| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Feb-25 16:26:52 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .-,`
Unusual section name found: .JMH Unusual section name found: .s^_ |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 42/71 (Scanned on 2026-06-03 15:25:29) |
ALYac:
Gen:Variant.Tedy.935265
APEX: Malicious AVG: Win64:MalwareX-gen [Misc] Antiy-AVL: Trojan[Packed]/Win32.VMProtect Arcabit: Trojan.Tedy.DE4561 Avast: Win64:MalwareX-gen [Misc] Avira: TR/W64.Agent BitDefender: Gen:Variant.Tedy.935265 Bkav: W32.Malware.1E7C0F97 CTX: dll.trojan.vmprotect CrowdStrike: win/malicious_confidence_100% (W) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS ESET-NOD32: Win32/Packed.VMProtect.ACT trojan Elastic: malicious (moderate confidence) Emsisoft: Gen:Variant.Tedy.935265 (B) F-Secure: Trojan.TR/W64.Agent Fortinet: W32/PossibleThreat GData: Gen:Variant.Tedy.935265 Google: Detected Gridinsoft: Trojan.Win64.Packed.cl Ikarus: Trojan.Win32.VMProtect Lionic: Trojan.Win32.VMProtect.4!c Malwarebytes: VMProtect.Trojan.MalPack.DDS MaxSecure: Trojan.Malware.324995110.susgen McAfeeD: ti!A4E300298AA7 MicroWorld-eScan: Gen:Variant.Tedy.935265 Microsoft: Trojan:Win32/Wacatac.B!ml Paloalto: generic.ml SentinelOne: Static AI - Suspicious PE Skyhigh: BehavesLike.Win64.Injector.vc Sophos: Mal/Generic-S Symantec: Trojan.Gen.MBT Trapmine: suspicious.low.ml.score TrellixENS: Artemis!51A176AEC611 TrendMicro: Trojan.Win64.VMPROTECT.USBLCM26 TrendMicro-HouseCall: Trojan.Win64.VMPROTECT.USBLCM26 VIPRE: Gen:Variant.Tedy.935265 Varist: W64/ABTrojan.AIEI-9241 Zillya: Trojan.VMProtect.Win32.144342 alibabacloud: VirTool:Win/Packed.VMProtect.AWB |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 9 |
| TimeDateStamp | 2026-Feb-25 16:26:52 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x4e00 |
| SizeOfInitializedData | 0x4600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000004286C9 (Section: .s^_) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x679000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetProcAddress
HeapDestroy HeapCreate LoadLibraryW VirtualProtect HeapAlloc DisableThreadLibraryCalls GetModuleHandleW GetLastError CloseHandle HeapFree Sleep GetCurrentProcess GetCurrentProcessId GetCurrentThreadId OpenThread SuspendThread ResumeThread GetThreadContext SetThreadContext FlushInstructionCache CreateToolhelp32Snapshot Thread32First Thread32Next GetSystemInfo VirtualAlloc VirtualFree VirtualQuery RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent HeapReAlloc |
|---|---|
| USER32.dll |
MessageBoxA
|
| ADVAPI32.dll |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
| MSVCP140.dll |
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Xlength_error@std@@YAXPEBD@Z ?_Xbad_alloc@std@@YAXXZ ?_Xinvalid_argument@std@@YAXPEBD@Z ?_Xout_of_range@std@@YAXPEBD@Z ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ??Bios_base@std@@QEBA_NXZ |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__C_specific_handler
__std_exception_copy __std_terminate _CxxThrowException __std_type_info_destroy_list __std_exception_destroy memset memcpy |
| api-ms-win-crt-runtime-l1-1-0.dll |
_initterm_e
_seh_filter_dll _configure_narrow_argv _errno _invoke_watson _initialize_narrow_environment _initialize_onexit_table _execute_onexit_table _cexit _initterm |
| api-ms-win-crt-convert-l1-1-0.dll |
strtol
|
| api-ms-win-crt-heap-l1-1-0.dll |
free
malloc _callnewh |
| KERNEL32.dll (#2) |
GetProcAddress
HeapDestroy HeapCreate LoadLibraryW VirtualProtect HeapAlloc DisableThreadLibraryCalls GetModuleHandleW GetLastError CloseHandle HeapFree Sleep GetCurrentProcess GetCurrentProcessId GetCurrentThreadId OpenThread SuspendThread ResumeThread GetThreadContext SetThreadContext FlushInstructionCache CreateToolhelp32Snapshot Thread32First Thread32Next GetSystemInfo VirtualAlloc VirtualFree VirtualQuery RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent HeapReAlloc |
| USER32.dll (#2) |
MessageBoxA
|
| KERNEL32.dll (#3) |
GetProcAddress
HeapDestroy HeapCreate LoadLibraryW VirtualProtect HeapAlloc DisableThreadLibraryCalls GetModuleHandleW GetLastError CloseHandle HeapFree Sleep GetCurrentProcess GetCurrentProcessId GetCurrentThreadId OpenThread SuspendThread ResumeThread GetThreadContext SetThreadContext FlushInstructionCache CreateToolhelp32Snapshot Thread32First Thread32Next GetSystemInfo VirtualAlloc VirtualFree VirtualQuery RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent HeapReAlloc |
| Ordinal | 1 |
|---|---|
| Address | 0x2070 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x180009240 |
No comments yet.