903fa81afe6144920cd116da27ba0267f1210b083bc61b2929d837c9e2fdf5b0

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Jul-13 02:50:04
Detected languages English - United States
Debug artifacts C:\Users\U_Know_69\source\repos\CCS - INT 8.51 Cheat\Build\test.pdb

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • github.com
  • https://discord.gg
  • https://files.catbox.moe
  • https://files.catbox.moe/w7afic.bin
  • https://github.com
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Possibly launches other programs:
  • ShellExecuteW
  • system
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Has Internet access capabilities:
  • URLDownloadToFileA
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 36/68 (Scanned on 2026-08-10 11:06:13) ALYac: Trojan.GenericKD.80901001
Antiy-AVL: Trojan/Win32.Agent
Arcabit: Trojan.Generic.D4D27389
Avira: TR/W64.Agent
BitDefender: Trojan.GenericKD.80901001
Bkav: W32.Malware.8E847634
CTX: dll.trojan.generic
CrowdStrike: win/malicious_confidence_60% (D)
Cynet: Malicious (score: 100)
DeepInstinct: MALICIOUS
Elastic: malicious (moderate confidence)
Emsisoft: Trojan.GenericKD.80901001 (B)
F-Secure: Trojan.TR/W64.Agent
Fortinet: W32/PossibleThreat
GData: Trojan.GenericKD.80901001
Google: Detected
Gridinsoft: Trojan.Win64.Downloader.cl
Kingsoft: Win32.TrojDownloader.agent.v
Lionic: Trojan.Win32.Generic.4!c
McAfeeD: ti!903FA81AFE61
MicroWorld-eScan: Trojan.GenericKD.80901001
Microsoft: Trojan:Win32/Wacatac.B!ml
Paloalto: generic.ml
Panda: Trj/PhxIK.A
Rising: Downloader.Agent!8.B23 (CLOUD)
SentinelOne: Static AI - Suspicious PE
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
TrellixENS: Artemis!8F7D3CDB94FD
TrendMicro: Trojan.Win32.POSSIBLETHREAT.USBLGU26
TrendMicro-HouseCall: Trojan.Win32.POSSIBLETHREAT.USBLGU26
VIPRE: Trojan.GenericKD.80901001
Varist: W64/ABTrojan.BWNN-4305
ViRobot: Trojan.Win.Z.Agent.660992.MZ
alibabacloud: Trojan:Win/Wacatac.B9nj
huorong: TrojanDownloader/Agent.bfs

Hashes

MD5 8f7d3cdb94fd80a51f543f567d149f91 🔍
SHA1 d5fc1fab478a8c109f6327907a63ab29ace13450 🔍
SHA256 903fa81afe6144920cd116da27ba0267f1210b083bc61b2929d837c9e2fdf5b0 🔍
SHA3 b9f1195f162289b3048076ef6be77d5616ad68a5798ce76b455b122499c0bf52 🔍
SSDeep 12288:0+uSCXw0FI7kq28KbGGQGcCjO4GCcW1QkRkeKakF+faY4MNVaMWLLaiidn87xE:0+uS5BJ28KyGQGcCjO4GCcW1QokxakF 🔍
Imports Hash 3347363aa4462af24765f18b753282ac 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jul-13 02:50:04
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x72600
SizeOfInitializedData 0x2fe00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000071BB0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa6000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 62fc207aa9485aec3254ab158557cd71 🔍
SHA1 cd50b4ea7538800aa6fe2a2eb51a0bb8907115c7 🔍
SHA256 d49b0ba35d969f1d01edc4c90a753dd706b72c019a11fd26439fd6eefed47cca 🔍
SHA3 ce1ca6cbb93e4489e6397a10e9b40b6927914cac0538770cd3559df80dd14b46 🔍
VirtualSize 0x725c5
VirtualAddress 0x1000
SizeOfRawData 0x72600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.49635

