9b9bb4416631666372cf343f2a92b94f06a4a3f00cf1f6db30917e2e6f6a978e

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Sep-27 12:13:30
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.
Debug artifacts vesta.pdb

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to security software:
  • rshell.exe
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • EyeAndDistance.xyz
  • Tangent.xyz
  • github.com
  • google.com
  • http://www.google.com
  • http://www.google.com/get/noto/http
  • http://www.monotype.com
  • http://www.monotype.com/studioThis
  • https://github.com
  • https://scripts.sil.org
  • https://scripts.sil.org/OFLNoto
  • https://scripts.sil.org/OFLhttps
  • input.Tangent.xyz
  • monotype.com
  • scripts.sil.org
  • skinned.xyz
  • www.google.com
  • www.monotype.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA1
Uses constants related to RC5 or RC6
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExA
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
  • CreateToolhelp32Snapshot
  • FindWindowW
Can access the registry:
  • RegQueryValueExA
  • RegOpenKeyExA
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessAsUserW
  • CreateProcessW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
  • CreateFileA
Uses functions commonly found in keyloggers:
  • CallNextHookEx
  • MapVirtualKeyW
  • GetForegroundWindow
  • GetAsyncKeyState
Functions related to the privilege level:
  • OpenProcessToken
  • DuplicateTokenEx
Manipulates other processes:
  • Process32FirstW
  • OpenProcess
  • Process32NextW
  • ReadProcessMemory
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 19/71 (Scanned on 2026-09-27 15:15:02) ALYac: Gen:Variant.Yogi.38273
APEX: Malicious
AhnLab-V3: Trojan/Win.Generic.R793444
Arcabit: Trojan.Yogi.D9581
BitDefender: Gen:Variant.Yogi.38273
Bkav: W32.Malware.AD741302
CTX: exe.unknown.yogi
ESET-NOD32: Win64/GenKryptik_AGen.EZE trojan
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Yogi.38273 (B)
GData: Gen:Variant.Yogi.38273
Google: Detected
Ikarus: Trojan-PSW.Agent
Malwarebytes: Malware.AI.1147289918
MicroWorld-eScan: Gen:Variant.Yogi.38273
Microsoft: Trojan:Win32/Wacatac.B!ml
Rising: Trojan.Kryptik@AI.100 (RDML:Am8j/f7nKG1I3AIDNGNxXA)
Symantec: ML.Attribute.HighConfidence
VIPRE: Gen:Variant.Yogi.38273

Hashes

MD5 43df62faec84e53e9b5e2f7e0f939cc8 🔍
SHA1 0311d0067183da37ae8c8760068485bbe93b385c 🔍
SHA256 9b9bb4416631666372cf343f2a92b94f06a4a3f00cf1f6db30917e2e6f6a978e 🔍
SHA3 9820826c94e25311ff3da0f005fcc9fd34caae87e57570e87df91d5225f47d23 🔍
SSDeep 49152:WhTKPypxi2Li0mPiJI7BZVKO7WyVnN2PbsFyi7p9lXDMKw4nD6YHNThy0TeAOo1:WhOCLO7KbsFH19lVeAOo7/u 🔍
Imports Hash 2428a5bfafba7790c4743854ab8f7421 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Sep-27 12:13:30
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x2f9e00
SizeOfInitializedData 0x1cde00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000002AD6C4 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x4cd000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 33306b3988cb118d7b8200aaca3feb4e 🔍
SHA1 746949a71b3044afd6a209e9bb482abcc27c70a8 🔍
SHA256 ea85c775fe5b144717f23c7fed1a0ea1c9242f67789b62ddd2801f0c0afebb20 🔍
SHA3 11b6005a745fe95a514380478c0f3cef0c641906308c46bf8ec9eec6d493e2d2 🔍
VirtualSize 0x2f9c68
VirtualAddress 0x1000
SizeOfRawData 0x2f9e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.60171

.rdata

MD5 3e1c00d7cecfea449cb60538b3f5b9d9 🔍
SHA1 073067ea21fdb0e0263f3361500a0c9486089716 🔍
SHA256 3d32316a08121d90c050607acf3f23822e3a4dd36fdd3da4aecc68a553e9960e 🔍
SHA3 bb6d5681db6d61bc6b6a2145ed8d88c3e3d7954bf11e1092a9424dfdc1650f64 🔍
VirtualSize 0xff2dc
VirtualAddress 0x2fb000
SizeOfRawData 0xff400
PointerToRawData 0x2fa200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.4965

.data

MD5 6b4bba4a526a37f35a71bbd2db2404dd 🔍
SHA1 6c825188d3ca381f7d203819ed833cc7b09b3cb4 🔍
SHA256 e5d1ce9ef8012324a8f61ec58d7e313667f2e3ead25e6828b3a79ce0f9364152 🔍
SHA3 b3d33e9d10435002f778868e8763631af1255a7d48c406ed2d48d3a173b15713 🔍
VirtualSize 0xac794
VirtualAddress 0x3fb000
SizeOfRawData 0x8e200
PointerToRawData 0x3f9600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.0017

