| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-May-21 20:17:50 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\Recso\Desktop\dcplus\bin\Release\x64\dcplus.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 21/71 (Scanned on 2026-05-23 17:18:12) |
ALYac:
Gen:Variant.Tedy.964076
APEX: Malicious AhnLab-V3: Trojan/Win.Tedy.C5884610 Arcabit: Trojan.Tedy.DEB5EC BitDefender: Gen:Variant.Tedy.964076 Bkav: W32.Malware.6A8B3511 CTX: exe.unknown.tedy ESET-NOD32: Win64/GameHack_AGen.AON potentially unsafe application Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Tedy.964076 (B) GData: Gen:Variant.Tedy.964076 Google: Detected Ikarus: Trojan.Win64.Krypt Malwarebytes: Malware.AI.1931240678 MaxSecure: Trojan.Malware.300983.susgen McAfeeD: ti!B1FBF112041B MicroWorld-eScan: Gen:Variant.Tedy.964076 Microsoft: Trojan:Win32/Wacatac.B!ml Rising: Trojan.Kryptik@AI.100 (RDML:OQ7drRWOH4etcDkUnBFSFw) Symantec: ML.Attribute.HighConfidence VIPRE: Gen:Variant.Tedy.964076 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-May-21 20:17:50 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xa3600 |
| SizeOfInitializedData | 0x52200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000A0BA4 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xfa000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| KERNEL32.dll |
LoadLibraryExW
GetLastError GetProcAddress OutputDebugStringA MultiByteToWideChar GlobalAlloc GlobalFree GlobalLock WideCharToMultiByte GlobalUnlock GetModuleHandleA GetLocaleInfoA LoadLibraryA QueryPerformanceFrequency IsDBCSLeadByte FreeLibrary QueryPerformanceCounter GetStdHandle GetConsoleMode SetConsoleMode GetCurrentConsoleFontEx SetCurrentConsoleFontEx GetConsoleScreenBufferInfoEx SetConsoleScreenBufferInfoEx GetConsoleWindow SetConsoleWindowInfo SetConsoleScreenBufferSize SetConsoleCursorInfo FlushConsoleInputBuffer SetConsoleTitleA CloseHandle GetExitCodeProcess CreateToolhelp32Snapshot Process32FirstW lstrcmpiW Process32NextW OpenProcess Module32FirstW ReadProcessMemory lstrcmpW Module32NextW CreateDirectoryA GetModuleHandleW GetCurrentProcess SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext WakeAllConditionVariable GetCurrentThreadId Sleep SleepConditionVariableSRW AcquireSRWLockShared AcquireSRWLockExclusive ReleaseSRWLockShared ReleaseSRWLockExclusive SetConsoleCP SetConsoleOutputCP TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetCurrentProcessId GetSystemTimeAsFileTime InitializeSListHead GetTickCount64 |
| USER32.dll |
SetClipboardData
SetWindowLongW GetWindowLongW GetClipboardData RegisterClassExW GetKeyState PeekMessageW LoadCursorW TranslateMessage GetClassInfoExW DispatchMessageW UpdateWindow ShowWindow SetLayeredWindowAttributes GetMessageExtraInfo UnregisterClassW CreateWindowExW GetSystemMetrics DefWindowProcW ScreenToClient PostQuitMessage EmptyClipboard CloseClipboard OpenClipboard GetCursorPos SetCursorPos ReleaseCapture DestroyWindow IsWindowUnicode GetClientRect SetCursor SetCapture GetKeyboardLayout MessageBoxA GetAsyncKeyState TrackMouseEvent ClientToScreen GetCapture GetForegroundWindow GetWindowTextW |
| GDI32.dll |
GetStockObject
|
| SHELL32.dll |
ShellExecuteA
ShellExecuteW SHGetFolderPathA |
| ole32.dll |
CoUninitialize
CoInitializeEx |
| MSVCP140.dll |
?put@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@QEBA?AV?$ostreambuf_iterator@DU?$char_traits@D@std@@@2@V32@AEAVios_base@2@DPEBUtm@@PEBD3@Z
