
BitDefender: Gen:Variant.Tedy.924155
Bkav: W32.Malware.DDD5BF78
CTX: exe.trojan.convagent
CrowdStrike: win/malicious_confidence_70% (W)
Cylance: Unsafe
Cynet: Malicious (score: 99)
DeepInstinct: MALICIOUS
ESET-NOD32: Win64/GenKryptik_AGen.CLY trojan
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Tedy.924155 (B)
F-Secure: Trojan.TR/W64.Agent
Fortinet: W64/MALD2.DB13!tr
GData: Gen:Variant.Tedy.924155
Google: Detected
Gridinsoft: Trojan.Win64.Agent.oa!s1
Lionic: Trojan.Win32.Convagent.4!c
Malwarebytes: Malware.AI.3883692123
MaxSecure: Trojan.Malware.338148470.susgen
McAfeeD: ti!86A52DCA75C2
MicroWorld-eScan: Gen:Variant.Tedy.924155
Microsoft: Trojan:Win32/Wacatac.B!ml
Paloalto: generic.ml
Rising: Trojan.Convagent!8.12323 (CLOUD)
SentinelOne: Static AI - Malicious PE
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
Tencent: Malware.Win32.Gencirc.14ab5b02
Trapmine: suspicious.low.ml.score
TrellixENS: Artemis!201702C37D30
VBA32: Trojan.Convagent
VIPRE: Gen:Variant.Tedy.924155
Varist: W64/ABTrojan.VPPY-8167
ViRobot: Trojan.Win.Z.Lazy.1502720
alibabacloud: Trojan:Win/Sabsik.ET

Hashes

MD5 201702c37d308767e4fa3c4c103970f9 🔍
SHA1 12019663ab5a4461f87ad85c23f3cebf9cb08745 🔍
SHA256 86a52dca75c2b349fc7db2cc7371b4060f1df21e406ac38fd72b1f605d4d9665 🔍
SHA3 73869f149e68d7372caef4381ef4774985f483bef2b49eed32257fca6c7ac7af 🔍
SSDeep 24576:OGeXdNW8sBw698zXRYHT2XPuMcf2SUF4parIfIaBQjK9/CaZ+iZnbZNLOk1nqMJ:OGeqNYjZPuMc/LMaqK95ZnHLOkNNtUs 🔍
Imports Hash 0fbf2117258fef2d70248b31c3ef3313 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Mar-06 12:03:06
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xe5e00
SizeOfInitializedData 0x89400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000E45D0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x172000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 362d0eeeee436f2c61c54350e87e2ecb 🔍
SHA1 4cdc60f89519564ed3cc0d84c27be03debbb96bc 🔍
SHA256 87899d96a92a0a04a933a9c68cc3d1c939263fd79ddb20c1c55ff8ce9bebbeaa 🔍
SHA3 eb97fc5ac08086ac2dd070548752169973cf8f58f753a1d949a353cd7a9a614b 🔍
VirtualSize 0xe5d62
VirtualAddress 0x1000
SizeOfRawData 0xe5e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.50553

.rdata

MD5 c4c0bb6e78e3364e004b12f136853ef7 🔍
SHA1 c73c1174aed84563bcb0c3da59543746e26219fc 🔍
SHA256 5f8e0072fed71726a369ebd17aedc2792516a50d86a5286bda9f1bdf3780d7ac 🔍
SHA3 460a18eb58a473be669269455f0f68ae1c06739eea07531f37261e38c7fb60a3 🔍
VirtualSize 0x38f48
VirtualAddress 0xe7000
SizeOfRawData 0x39000
PointerToRawData 0xe6200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.25283

.data

MD5 61469d75da3ce7bd0c974289dfdb5e03 🔍
SHA1 843f0f21a2e467e1d9274d6182c0a7941c071bb2 🔍
SHA256 4e8e175d3cded3304afee25624c15d0cf55d587cf80d8f3bb94e758c24936e3b 🔍
SHA3 4330a35ae13d13215dd46f4dccb0f2152a01af920f6cf23f51925543407ce06f 🔍
VirtualSize 0x449e0
VirtualAddress 0x120000
SizeOfRawData 0x44200
PointerToRawData 0x11f200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.81868

.pdata

MD5 43b857785d0e71834ef7ac58ac695089 🔍
SHA1 461427bb14d00303cc2fe2f37cfadb26c067e7e7 🔍
SHA256 05e448e30593f8da3c9947595ae0bb2201a08a58fe6f4929ef27d62e818cef04 🔍
SHA3 c9573591d99300fbff606ce32bf93f477221a07a7d69c030e5b63a4d2edb2603 🔍
VirtualSize 0xa938
VirtualAddress 0x165000
SizeOfRawData 0xaa00
PointerToRawData 0x163400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.08859

.rsrc

MD5 c1b18cca1fb89dbfcb908da8e42f27d5 🔍
SHA1 3e330e173459666cb4bb4e61a56ef28537e7b51e 🔍
SHA256 0d30844e784c626f4653aed41713c0b4af39ec49ce6a12965992a3e83c214650 🔍
SHA3 ec77fe459d24003b65fa5215be946d6f4ac71f4106013793d4640509139fecb8 🔍
VirtualSize 0x1e8
VirtualAddress 0x170000
SizeOfRawData 0x200
PointerToRawData 0x16de00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.75615

.reloc

MD5 06f9604de75b3daa70545e660b239b78 🔍
SHA1 b61dd753bd00b4439f07e69c960ee48bc065cf94 🔍
SHA256 d8d3ac652474ff25aff2d12d4eb63fdaeb95620a03ca70d06e7fe2931a16c1e8 🔍
SHA3 71bc49612a169274d5a9ac66d0167eeaa9fad14c21caa5ab2f44c9403bfcae80 🔍
VirtualSize 0xd1c
VirtualAddress 0x171000
SizeOfRawData 0xe00
PointerToRawData 0x16e000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.30402