.pdata

MD5 2d71209077fcaa45f058cc8bf320ef74 🔍
SHA1 9910f48de653cb3a54939104e429776f9d8e5558 🔍
SHA256 a3cec5fb06570d1053f9da2db752bfb955fe0e72c8a97d67c6e4505ac8e82f88 🔍
SHA3 3ba63bcb7564070f697780ff2742b8be4e6edb19ebbb3248f9a8e73798e2dccb 🔍
VirtualSize 0x1e7d4
VirtualAddress 0x4a8000
SizeOfRawData 0x1e800
PointerToRawData 0x487800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.35649

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x4c7000
SizeOfRawData 0x200
PointerToRawData 0x4a6000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 f73835baba29209c63d37e173f62fecd 🔍
SHA1 e0db18e72d8cde97c61fdb5d6db832beeec46e29 🔍
SHA256 353aa0486628f82212b2b722d8bad3c46b37884498eadb373f3470e90b80fe1b 🔍
SHA3 809abcd1f5bc37480313a4c972ab7daac9a8faad488c361d7dbd3014cf4d9eb2 🔍
VirtualSize 0x1e0
VirtualAddress 0x4c8000
SizeOfRawData 0x200
PointerToRawData 0x4a6200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.70839

.reloc

MD5 2fe49b89aa8864f99c290cdf3e9dfb1f 🔍
SHA1 977d8dd315b4f5e885e776989a6ade49bbf5ce64 🔍
SHA256 5d6e2def06b95d9dcc2ea63e74e9d140195f8e0f86a630a308753af99fa1d726 🔍
SHA3 db84a82c12d06cfdd4d71c0dea9216c30af88b00d39c11bcce8ac8e88abebc8e 🔍
VirtualSize 0x34f0
VirtualAddress 0x4c9000
SizeOfRawData 0x3600
PointerToRawData 0x4a6400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.43904