.rdata

MD5 d5348755d6bd657658387a9a13336e73 🔍
SHA1 71de2995fda37e906a7c0d81cd8e4903d38cf99d 🔍
SHA256 b014fe67ecf478a8ecc0e43bf3b598f975617a599c548382f67d7a5c270b04d6 🔍
SHA3 8b2533580a47705053d3ad109333a1dd0fc61335105af58ff4290fe01e69edfc 🔍
VirtualSize 0x25cd6
VirtualAddress 0x74000
SizeOfRawData 0x25e00
PointerToRawData 0x72a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.52661

.data

MD5 f9e760c2b8be7e816c81e3f61c08acec 🔍
SHA1 29dbe0e9817b8905bcd767071161374054173892 🔍
SHA256 a3ccb48cd280228dc4d099ceaf19346663bc137d40edae97d25484558ee76610 🔍
SHA3 2ff2d3dd19cc7a2f4f360781df74350979e14c1b527141f84b448442250d9b4c 🔍
VirtualSize 0x3ff8
VirtualAddress 0x9a000
SizeOfRawData 0x2e00
PointerToRawData 0x98800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.42848

.pdata

MD5 b14797332c51d349a3113d67b26e7d6e 🔍
SHA1 627e8dff636dde1724dcd6a1a59a731c6e7e6a6b 🔍
SHA256 dddfc70ae019af9052b8b335fed38e63ed72c67003e4301b1368e52a77920d0a 🔍
SHA3 cc464d21bd4ca04a6c867ddcefb0cf6fb27818712e0024fb763ca1f416136a2e 🔍
VirtualSize 0x58e0
VirtualAddress 0x9e000
SizeOfRawData 0x5a00
PointerToRawData 0x9b600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.8916

.rsrc

MD5 e8644f91505b58fb4a45889cb2c3b6fe 🔍
SHA1 dd9fd560d4abc11d484beb5344430eb0cdb9e919 🔍
SHA256 aaf4de0aaf9420c90b31b308dd4b313727c3081ff553f87bcd60cea90af847ac 🔍
SHA3 33be8df783cf5f9059ab61500db3d1d66c6d4a0edd74a28dc04ee7e6b902039e 🔍
VirtualSize 0x1e0
VirtualAddress 0xa4000
SizeOfRawData 0x200
PointerToRawData 0xa1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.71529

.reloc

MD5 eea0ea3b679adf080f3012060c2e68cf 🔍
SHA1 a48787dd7cc197b6303255bee6f270d62245cba8 🔍
SHA256 ada1b88f9b1346058902049f0beed31fd0a11b8ff78c4a9a10fd2127b7cbabf0 🔍
SHA3 6d833b9566a7bf20f46d99dd74bc5da94780db2cc36bfce0f60f3946ad200361 🔍
VirtualSize 0x358
VirtualAddress 0xa5000
SizeOfRawData 0x400
PointerToRawData 0xa1200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.84799

