| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Aug-11 23:45:02 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Malicious | The PE contains functions mostly used by malware. |
Functions which can be used for anti-debugging purposes:
|
| Malicious | VirusTotal score: 7/70 (Scanned on 2026-08-13 22:08:44) |
APEX:
Malicious
CrowdStrike: win/malicious_confidence_60% (D) DeepInstinct: MALICIOUS Elastic: malicious (moderate confidence) Microsoft: Trojan:Win32/Wacatac.B!ml SentinelOne: Static AI - Suspicious PE Symantec: ML.Attribute.HighConfidence |
| MD5 | 6d5ffb99367a9de348aae976253b1dc3 🔍 |
|---|---|
| SHA1 | 86f51f3194b106017c15f61a71d49578f48e872b 🔍 |
| SHA256 | 8a519121a263cb7838bb9a57684f4ff8b83d1faf07e0f8d1b9f568c652b59490 🔍 |
| SHA3 | 7a24da68cd9b005016d99f6e3f50c4d8009440ae6b3dd69a2641bb7f82ae603f 🔍 |
| SSDeep | 12288:8EisVz9gYkyCe+g99weocQOmSUY8EWfS+Iia33WynZJ:85sVz9Ys+g9ijcQBZYYIijyn 🔍 |
| Imports Hash | ad52e32d4cc827b89add78c68f452510 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Aug-11 23:45:02 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x6e600 |
| SizeOfInitializedData | 0x1da00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000006DD08 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x91000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | c91469b8125b286dc3a6f84ab1977aee 🔍 |
|---|---|
| SHA1 | bb89e5c9069e1fa61000eca6f50c146a9663371f 🔍 |
| SHA256 | fb3e56976c90ec3d5a2132d9a325d34550a199fd28f3c897f6710c2762609c7d 🔍 |
| SHA3 | 1ac777ee23e5713baeed90d8571b15f224ad43993bbbe3eb8c04d8c5564007b8 🔍 |
| VirtualSize | 0x6e5d5 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x6e600 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.48853 |
| MD5 | d1b1af3273522d9eb800434e2f96687a 🔍 |
|---|---|
| SHA1 | fae2c7a5b286def8a3cbea1dfd6311e093beb9d5 🔍 |
| SHA256 | e9b66b7bdc5a78727ffcc126258a1f923f32e768936573eb96a6046a4e8129e0 🔍 |
| SHA3 | d09ef200e1d454e24d2c217f828c2016d0ec55c027847984cd038f1c679ab545 🔍 |
| VirtualSize | 0x18442 |
| VirtualAddress | 0x70000 |
| SizeOfRawData | 0x18600 |
| PointerToRawData | 0x6ea00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.32559 |
| MD5 | 195e22c3c4d2b68de6c1d84ea44ad835 🔍 |
|---|---|
| SHA1 | 31b554c9acbd592051e5cef3e7a62238d64ff113 🔍 |
| SHA256 | d075837a16e7c9709b59b168517975a8780973ae5369d4132883cd5f6e36e75b 🔍 |
| SHA3 | 679a80cae49057d02b71f5fe0e8d370943fd5f15577703c8ae61212973a1a379 🔍 |
| VirtualSize | 0x440 |
| VirtualAddress | 0x89000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x87000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 2.95821 |
| MD5 | 5f242c7efc843d672cbf31c6f61f7856 🔍 |
|---|---|
| SHA1 | e7e7a72f4d623f845e2048463c58129c7a5004ac 🔍 |
| SHA256 | 655bfdd8e559b7b6bddf04147c7842405d765f9f0641118476e5b68846e1661f 🔍 |
| SHA3 | bb880d377749d98d6facacdb5e959011bd0caef50f75029c45e139044044aba3 🔍 |
| VirtualSize | 0x46c8 |
| VirtualAddress | 0x8a000 |
| SizeOfRawData | 0x4800 |
| PointerToRawData | 0x87200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.87938 |
| MD5 | 770dc0cfd5c43c4c579d5319651b6651 🔍 |
|---|---|
| SHA1 | 2ecb03e67427a7f6e90b9843b64860693f5d7e5b 🔍 |
| SHA256 | 192f759e575c9dbaa1fd770e514f87add6ab066e1c59be1008bf98cb244fe896 🔍 |
| SHA3 | 261d614a5950c88ecf77f2317f42f018d0c7ce9313775ac8c192dc3450cca76f 🔍 |
| VirtualSize | 0x1e0 |
| VirtualAddress | 0x8f000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x8ba00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.71768 |
| MD5 | 17f701fd2ab5d5610226672fb4f168cb 🔍 |
|---|---|
| SHA1 | 2a2cf706c5e9ad8a53228877e4a18c7579cd11d2 🔍 |
| SHA256 | 7a4274c48cccc811969b2792b843c3c1ab1e7c0df411203094943c24a4a1ef56 🔍 |
| SHA3 | f7b488937e41638db318d7f34a53d6fb761600d11b2a402969706cecc0f0977a 🔍 |
| VirtualSize | 0x254 |