?_Xlength_error@std@@YAXPEBD@Z _Query_perf_counter _Query_perf_frequency ?_Incref@facet@locale@std@@UEAAXXZ ??1_Locinfo@std@@QEAA@XZ ??1_Lockit@std@@QEAA@XZ ??0_Locinfo@std@@QEAA@PEBD@Z ??0_Lockit@std@@QEAA@H@Z ?_Gettrue@_Locinfo@std@@QEBAPEBDXZ ?_Xbad_alloc@std@@YAXXZ ?_Getfalse@_Locinfo@std@@QEBAPEBDXZ ?_Getcvt@_Locinfo@std@@QEBA?AU_Cvtvec@@XZ ?_Getlconv@_Locinfo@std@@QEBAPEBUlconv@@XZ ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ ??1facet@locale@std@@MEAA@XZ ??0facet@locale@std@@IEAA@_K@Z ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?id@?$numpunct@D@std@@2V0locale@2@A ?_Id_cnt@id@locale@std@@0HA ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z ?_Xout_of_range@std@@YAXPEBD@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?always_noconv@codecvt_base@std@@QEBA_NXZ ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?_Xbad_function_call@std@@YAXXZ ?uncaught_exceptions@std@@YAHXZ ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z _Xtime_get_ticks ?_Getcat@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ ?id@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@2V0locale@2@A |
| IMM32.dll |
ImmSetCandidateWindow
ImmGetContext ImmSetCompositionWindow ImmReleaseContext |
| D3DCOMPILER_47.dll |
D3DCompile
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
memcpy
__std_terminate __std_exception_copy __std_exception_destroy _CxxThrowException __current_exception_context __current_exception __C_specific_handler memset memmove memcmp memchr strchr |
| api-ms-win-crt-runtime-l1-1-0.dll |
exit
_register_thread_local_exe_atexit_callback _c_exit _errno __p___argv __p___argc _exit _initterm_e _initterm _get_initial_narrow_environment _set_app_type _seh_filter_exe terminate _cexit _crt_atexit _register_onexit_function _initialize_onexit_table _invoke_watson _initialize_narrow_environment _configure_narrow_argv |
| api-ms-win-crt-heap-l1-1-0.dll |
free
calloc _set_new_mode _callnewh malloc |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
powf pow _dsign _fdsign roundf log sinf fminf fmaxf sqrtf fmodf cosf ceilf _dclass _ldclass _fdclass fmaf _ldsign logf atan2f acosf |
| api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vsprintf
__p__commode _set_fmode fflush getchar setvbuf __stdio_common_vsscanf _wfopen fsetpos __stdio_common_vfprintf fseek __acrt_iob_func ftell fgetpos fclose _get_stream_buffer_pointers fputc ungetc fgetc fread fwrite _fseeki64 |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_lock_file
_unlock_file |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
localeconv |
| api-ms-win-crt-convert-l1-1-0.dll |
strtoull
strtoll atof strtod |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-string-l1-1-0.dll |
strncmp
wcscpy_s strcmp strncpy |
| api-ms-win-crt-time-l1-1-0.dll |
_localtime64_s
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-21 20:17:50 |
| Version | 0.0 |
| SizeofData | 81 |
| AddressOfRawData | 0xd9734 |
| PointerToRawData | 0xd8134 |
| Referenced File | C:\Users\Recso\Desktop\dcplus\bin\Release\x64\dcplus.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-21 20:17:50 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xd9788 |
| PointerToRawData | 0xd8188 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-21 20:17:50 |
| Version | 0.0 |
| SizeofData | 912 |
| AddressOfRawData | 0xd979c |
| PointerToRawData | 0xd819c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-21 20:17:50 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1400d9b50 |
|---|---|
| EndAddressOfRawData | 0x1400d9b58 |
| AddressOfIndex | 0x1400eb57c |
| AddressOfCallbacks | 0x1400a5a00 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400ea040 |
| XOR Key | 0x4d377cda |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 20 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 36 |
| Imports (35207) | 6 |
| Imports (33145) | 19 |
| Total imports | 353 |
| C++ objects (LTCG) (35227) | 30 |
| Resource objects (35227) | 1 |
| 151 | 1 |
| Linker (35227) | 1 |
No comments yet.