| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Aug-11 21:37:15 |
| Detected languages |
English - United States
|
| Suspicious | The PE contains functions most legitimate programs don't use. |
Can take screenshots:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xc8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 5 |
| TimeDateStamp | 2026-Aug-11 21:37:15 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xa200 |
| SizeOfInitializedData | 0xdef0a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000001000 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xdeff000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetFileSize
WriteFile ReadFile GetModuleHandleA CloseHandle GetModuleFileNameA QueryPerformanceFrequency QueryPerformanceCounter ExitProcess CreateFileA |
|---|---|
| USER32.dll |
RegisterClassExA
CreateWindowExA DefWindowProcA PeekMessageA TranslateMessage DispatchMessageA PostQuitMessage DestroyWindow GetDC ReleaseDC LoadCursorA GetClientRect ClientToScreen GetCursorPos GetWindowRect GetSystemMetrics SetWindowPos SetWindowLongPtrA GetWindowLongPtrA ScreenToClient ShowCursor SetCursorPos |
| GDI32.dll |
CreateFontA
SetPixelFormat SwapBuffers CreateCompatibleDC CreateDIBSection SelectObject SetTextColor SetBkMode SetBkColor TextOutA DeleteDC PatBlt ChoosePixelFormat |
| OPENGL32.dll |
glScissor
glNormal3f glLightfv glTexCoord2f glTexParameteri glTexImage2D glBindTexture glGenTextures glBlendFunc glLineWidth glColor4f glColor3f glVertex3f glEnd glBegin glRotatef glTranslatef glOrtho glFrustum glViewport glPopMatrix glPushMatrix glClearColor wglCreateContext wglMakeCurrent wglDeleteContext wglGetProcAddress glMatrixMode glClear glEnable glDisable glLoadIdentity |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-11 21:37:15 |
| Version | 0.0 |
| SizeofData | 276 |
| AddressOfRawData | 0xc2d8 |
| PointerToRawData | 0xa8d8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-11 21:37:15 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| XOR Key | 0xaf564c93 |
|---|---|
| Unmarked objects | 0 |
| Imports (33145) | 9 |
| Total imports | 77 |
| Unmarked objects (#2) | 1 |
| Resource objects (35228) | 1 |
| Linker (35228) | 1 |
No comments yet.