| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Sep-04 22:27:30 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\ghait\Downloads\SRC\P1XEL\build\bin\x64\Preazy-ESP-Audit\preazy.cc.pdb
|
| CompanyName | preazy.cc |
| FileDescription | preazy.cc launcher |
| FileVersion | 1.0.0.0 |
| InternalName | preazy.cc |
| OriginalFilename | preazy.cc.exe |
| ProductName | preazy.cc |
| ProductVersion | 1.0.0.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA256 |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE is possibly a dropper. | Resource 101 detected as a PE Executable. |
| Malicious | VirusTotal score: 7/70 (Scanned on 2026-09-05 12:10:50) |
APEX:
Malicious
Bkav: W32.Malware.7B7B67D7 Elastic: Windows.Generic.MalCert Kaspersky: HEUR:Trojan.Win32.Agent.aaaa McAfeeD: Trojan:Win/Genkryptik.ECN Rising: Trojan.Kryptik@AI.81 (RDML:Scg5FLmX+kn1T23OoZFR8A) Sophos: Generic ML PUA (PUA) |
| MD5 | 06f1febf6fe0c791ce3d89ec81a04f49 🔍 |
|---|---|
| SHA1 | f2f9ca40828b9d39be5cbde916f5b5ffa93e8e79 🔍 |
| SHA256 | d6c62947e386e7db60c79c09ef64e9f5ee2e91fcf2b97440c1e97f7b898ae38b 🔍 |
| SHA3 | 8a827fa20e32533dc19527f2fc721276aeb4e92f4fe165baba93bd98d7406145 🔍 |
| SSDeep | 24576:AWSmbfNcH3kcumvreNQOvA9lNwhPEAq2nB9hGei5VyvmP:A8bfNcH3kcmTAH2tEbuBrcbyvmP 🔍 |
| Imports Hash | 3862d13492eb4586aeac439dd7a141d0 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Sep-04 22:27:30 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xd6c00 |
| SizeOfInitializedData | 0x104600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000061884 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1df000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 053b7b72cb79d362f54f254aa5a38871 🔍 |
|---|---|
| SHA1 | 64da7e5b3d01edb78dadfb151e58ab865b694c1f 🔍 |
| SHA256 | c022334b6cae952799ce4ff67604056c1c036685533d699261e4aaf172df3d8b 🔍 |
| SHA3 | 284fc22bff802dfc02b6f0e6ad65a390f4899aed26a0ce34c7f7021e5e061938 🔍 |
| VirtualSize | 0xd6b14 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0xd6c00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.53958 |
| MD5 | 00729610bcad9e1f72281c9f7499c7c0 🔍 |
|---|---|
| SHA1 | 456446baa04e3546b90fb9ae1cc55f9682238206 🔍 |
| SHA256 | cc25280d52218fb8edee13cdc1e27fceca4592c5003ace479e83f24903727d54 🔍 |
| SHA3 | 5f62f294cd1ecf957acea04fc733fb7f6b79bd07ccc463371af5923b893bbeec 🔍 |
| VirtualSize | 0x29b8a |
| VirtualAddress | 0xd8000 |
| SizeOfRawData | 0x29c00 |
| PointerToRawData | 0xd7000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.37963 |
| MD5 | 28e0f8ca6ae73578bd7771d13e7788b3 🔍 |
|---|---|
| SHA1 | 932d5f044d95babf64e5d0b520807b33d277f620 🔍 |
| SHA256 | f75967acfd925b34372390dfdec02c1163ba55a87e4879bd8d772134c9ee7011 🔍 |
| SHA3 | 79520eb15fecf34df2c6115fed6670b6ab3a2de202db99645583c7e833439a3d 🔍 |
| VirtualSize | 0x4784 |
| VirtualAddress | 0x102000 |
| SizeOfRawData | 0x2600 |
| PointerToRawData | 0x100c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.57444 |
| MD5 | c42624c2e97caefa64fdbdfb5592174a 🔍 |
|---|---|
| SHA1 | 706d28312ec4d99e7ab923a88f1911061961696e 🔍 |
| SHA256 | 24a1cedc67cd1580402e6f4c171c3851cbb1c144a6c085f36c9788c12c339e95 🔍 |
| SHA3 | 68a0e729a4fc0db3ae4e941934a553d80f45a419c08396c0b9bd49faffab6e1b 🔍 |
| VirtualSize | 0xa1a0 |
| VirtualAddress | 0x107000 |
| SizeOfRawData | 0xa200 |
| PointerToRawData | 0x103200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.04549 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x100 |
| VirtualAddress | 0x112000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x10d400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 49671c6b7594df518af9dcaac8ba60c7 🔍 |
|---|---|
| SHA1 | 9efa60dfd366b0cc9320f4a97ed85ffa23dc0039 🔍 |
| SHA256 | 7cde1523801e0b3cea0f51d135dbf812a46f0ca8908396717670c0a3029c5969 🔍 |
| SHA3 | 3c247843a56179ff4d76efbe1a20f99e07016a7e41f7e8376ad8fdb8e8d4c16f 🔍 |
| VirtualSize | 0xcac80 |
| VirtualAddress | 0x113000 |
| SizeOfRawData | 0xcae00 |
| PointerToRawData | 0x10d600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 7.21204 |
| MD5 | 7e09631b0636c6545b6b070bb2e9325c 🔍 |
|---|---|
| SHA1 | 66ecafee15ce4d069e2039968ec77512f6c890c3 🔍 |
| SHA256 | e06a728e2574512c09ed793375a3911c99b44e7fc3bb1ba98936956dcac4b204 🔍 |
| SHA3 | 32fc4e6bf1f43aaa7d8b349d48e0c14c659a65e22f99269703210849c187b625 🔍 |
| VirtualSize | 0xf24 |
| VirtualAddress | 0x1de000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0x1d8400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.3485 |
