| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Apr-18 07:06:07 |
| Detected languages |
English - United States
|
| CompanyName | MaxDesign Studio |
| FileDescription | Maxim's Custom Graphic Optimizer |
| FileVersion | 1.3.3.7 |
| InternalName | vsheap.exe |
| LegalCopyright | Copyright (C) 2026 Canema |
| OriginalFilename | vsheap.exe |
| ProductName | Secret of Maxim |
| ProductVersion | 1.3.3.7 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 6/71 (Scanned on 2026-04-26 22:20:38) |
APEX:
Malicious
CrowdStrike: win/malicious_confidence_70% (D) Cylance: Unsafe Elastic: malicious (moderate confidence) McAfeeD: ti!B9FD434C3360 Trapmine: suspicious.low.ml.score |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Apr-18 07:06:07 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x33c00 |
| SizeOfInitializedData | 0x17e00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000014A30 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x50000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetModuleFileNameA
WaitForSingleObject GetModuleHandleA LoadLibraryA CloseHandle SetEndOfFile EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection EncodePointer DecodePointer MultiByteToWideChar WideCharToMultiByte LCMapStringEx GetStringTypeW GetCPInfo RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW GetModuleHandleW RtlUnwindEx RtlPcToFileHeader RaiseException GetLastError SetLastError InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary GetProcAddress LoadLibraryExW GetStdHandle WriteFile GetModuleFileNameW ExitProcess GetModuleHandleExW GetCommandLineA GetCommandLineW GetFileSizeEx SetFilePointerEx GetFileType FlushFileBuffers GetConsoleOutputCP GetConsoleMode HeapFree HeapAlloc FlsAlloc FlsGetValue FlsSetValue FlsFree CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW ReadFile ReadConsoleW HeapReAlloc FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW SetStdHandle GetProcessHeap CreateFileW HeapSize WriteConsoleW RtlUnwind |
|---|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.3.3.7 |
| ProductVersion | 1.3.3.7 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | MaxDesign Studio |
| FileDescription | Maxim's Custom Graphic Optimizer |
| FileVersion (#2) | 1.3.3.7 |
| InternalName | vsheap.exe |
| LegalCopyright | Copyright (C) 2026 Canema |
| OriginalFilename | vsheap.exe |
| ProductName | Secret of Maxim |
| ProductVersion (#2) | 1.3.3.7 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-18 07:06:07 |
| Version | 0.0 |
| SizeofData | 916 |
| AddressOfRawData | 0xc774 |
| PointerToRawData | 0xbb74 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-18 07:06:07 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140035080 |
| XOR Key | 0x9938d8e7 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 5 |
| C++ objects (30795) | 174 |
| C objects (30795) | 16 |
| Unmarked objects (#2) | 1 |
| C objects (33218) | 16 |
| ASM objects (33218) | 18 |
| C++ objects (33218) | 80 |
| Imports (30795) | 3 |
| Total imports | 102 |
| C++ objects (LTCG) (33523) | 1 |
| Resource objects (33523) | 1 |
| 151 | 1 |
| Linker (33523) | 1 |
No comments yet.