| VirtualAddress | 0x90000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x8bc00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 3.67988 |
| KERNEL32.dll |
Process32FirstW
CloseHandle Module32FirstW ReadProcessMemory GetModuleHandleW Module32NextW MultiByteToWideChar GetLocaleInfoA QueryPerformanceFrequency IsDBCSLeadByte QueryPerformanceCounter CreateToolhelp32Snapshot ReleaseSRWLockExclusive AcquireSRWLockExclusive SleepConditionVariableSRW Sleep GetCurrentThreadId WakeAllConditionVariable SetUnhandledExceptionFilter GetCurrentProcessId GetSystemTimeAsFileTime InitializeSListHead OpenProcess K32GetModuleFileNameExW GetProcessId Process32NextW WriteProcessMemory |
|---|---|
| USER32.dll |
GetKeyState
GetMessageExtraInfo GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow LoadCursorW SetCapture SetCursor GetClientRect IsWindowUnicode ReleaseCapture SetCursorPos DefWindowProcW DestroyWindow PostMessageA PostQuitMessage SendInput GetCursorPos UpdateWindow FindWindowA RegisterClassExW SetWindowLongW FindWindowW CreateWindowExW ScreenToClient TranslateMessage UnregisterClassW GetSystemMetrics ShowWindow GetAsyncKeyState DispatchMessageW PeekMessageW SetLayeredWindowAttributes |
| MSVCP140.dll |
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@M@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ?good@ios_base@std@@QEBA_NXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z _Query_perf_frequency ?_Throw_Cpp_error@std@@YAXH@Z ?uncaught_exceptions@std@@YAHXZ ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?_Xout_of_range@std@@YAXPEBD@Z ?_Xlength_error@std@@YAXPEBD@Z _Cnd_do_broadcast_at_thread_exit _Thrd_id _Query_perf_counter _Thrd_join ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| D3DCOMPILER_47.dll |
D3DCompile
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
memset
__C_specific_handler _CxxThrowException __current_exception __current_exception_context memcpy memcmp memchr strchr __std_terminate __std_exception_copy __std_exception_destroy memmove |
| api-ms-win-crt-runtime-l1-1-0.dll |
_get_initial_narrow_environment
_initterm _initterm_e _exit exit __p___argc __p___argv _c_exit _register_thread_local_exe_atexit_callback _seh_filter_exe _cexit _beginthreadex system _crt_atexit terminate _register_onexit_function _set_app_type _initialize_onexit_table _initialize_narrow_environment _configure_narrow_argv |
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
_set_new_mode _callnewh free |
| api-ms-win-crt-string-l1-1-0.dll |
wcslen
strcmp strlen strncmp strncpy _wcsicmp |
| api-ms-win-crt-stdio-l1-1-0.dll |
fread
__stdio_common_vsprintf _wfopen fwrite fseek fclose fflush __acrt_iob_func ftell __p__commode __stdio_common_vsscanf _set_fmode |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-convert-l1-1-0.dll |
atof
|
| api-ms-win-crt-math-l1-1-0.dll |
sqrtf
atan2f cosf fmodf log ceilf sinf logf pow powf acosf _fdclass __setusermatherr |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-11 23:45:02 |
| Version | 0.0 |
| SizeofData | 892 |
| AddressOfRawData | 0x7f0f4 |
| PointerToRawData | 0x7daf4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-11 23:45:02 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x14007f490 |
|---|---|
| EndAddressOfRawData | 0x14007f498 |
| AddressOfIndex | 0x140089250 |
| AddressOfCallbacks | 0x140070618 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140089040 |
| XOR Key | 0xdc770f0a |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 16 |
| ASM objects (35403) | 4 |
| C objects (35403) | 10 |
| C++ objects (35403) | 30 |
| Imports (35403) | 6 |
| Imports (33145) | 13 |
| Total imports | 197 |
| C++ objects (LTCG) (35724) | 7 |
| Resource objects (35724) | 1 |
| Linker (35724) | 1 |
No comments yet.