Imports

urlmon.dll URLDownloadToFileA
d3d11.dll D3D11CreateDeviceAndSwapChain
KERNEL32.dll CreateThread
Beep
GetCurrentProcessId
WideCharToMultiByte
IsBadReadPtr
GetTickCount
VirtualFree
GetSystemInfo
VirtualQuery
HeapCreate
HeapFree
GetCurrentProcess
Thread32Next
Thread32First
GetCurrentThreadId
SuspendThread
ResumeThread
CreateToolhelp32Snapshot
HeapReAlloc
CloseHandle
HeapAlloc
GetThreadContext
GetProcAddress
GetModuleHandleW
FlushInstructionCache
SetThreadContext
VirtualAlloc
OutputDebugStringA
DisableThreadLibraryCalls
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
GetLocaleInfoA
QueryPerformanceFrequency
IsDBCSLeadByte
QueryPerformanceCounter
VirtualProtect
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
CreateEventW
WaitForSingleObjectEx
ResetEvent
SetEvent
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
LeaveCriticalSection
EnterCriticalSection
GetSystemTimeAsFileTime
LoadLibraryA
GetTempPathA
Sleep
MultiByteToWideChar
GetModuleHandleA
InitializeSListHead
OpenThread
USER32.dll GetKeyState
CallWindowProcW
GetMessageExtraInfo
LoadCursorA
GetCapture
DefWindowProcW
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
SetCapture
SetCursor
GetClientRect
IsWindowUnicode
ReleaseCapture
ClientToScreen
SetCursorPos
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
GetWindowThreadProcessId
GetWindow
DestroyWindow
GetCursorPos
RegisterClassExA
IsWindowVisible
SetWindowLongPtrW
ScreenToClient
IsWindow
GetAsyncKeyState
EnumWindows
DefWindowProcA
CreateWindowExA
UnregisterClassA
SHELL32.dll ShellExecuteW
MSVCP140D.dll ?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z
?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??Bid@locale@std@@QEAA_KXZ
?_Xbad_alloc@std@@YAXXZ
?always_noconv@codecvt_base@std@@QEBA_NXZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Xout_of_range@std@@YAXPEBD@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?_Xlength_error@std@@YAXPEBD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
IMM32.dll ImmSetCandidateWindow
ImmReleaseContext
ImmGetContext
ImmSetCompositionWindow
D3DCOMPILER_47.dll D3DCompile
VCRUNTIME140_1D.dll __CxxFrameHandler4
VCRUNTIME140D.dll _CxxThrowException
strchr
__std_terminate
__std_exception_copy
__std_exception_destroy
__C_specific_handler
memchr
memcmp
memmove
__std_type_info_destroy_list
memcpy
memset
ucrtbased.dll _get_stream_buffer_pointers
ftell
__acrt_iob_func
fseek
__stdio_common_vfprintf
qsort
strncpy
_wfopen
__stdio_common_vsprintf
free
__stdio_common_vsscanf
_wassert
malloc
strncmp
atof
_free_dbg
_malloc_dbg
_CrtDbgReportW
_callnewh
_seh_filter_dll
_configure_narrow_argv
_initialize_narrow_environment
fread
_register_onexit_function
_execute_onexit_table
_crt_atexit
_cexit
_initterm
_initterm_e
sinf
fgetc
__stdio_common_vsprintf_s
strtoul
wcscpy_s
strncpy_s
fclose
fflush
_invalid_parameter
__stdio_common_vswprintf_s
fputc
_CrtDbgReport
fsetpos
ungetc
setvbuf
_fseeki64
system
fwrite
sqrtf
_lock_file
_initialize_onexit_table
_unlock_file
strcmp
fgetpos
acosf
ceilf
cosf
fmodf
logf
pow
powf

Delayed Imports

2

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jul-13 02:50:04
Version 0.0
SizeofData 92
AddressOfRawData 0x8ed84
PointerToRawData 0x8d784
Referenced File C:\Users\U_Know_69\source\repos\CCS - INT 8.51 Cheat\Build\test.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jul-13 02:50:04
Version 0.0
SizeofData 20
AddressOfRawData 0x8ede0
PointerToRawData 0x8d7e0

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-13 02:50:04
Version 0.0
SizeofData 872
AddressOfRawData 0x8edf4
PointerToRawData 0x8d7f4

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jul-13 02:50:04
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x18008f180
EndAddressOfRawData 0x18008f188
AddressOfIndex 0x18009d23c
AddressOfCallbacks 0x180074770
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x18009a010

RICH Header

XOR Key 0xa91b4a6f
Unmarked objects 0
C objects (30034) 8
ASM objects (30034) 4
C++ objects (30034) 21
Imports (30034) 6
Imports (35215) 21
Total imports 247
C++ objects (LTCG) (30159) 17
Resource objects (30159) 1
Linker (30159) 1

Errors

Leave a comment

No comments yet.