| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Oct-05 08:06:41 |
| Detected languages |
English - United States
|
| ProductName | r-studio_rportable_rec |
| ProductVersion | 1.8 |
| FileVersion | 1.8 |
| FileDescription | r-studio_rportable_rec |
| InternalName | r-studio_rportable_rec |
| OriginalFilename | r-studio_rportable_rec.exe |
| LegalCopyright | Copyright (c) 2025 |
| Info | Matching compiler(s): | MASM/TASM - sig2(h) |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 12/70 (Scanned on 2026-05-26 11:04:32) |
APEX:
Malicious
AhnLab-V3: Trojan/Win.Generic.C5298273 Cylance: Unsafe Gridinsoft: Trojan.Win32.Wacatac.dd!n MaxSecure: Trojan.Malware.338151687.susgen McAfeeD: Trojan:Win/Generic.GSLT Paloalto: generic.ml Trapmine: malicious.high.ml.score TrellixENS: GenericRXAA-AA!7EF0F415D5F4 VBA32: BScope.Trojan.Wacatac Webroot: W32.Malware.gen Xcitium: Backdoor.Win32.Androm.XTA@4z809t |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2025-Oct-05 08:06:41 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x19400 |
| SizeOfInitializedData | 0x10000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00001000 (Section: .code) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x1b000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x2c000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MSVCRT.dll |
memset
wcscmp memmove wcslen wcscpy memcpy wcsncmp _wcsicmp fabs malloc free ceil floor fseek ftell fread fclose pow ??3@YAXPAX@Z cos fmod sin abs wcsncpy wcscat localtime mktime gmtime tolower _vsnwprintf |
|---|---|
| KERNEL32.dll |
GetModuleHandleW
HeapCreate HeapDestroy ExitProcess VirtualProtect GetProcAddress EnterCriticalSection CloseHandle LeaveCriticalSection InitializeCriticalSection WaitForSingleObject CreateThread TerminateThread GetModuleFileNameW HeapAlloc FreeLibrary HeapFree LoadLibraryW HeapReAlloc GetVersionExW SetLastError GetCurrentProcessId CreateFileW WriteFile DeleteFileW MultiByteToWideChar WideCharToMultiByte TlsAlloc TlsSetValue MulDiv GetDriveTypeW FindFirstFileW FindClose GetFileAttributesW MoveFileW FileTimeToLocalFileTime FileTimeToSystemTime SystemTimeToFileTime LocalFileTimeToFileTime SetFileTime GetLocalTime SetFilePointer GetFileSize ReadFile DeleteCriticalSection InterlockedCompareExchange Sleep InterlockedExchange GlobalAlloc GlobalLock GlobalUnlock |
| USER32.dll |
FindWindowW
GetWindowRect MoveWindow InvalidateRect MessageBoxW SendMessageW SetMenu DestroyMenu CreatePopupMenu AppendMenuW GetCursorPos SetForegroundWindow TrackPopupMenu DestroyWindow SystemParametersInfoW GetWindowTextLengthW GetWindowTextW GetSysColor GetSysColorBrush GetDC SetRect DrawTextW GetWindowLongW GetSystemMetrics ReleaseDC CreateWindowExW GetKeyState GetPropW BeginPaint EndPaint ClipCursor UpdateWindow SetFocus RedrawWindow GetMessagePos ScreenToClient ChildWindowFromPointEx SetCursor CallWindowProcW GetCapture ReleaseCapture GetClientRect MapWindowPoints SetCapture DefWindowProcW FillRect GetFocus DrawStateW DrawFocusRect LoadCursorW SetPropW RegisterClassExW EnableWindow GetWindow SetWindowLongW SetWindowTextW IsWindowEnabled RemovePropW SetWindowPos SetScrollPos GetParent InflateRect GetWindowDC SetActiveWindow DestroyIcon LoadIconW PeekMessageW MsgWaitForMultipleObjects GetMessageW GetActiveWindow TranslateAcceleratorW TranslateMessage DispatchMessageW RegisterClassW AdjustWindowRectEx ShowWindow CreateAcceleratorTableW UnregisterClassW DefFrameProcW DestroyAcceleratorTable EnumChildWindows PostMessageW IsWindowVisible GetClassNameW GetWindowThreadProcessId IsChild RegisterWindowMessageW EnumDisplaySettingsW OpenClipboard EmptyClipboard SetClipboardData CloseClipboard GetIconInfo DrawIconEx |
| GDI32.dll |
CreateSolidBrush
GetStockObject SetBkMode SetTextColor DeleteObject CreateFontIndirectW SetBkColor SelectObject GetObjectW CreateCompatibleDC BitBlt DeleteDC CreateCompatibleBitmap CreateDIBSection GdiGetBatchLimit GdiSetBatchLimit GetTextExtentPoint32W ExcludeClipRect GetObjectType CreateDCW SetStretchBltMode StretchBlt GetDeviceCaps CreateRectRgnIndirect GetClipRgn ExtSelectClipRgn SelectClipRgn CreateBitmap SetPixel GetDIBits SetTextAlign TextOutW SetBrushOrgEx GetTextMetricsW GetPixel CreateFontW |
| COMDLG32.dll |
GetOpenFileNameW
|
| ole32.dll |
RevokeDragDrop
|
| gdiplus.dll |
GdipDeleteFont
GdipDeleteGraphics GdipDeletePath GdipDeleteMatrix GdipDeletePen GdipDeleteStringFormat GdipFree GdipGetDpiX GdipGetDpiY |
| COMCTL32.dll |
InitCommonControlsEx
_TrackMouseEvent ImageList_Replace ImageList_Add ImageList_ReplaceIcon ImageList_Remove ImageList_AddMasked ImageList_Destroy ImageList_Create |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.8.0.0 |
| ProductVersion | 1.8.0.0 |
| FileFlags | (EMPTY) |
| FileOs | (EMPTY) |
| FileType |
VFT_UNKNOWN
|
| Language | UNKNOWN |
| ProductName | r-studio_rportable_rec |
| ProductVersion (#2) | 1.8 |
| FileVersion (#2) | 1.8 |
| FileDescription | r-studio_rportable_rec |
| InternalName | r-studio_rportable_rec |
| OriginalFilename | r-studio_rportable_rec.exe |
| LegalCopyright | Copyright (c) 2025 |
| Resource LangID | English - United States |
|---|
No comments yet.