Imports

d3d11.dll D3D11CreateDevice
D3DCOMPILER_47.dll D3DCompile
ole32.dll CoInitializeEx
CoCreateInstance
CoUninitialize
dxgi.dll CreateDXGIFactory1
dwmapi.dll DwmGetWindowAttribute
DwmExtendFrameIntoClientArea
dcomp.dll DCompositionCreateDevice
WINMM.dll timeBeginPeriod
timeEndPeriod
ntdll.dll RtlPcToFileHeader
RtlUnwindEx
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
RtlUnwind
COMDLG32.dll GetSaveFileNameW
GetOpenFileNameW
ADVAPI32.dll SetTokenInformation
RegQueryValueExA
RegOpenKeyExA
OpenProcessToken
GetTokenInformation
LookupPrivilegeValueW
PrivilegeCheck
DuplicateTokenEx
SetThreadToken
RegCloseKey
CreateProcessAsUserW
RevertToSelf
SHELL32.dll ShellExecuteExW
KERNEL32.dll GetUserDefaultLCID
EnumSystemLocalesW
GetFileType
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
ReadConsoleW
GetExitCodeProcess
CreatePipe
GetTimeZoneInformation
DeleteFileW
FlsSetValue
FlsGetValue
CreateMutexW
GetLastError
CloseHandle
WaitForSingleObject
ExitProcess
SetThreadPriority
GetCurrentThread
SwitchToThread
SetWaitableTimer
Sleep
SetThreadInformation
CreateWaitableTimerExW
CreateWaitableTimerW
GetTempPathW
CreateDirectoryW
CreateFileW
GetFileSizeEx
SetFilePointer
SetEndOfFile
GetCurrentProcessId
GetTickCount64
WriteFile
MoveFileExW
CreateToolhelp32Snapshot
Process32FirstW
OpenProcess
QueryFullProcessImageNameW
Process32NextW
MultiByteToWideChar
CompareStringOrdinal
ReadProcessMemory
Module32FirstW
Module32NextW
VirtualQueryEx
LoadLibraryExA
GetProcAddress
WideCharToMultiByte
GetModuleHandleW
GetCurrentThreadId
SetLastError
OutputDebugStringW
GetSystemInfo
GetProcessTimes
GetCurrentProcess
GetSystemTimeAsFileTime
lstrcmpW
CreateProcessW
GlobalAlloc
GlobalLock
GlobalUnlock
GlobalFree
GetLocaleInfoA
QueryPerformanceFrequency
QueryPerformanceCounter
LoadLibraryA
FreeLibrary
GetModuleFileNameW
lstrcmpiW
IsValidCodePage
GetModuleFileNameA
FormatMessageA
CreateFileA
ReadFile
HeapAlloc
HeapReAlloc
HeapFree
GetProcessHeap
MapViewOfFile
UnmapViewOfFile
CreateFileMappingA
FlsAlloc
GetCommandLineA
GetStdHandle
DuplicateHandle
FreeLibraryAndExitThread
ExitThread
CreateThread
LoadLibraryExW
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
GetStartupInfoW
IsDebuggerPresent
InitializeSListHead
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
GetCPInfo
GetStringTypeW
LCMapStringEx
FlsFree
DeleteCriticalSection
InitializeCriticalSectionEx
LeaveCriticalSection
EnterCriticalSection
DecodePointer
EncodePointer
GetModuleHandleExW
CloseThreadpoolWork
SubmitThreadpoolWork
CreateThreadpoolWork
FreeLibraryWhenCallbackReturns
InitOnceComplete
InitOnceBeginInitialize
IsProcessorFeaturePresent
RaiseException
GetLocaleInfoEx
LocalFree
GetFileInformationByHandleEx
CopyFileW
AreFileApisANSI
SetFileInformationByHandle
GetFinalPathNameByHandleW
GetFileInformationByHandle
GetFileAttributesExW
GetFileAttributesW
FindNextFileW
FindFirstFileExW
FindFirstFileW
FindClose
WakeConditionVariable
AcquireSRWLockShared
IsValidLocale
GetACP
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
HeapSize
GetCommandLineW
WriteConsoleW
GetLocaleInfoW
LCMapStringW
CompareStringW
GetTimeFormatW
GetDateFormatW
VirtualProtect
WaitForSingleObjectEx
GetExitCodeThread
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
TryAcquireSRWLockExclusive
ReleaseSRWLockShared
USER32.dll CallNextHookEx
SendInput
GetClassNameA
GetClipboardData
SetClipboardData
CloseClipboard
EmptyClipboard
OpenClipboard
UnhookWinEvent
SetWinEventHook
IntersectRect
GetWindowPlacement
IsWindowVisible
IsIconic
SetWindowPos
MonitorFromRect
EnumWindows
GetClassNameW
PostQuitMessage
LoadCursorA
SetCursor
DefWindowProcW
GetDpiForWindow
EnumThreadWindows
GetParent
SetWindowLongPtrW
GetCursorInfo
GetKeyboardLayout
SetWindowsHookExW
ScreenToClient
GetMonitorInfoW
MonitorFromWindow
UnregisterClassW
DestroyWindow
ShowWindow
SetWindowDisplayAffinity
PostMessageW
MsgWaitForMultipleObjectsEx
DispatchMessageW
TranslateMessage
PeekMessageW
RegisterClassExW
GetClassInfoExW
SetLayeredWindowAttributes
CreateWindowExW
GetWindow
IsWindowEnabled
GetWindowLongPtrW
WindowFromPoint
EnumDisplaySettingsW
GetKeyNameTextW
MapVirtualKeyW
GetWindowThreadProcessId
GetForegroundWindow
GetCursorPos
FindWindowW
IsWindow
SetCursorPos
ClientToScreen
GetAncestor
GetGUIThreadInfo
GetClientRect
GetAsyncKeyState
MessageBoxW
SetProcessDpiAwarenessContext
PostThreadMessageW
ClipCursor
UnhookWindowsHookEx
ToUnicodeEx
GetMessageW
GetKeyboardState
IMM32.dll ImmSetCandidateWindow
ImmGetContext
ImmSetCompositionWindow
ImmReleaseContext

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Sep-27 12:13:30
Version 0.0
SizeofData 34
AddressOfRawData 0x3bff60
PointerToRawData 0x3bf160
Referenced File vesta.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Sep-27 12:13:30
Version 0.0
SizeofData 20
AddressOfRawData 0x3bff84
PointerToRawData 0x3bf184

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Sep-27 12:13:30
Version 0.0
SizeofData 1132
AddressOfRawData 0x3bff98
PointerToRawData 0x3bf198

TLS Callbacks

StartAddressOfRawData 0x1403c0460
EndAddressOfRawData 0x1403c18bc
AddressOfIndex 0x14048e784
AddressOfCallbacks 0x1402fba88
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks 0x00000001402ADC24
0x00000001402ADC8C

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1403fb340

RICH Header

XOR Key 0x6423d52d
Unmarked objects 0
C objects (33145) 57
ASM objects (33145) 35
253 (35207) 1
C objects (35207) 19
ASM objects (35207) 14
C++ objects (35207) 107
C++ objects (35229) 2
C objects (35229) 67
C++ objects (33145) 217
Imports (33145) 31
Total imports 320
C++ objects (LTCG) (35229) 97
Resource objects (35229) 1
Linker (35229) 1

Errors

Leave a comment

No comments yet.