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
D3DCOMPILER_47.dll D3DCompile
MSVCP140.dll _Query_perf_frequency
?_Throw_Cpp_error@std@@YAXH@Z
_Mtx_lock
_Cnd_do_broadcast_at_thread_exit
_Query_perf_counter
_Thrd_detach
?_Xout_of_range@std@@YAXPEBD@Z
_Mtx_unlock
?_Xlength_error@std@@YAXPEBD@Z
GDI32.dll GetDeviceCaps
dwmapi.dll DwmExtendFrameIntoClientArea
USER32.dll PostQuitMessage
RegisterClassExA
UpdateWindow
IsIconic
mouse_event
GetAsyncKeyState
FindWindowA
SendInput
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
GetKeyState
GetMessageExtraInfo
LoadCursorA
SetLayeredWindowAttributes
PeekMessageA
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
SetCapture
SetCursor
GetClientRect
IsWindowUnicode
ReleaseCapture
SetCursorPos
ReleaseDC
GetCursorPos
CreateWindowExA
DefWindowProcA
MoveWindow
UnregisterClassA
MessageBoxA
TranslateMessage
SetWindowDisplayAffinity
MonitorFromPoint
SetWindowLongA
ShowWindow
GetSystemMetrics
IsWindowVisible
DestroyWindow
GetWindowRect
DispatchMessageA
GetDC
KERNEL32.dll GetCurrentProcessId
GetSystemTimeAsFileTime
IsProcessorFeaturePresent
TerminateProcess
GetCurrentProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
InitializeSListHead
IsDebuggerPresent
GetModuleHandleW
GetCurrentThreadId
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
WakeAllConditionVariable
SleepConditionVariableSRW
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
CreateFileMappingA
UnmapViewOfFile
MapViewOfFile
HeapFree
HeapAlloc
ReadFile
GetFileSizeEx
CreateFileA
SetConsoleTitleA
VirtualAllocEx
CloseHandle
Process32Next
CreateToolhelp32Snapshot
OpenProcess
Module32First
GetProcessId
Module32Next
Process32First
GetCurrentThread
SetThreadPriority
WriteProcessMemory
Sleep
ReadProcessMemory
GetConsoleMode
SetConsoleMode
GetStdHandle
GlobalUnlock
WideCharToMultiByte
GlobalLock
GlobalFree
GlobalAlloc
QueryPerformanceCounter
FreeLibrary
VerSetConditionMask
GetProcAddress
QueryPerformanceFrequency
LoadLibraryA
MultiByteToWideChar
GetLocaleInfoA
GetModuleHandleA
SHELL32.dll ShellExecuteW
IMM32.dll ImmSetCandidateWindow
ImmGetContext
ImmReleaseContext
ImmSetCompositionWindow
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __C_specific_handler
memcmp
memchr
__current_exception
_CxxThrowException
__intrinsic_setjmp
memset
__std_exception_destroy
__std_exception_copy
__std_terminate
strstr
strrchr
longjmp
memcpy
memmove
__current_exception_context
api-ms-win-crt-heap-l1-1-0.dll _callnewh
_set_new_mode
malloc
free
api-ms-win-crt-runtime-l1-1-0.dll system
terminate
_invoke_watson
_beginthreadex
_register_thread_local_exe_atexit_callback
_c_exit
__p___argv
__p___argc
_exit
exit
_initterm_e
_initterm
_get_initial_narrow_environment
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_cexit
_seh_filter_exe
_set_app_type
api-ms-win-crt-math-l1-1-0.dll acosf
atan2f
sinf
ceilf
nearbyint
cosf
logf
log
__setusermatherr
fmodf
sqrtf
pow
_fdclass
powf
roundf
api-ms-win-crt-stdio-l1-1-0.dll __stdio_common_vsscanf
ftell
__acrt_iob_func
fflush
fclose
_set_fmode
fseek
fread
fwrite
__p__commode
__stdio_common_vsprintf
_wfopen
__stdio_common_vfprintf
api-ms-win-crt-utility-l1-1-0.dll rand
qsort
api-ms-win-crt-string-l1-1-0.dll _stricmp
tolower
strcmp
strncmp
strncpy
api-ms-win-crt-convert-l1-1-0.dll strtol
atof
api-ms-win-crt-time-l1-1-0.dll strftime
_localtime64_s
_time64
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b 🔍
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Mar-06 12:03:06
Version 0.0
SizeofData 86
AddressOfRawData 0x10dc10
PointerToRawData 0x10ce10
Referenced File C:\Users\atlas\Downloads\Fang Source Fixed\Build\Addition.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Mar-06 12:03:06
Version 0.0
SizeofData 20
AddressOfRawData 0x10dc68
PointerToRawData 0x10ce68

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Mar-06 12:03:06
Version 0.0
SizeofData 892
AddressOfRawData 0x10dc7c
PointerToRawData 0x10ce7c

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Mar-06 12:03:06
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x14010e018
EndAddressOfRawData 0x14010e020
AddressOfIndex 0x1401645f8
AddressOfCallbacks 0x1400e77f0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140120040

RICH Header

XOR Key 0x40be4759
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 20
253 (35207) 1
ASM objects (35207) 4
C objects (35207) 10
C++ objects (35207) 37
Imports (35207) 6
C objects (VS2022 Update 4 (17.4.5) compiler 31942) 26
Imports (33145) 17
Total imports 236
C++ objects (LTCG) (35222) 30
ASM objects (35222) 1
Resource objects (35222) 1
151 1
Linker (35222) 1

Errors

Leave a comment

No comments yet.