| USER32.dll |
IsWindowVisible
GetWindowThreadProcessId GetClassNameW EnumWindows |
|---|---|
| bcrypt.dll |
BCryptHash
BCryptCloseAlgorithmProvider BCryptOpenAlgorithmProvider |
| SHELL32.dll |
SHGetKnownFolderPath
|
| ole32.dll |
CoTaskMemFree
|
| dbghelp.dll |
ImageDirectoryEntryToData
|
| KERNEL32.dll |
WideCharToMultiByte
SetEndOfFile WriteConsoleW HeapSize SetStdHandle OutputDebugStringW GetProcessHeap SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetOEMCP GetACP IsValidCodePage GetTimeZoneInformation HeapReAlloc GetStdHandle CreateFileW FlushFileBuffers GetFileSizeEx ReadFile WriteFile GetTempPathA CloseHandle GetLastError SetLastError CreateMutexW OpenMutexW Sleep GetCurrentProcessId GetLocalTime GetTickCount64 FreeLibrary GetModuleHandleW GetProcAddress LoadLibraryExW LoadResource LockResource SizeofResource FindResourceW GetConsoleMode SetConsoleCtrlHandler SetConsoleTitleW CreateToolhelp32Snapshot Process32FirstW Process32NextW ReadConsoleW LocalFree FormatMessageA GetLocaleInfoEx SetCurrentDirectoryW GetCurrentDirectoryW CreateDirectoryW FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetDiskFreeSpaceExW GetFileAttributesW GetFileAttributesExW GetFileInformationByHandle GetFinalPathNameByHandleW GetFullPathNameW SetFileAttributesW SetFileInformationByHandle SetFileTime GetTempPathW AreFileApisANSI DeviceIoControl CreateDirectoryExW CopyFileW MoveFileExW CreateHardLinkW GetFileInformationByHandleEx CreateSymbolicLinkW MultiByteToWideChar RtlUnwind GetStringTypeW EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection EncodePointer DecodePointer LCMapStringEx CompareStringEx GetCPInfo RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent GetCurrentProcess TerminateProcess QueryPerformanceCounter GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead RtlPcToFileHeader RaiseException RtlUnwindEx InterlockedPushEntrySList InterlockedFlushSList InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree ExitProcess GetModuleHandleExW GetModuleFileNameW GetCommandLineA GetCommandLineW GetCurrentThread HeapAlloc HeapFree FlsAlloc FlsGetValue FlsSetValue FlsFree IsThreadAFiber VirtualProtect GetDateFormatW GetTimeFormatW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetFileType GetConsoleOutputCP SetFilePointerEx |
| Type |
RT_RCDATA
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0xca7a0 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 7.21621 |
| Detected Filetype | PE Executable |
| MD5 | 2583d4f374a4949fb6a090a7514fa243 🔍 |
| SHA1 | 83cd58142053253f009db07da1977568dcfd4104 🔍 |
| SHA256 | cebdb845effdca26e843e74187bf9223d2de53de6ddee27b811d732dc01f8e52 🔍 |
| SHA3 | 4ea1a8ad5d83b0cae8ea19477b133427fff1029e57e7fe4d2e00080553c71e8b 🔍 |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x270 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.21484 |
| MD5 | 65ec1ffeec327d05db5b62265557b264 🔍 |
| SHA1 | c13c73da66bdda2c0ef70f97dbd4482cf42e2349 🔍 |
| SHA256 | 80e6a84f976e0dac109fb32cdb4f8365e77d2f5b03a4105210b2d4f1cb3a2808 🔍 |
| SHA3 | cfbde85ca53d6af332221b7722aabf3582bca52dd10488325856b2cbf4a64487 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | preazy.cc |
| FileDescription | preazy.cc launcher |
| FileVersion (#2) | 1.0.0.0 |
| InternalName | preazy.cc |
| OriginalFilename | preazy.cc.exe |
| ProductName | preazy.cc |
| ProductVersion (#2) | 1.0.0.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Sep-04 22:27:30 |
| Version | 0.0 |
| SizeofData | 104 |
| AddressOfRawData | 0xef5d8 |
| PointerToRawData | 0xee5d8 |
| Referenced File | C:\Users\ghait\Downloads\SRC\P1XEL\build\bin\x64\Preazy-ESP-Audit\preazy.cc.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Sep-04 22:27:30 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xef640 |
| PointerToRawData | 0xee640 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Sep-04 22:27:30 |
| Version | 0.0 |
| SizeofData | 1012 |
| AddressOfRawData | 0xef654 |
| PointerToRawData | 0xee654 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140102200 |
| XOR Key | 0xf12789db |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 174 |
| C objects (33145) | 17 |
| ASM objects (33145) | 8 |
| ASM objects (35207) | 10 |
| C objects (35207) | 16 |
| C++ objects (35207) | 85 |
| C objects (CVTCIL) (33145) | 1 |
| Imports (33145) | 13 |
| Total imports | 145 |
| C++ objects (35227) | 1 |
| Resource objects (35227) | 1 |
| 151 | 1 |
| Linker (35227) | 1 |
No comments yet.