| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Feb-23 03:54:45 |
| Detected languages |
English - United States
|
| FileDescription | geanswag massinha |
| FileVersion | 1.0.0.0 |
| InternalName | version.dll |
| OriginalFilename | version.dll |
| ProductName | geanswag massinha |
| ProductVersion | 1.0.0.0 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 8.0
MASM/TASM - sig1(h) |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 23/70 (Scanned on 2026-06-17 00:11:45) |
ALYac:
Gen:Variant.Tedy.914244
AVG: Other:Malware-gen [Trj] Arcabit: Trojan.Tedy.DDF344 Avast: Other:Malware-gen [Trj] Avira: TR/Malware BitDefender: Gen:Variant.Tedy.914244 CTX: dll.trojan.dllinject Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS F-Secure: Trojan.TR/Malware GData: Gen:Variant.Tedy.914244 Google: Detected Gridinsoft: Trojan.Win64.Gen.cl Lionic: Trojan.UKP.Generic.4!c MicroWorld-eScan: Gen:Variant.Tedy.914244 Microsoft: HackTool:Win32/DllInject!MTB Sophos: Generic Reputation PUA (PUA) Symantec: Trojan.Gen.MBT TrendMicro-HouseCall: TROJ_GEN.R002H09CM26 VIPRE: Gen:Variant.Tedy.914244 Varist: W64/ABApplication.HNEL-1842 Webroot: Win.Trojan.Gen alibabacloud: Trojan:Win/DllInject.Gen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Feb-23 03:54:45 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x1d400 |
| SizeOfInitializedData | 0x44a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000001D744 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x66000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| OPENGL32.dll |
wglGetCurrentDC
glGetString glTexParameterf glHint glGetIntegerv glDisable wglGetProcAddress |
|---|---|
| KERNEL32.dll |
VirtualFree
RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent Sleep CreateThread GetSystemDirectoryA DisableThreadLibraryCalls FreeLibrary GetModuleHandleA GetProcAddress LoadLibraryA CloseHandle GetLastError HeapCreate HeapDestroy HeapAlloc HeapReAlloc HeapFree GetCurrentProcess GetCurrentProcessId GetCurrentThreadId OpenThread SuspendThread ResumeThread GetThreadContext SetThreadContext FlushInstructionCache VirtualProtect CreateToolhelp32Snapshot Thread32First Thread32Next GetSystemInfo VirtualAlloc VirtualQuery RtlCaptureContext |
| VCRUNTIME140.dll |
__std_type_info_destroy_list
memset memcpy __C_specific_handler |
| api-ms-win-crt-string-l1-1-0.dll |
strcat_s
|
| api-ms-win-crt-runtime-l1-1-0.dll |
_initterm_e
_execute_onexit_table _initialize_onexit_table _cexit _initialize_narrow_environment _configure_narrow_argv _seh_filter_dll _initterm |
| Ordinal | 1 |
|---|---|
| Address | 0x19f0 |
| Ordinal | 2 |
|---|---|
| Address | 0x1a10 |
| Ordinal | 3 |
|---|---|
| Address | 0x1a30 |
| Ordinal | 4 |
|---|---|
| Address | 0x1a40 |
| Ordinal | 5 |
|---|---|
| Address | 0x1a50 |
| Ordinal | 6 |
|---|---|
| Address | 0x1a60 |
| Ordinal | 7 |
|---|---|
| Address | 0x1a70 |
| Ordinal | 8 |
|---|---|
| Address | 0x1a80 |
| Ordinal | 9 |
|---|---|
| Address | 0x1a90 |
| Ordinal | 10 |
|---|---|
| Address | 0x1ab0 |
| Ordinal | 11 |
|---|---|
| Address | 0x1ac0 |
| Ordinal | 12 |
|---|---|
| Address | 0x1ad0 |
| Ordinal | 13 |
|---|---|
| Address | 0x1ae0 |
| Ordinal | 14 |
|---|---|
| Address | 0x1af0 |
| Ordinal | 15 |
|---|---|
| Address | 0x1b00 |
| Ordinal | 16 |
|---|---|
| Address | 0x1b10 |
| Ordinal | 17 |
|---|---|
| Address | 0x1b20 |
| Ordinal | 18 |
|---|---|
| Address | 0x19f0 |
| Ordinal | 19 |
|---|---|
| Address | 0x1a10 |
| Ordinal | 20 |
|---|---|
| Address | 0x1a30 |
| Ordinal | 21 |
|---|---|
| Address | 0x1a40 |
| Ordinal | 22 |
|---|---|
| Address | 0x1a50 |
| Ordinal | 23 |
|---|---|
| Address | 0x1a60 |
| Ordinal | 24 |
|---|---|
| Address | 0x1a70 |
| Ordinal | 25 |
|---|---|
| Address | 0x1a80 |
| Ordinal | 26 |
|---|---|
| Address | 0x1a90 |
| Ordinal | 27 |
|---|---|
| Address | 0x1ab0 |
| Ordinal | 28 |
|---|---|
| Address | 0x1ac0 |
| Ordinal | 29 |
|---|---|
| Address | 0x1ad0 |
| Ordinal | 30 |
|---|---|
| Address | 0x1ae0 |
| Ordinal | 31 |
|---|---|
| Address | 0x1af0 |
| Ordinal | 32 |
|---|---|
| Address | 0x1b00 |
| Ordinal | 33 |
|---|---|
| Address | 0x1b10 |
| Ordinal | 34 |
|---|---|
| Address | 0x1b20 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| FileDescription | geanswag massinha |
| FileVersion (#2) | 1.0.0.0 |
| InternalName | version.dll |
| OriginalFilename | version.dll |
| ProductName | geanswag massinha |
| ProductVersion (#2) | 1.0.0.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Feb-23 03:54:45 |
| Version | 0.0 |
| SizeofData | 600 |
| AddressOfRawData | 0x36b48 |
| PointerToRawData | 0x35348 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x18003c540 |
| XOR Key | 0x561ad3e0 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 6 |
| Imports (35207) | 2 |
| ASM objects (35207) | 3 |
| C objects (35207) | 8 |
| C++ objects (35207) | 19 |
| Imports (30795) | 5 |
| Total imports | 81 |
| C objects (35222) | 5 |
| C++ objects (35222) | 2 |
| Exports (35222) | 1 |
| Resource objects (35222) | 1 |
| 151 | 1 |
| Linker (35222) | 1 |
No comments yet.