| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1970-Jan-01 00:00:00 |
| Detected languages |
English - United States
|
| CompanyName | CS.RiN.RU |
| FileVersion | 1.0.0.0 |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 4/72 (Scanned on 2026-03-13 20:34:55) |
Bkav:
W64.AIDetectMalware
CrowdStrike: win/malicious_confidence_70% (W) McAfeeD: ti!CCD390BE9263 Rising: Trojan.Kryptik@AI.82 (RDML:WMBB+YzDP15UyqF4PlsJ7w) |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xc800 |
| SizeOfInitializedData | 0xba00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000002C38 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1c000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x1c927 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d12.dll |
#101
|
|---|---|
| KERNEL32.dll |
TlsGetValue
WriteConsoleW GetModuleFileNameA GetVersionExA GetProcAddress HeapCreate VirtualProtect HeapFree GetCurrentProcess Thread32Next Thread32First GetCurrentThreadId SuspendThread ResumeThread CreateToolhelp32Snapshot Sleep HeapReAlloc CloseHandle HeapAlloc HeapDestroy GetThreadContext GetCurrentProcessId GetModuleHandleW FlushInstructionCache SetThreadContext OpenThread VirtualFree VirtualAlloc GetSystemInfo VirtualQuery QueryPerformanceCounter GetSystemTimeAsFileTime InitializeSListHead RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent TerminateProcess CreateFileW RtlUnwindEx InterlockedFlushSList GetLastError SetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsSetValue TlsFree FreeLibrary LoadLibraryExW RaiseException ExitProcess GetModuleHandleExW GetModuleFileNameW FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW MultiByteToWideChar WideCharToMultiByte GetEnvironmentStringsW FreeEnvironmentStringsW LCMapStringW GetProcessHeap GetStdHandle GetFileType GetStringTypeW HeapSize SetStdHandle FlushFileBuffers WriteFile GetConsoleCP GetConsoleMode SetFilePointerEx |
| Ordinal | 1 |
|---|---|
| Address | 0x1200 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | CS.RiN.RU |
| FileVersion (#2) | 1.0.0.0 |
| Resource LangID | English - United States |
|---|
| Size | 0x108 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x180017010 |
| XOR Key | 0x68cdd18d |
|---|---|
| Unmarked objects | 0 |
| C objects (VS2017 v14.15 compiler 26715) | 10 |
| ASM objects (VS2017 v14.15 compiler 26715) | 6 |
| C++ objects (VS2017 v14.15 compiler 26715) | 132 |
| C++ objects (26504) | 29 |
| C objects (26504) | 15 |
| ASM objects (26504) | 8 |
| Imports (VS2017 v14.15 compiler 26715) | 5 |
| Total imports | 104 |
| C++ objects (LTCG) (VS2019 Update 2 (16.2) compiler 27905) | 5 |
| Exports (VS2019 Update 2 (16.2) compiler 27905) | 1 |
| Linker (VS2019 Update 2 (16.2) compiler 27905) | 1 |
No comments yet.