d6c62947e386e7db60c79c09ef64e9f5ee2e91fcf2b97440c1e97f7b898ae38b

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Sep-04 22:27:30
Detected languages English - United States
Debug artifacts C:\Users\ghait\Downloads\SRC\P1XEL\build\bin\x64\Preazy-ESP-Audit\preazy.cc.pdb
CompanyName preazy.cc
FileDescription preazy.cc launcher
FileVersion 1.0.0.0
InternalName preazy.cc
OriginalFilename preazy.cc.exe
ProductName preazy.cc
ProductVersion 1.0.0.0

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Contains domain names:
  • cacerts.digicert.com
  • crl.thawte.com
  • crl3.digicert.com
  • digicert.com
  • http://cacerts.digicert.com
  • http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
  • http://cacerts.digicert.com/DigiCertTrustedG4TimeStampingRSA4096SHA2562025CA1.crt0_
  • http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
  • http://crl.thawte.com
  • http://crl.thawte.com/ThawtePCA.crl0
  • http://crl3.digicert.com
  • http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
  • http://crl3.digicert.com/DigiCertTrustedG4TimeStampingRSA4096SHA2562025CA1.crl0
  • http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
  • http://ocsp.digicert.com0
  • http://ocsp.digicert.com0A
  • http://ocsp.digicert.com0C
  • http://ocsp.thawte.com0
  • http://th.symcb.com
  • http://th.symcb.com/th.crl0
  • http://th.symcb.com/th.crt0
  • http://th.symcd.com0
  • http://th.symcd.com0&
  • https://w.wallhaven.cc
  • https://w.wallhaven.cc/full/
  • https://wallhaven.cc
  • https://whvn.cc
  • https://www.thawte.com
  • https://www.thawte.com/cps0/
  • https://www.thawte.com/repository0W
  • symcb.com
  • th.symcb.com
  • thawte.com
  • www.thawte.com
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA256
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Can create temporary files:
  • CreateFileW
  • GetTempPathA
  • GetTempPathW
Manipulates other processes:
  • Process32FirstW
  • Process32NextW
Malicious The PE is possibly a dropper. Resource 101 detected as a PE Executable.
Malicious VirusTotal score: 7/70 (Scanned on 2026-09-05 12:10:50) APEX: Malicious
Bkav: W32.Malware.7B7B67D7
Elastic: Windows.Generic.MalCert
Kaspersky: HEUR:Trojan.Win32.Agent.aaaa
McAfeeD: Trojan:Win/Genkryptik.ECN
Rising: Trojan.Kryptik@AI.81 (RDML:Scg5FLmX+kn1T23OoZFR8A)
Sophos: Generic ML PUA (PUA)

Hashes

MD5 06f1febf6fe0c791ce3d89ec81a04f49 🔍
SHA1 f2f9ca40828b9d39be5cbde916f5b5ffa93e8e79 🔍
SHA256 d6c62947e386e7db60c79c09ef64e9f5ee2e91fcf2b97440c1e97f7b898ae38b 🔍
SHA3 8a827fa20e32533dc19527f2fc721276aeb4e92f4fe165baba93bd98d7406145 🔍
SSDeep 24576:AWSmbfNcH3kcumvreNQOvA9lNwhPEAq2nB9hGei5VyvmP:A8bfNcH3kcmTAH2tEbuBrcbyvmP 🔍
Imports Hash 3862d13492eb4586aeac439dd7a141d0 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Sep-04 22:27:30
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xd6c00
SizeOfInitializedData 0x104600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000061884 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1df000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 053b7b72cb79d362f54f254aa5a38871 🔍
SHA1 64da7e5b3d01edb78dadfb151e58ab865b694c1f 🔍
SHA256 c022334b6cae952799ce4ff67604056c1c036685533d699261e4aaf172df3d8b 🔍
SHA3 284fc22bff802dfc02b6f0e6ad65a390f4899aed26a0ce34c7f7021e5e061938 🔍
VirtualSize 0xd6b14
VirtualAddress 0x1000
SizeOfRawData 0xd6c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.53958

.rdata

MD5 00729610bcad9e1f72281c9f7499c7c0 🔍
SHA1 456446baa04e3546b90fb9ae1cc55f9682238206 🔍
SHA256 cc25280d52218fb8edee13cdc1e27fceca4592c5003ace479e83f24903727d54 🔍
SHA3 5f62f294cd1ecf957acea04fc733fb7f6b79bd07ccc463371af5923b893bbeec 🔍
VirtualSize 0x29b8a
VirtualAddress 0xd8000
SizeOfRawData 0x29c00
PointerToRawData 0xd7000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.37963

.data

MD5 28e0f8ca6ae73578bd7771d13e7788b3 🔍
SHA1 932d5f044d95babf64e5d0b520807b33d277f620 🔍
SHA256 f75967acfd925b34372390dfdec02c1163ba55a87e4879bd8d772134c9ee7011 🔍
SHA3 79520eb15fecf34df2c6115fed6670b6ab3a2de202db99645583c7e833439a3d 🔍
VirtualSize 0x4784
VirtualAddress 0x102000
SizeOfRawData 0x2600
PointerToRawData 0x100c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.57444

.pdata

MD5 c42624c2e97caefa64fdbdfb5592174a 🔍
SHA1 706d28312ec4d99e7ab923a88f1911061961696e 🔍
SHA256 24a1cedc67cd1580402e6f4c171c3851cbb1c144a6c085f36c9788c12c339e95 🔍
SHA3 68a0e729a4fc0db3ae4e941934a553d80f45a419c08396c0b9bd49faffab6e1b 🔍
VirtualSize 0xa1a0
VirtualAddress 0x107000
SizeOfRawData 0xa200
PointerToRawData 0x103200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.04549

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x112000
SizeOfRawData 0x200
PointerToRawData 0x10d400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 49671c6b7594df518af9dcaac8ba60c7 🔍
SHA1 9efa60dfd366b0cc9320f4a97ed85ffa23dc0039 🔍
SHA256 7cde1523801e0b3cea0f51d135dbf812a46f0ca8908396717670c0a3029c5969 🔍
SHA3 3c247843a56179ff4d76efbe1a20f99e07016a7e41f7e8376ad8fdb8e8d4c16f 🔍
VirtualSize 0xcac80
VirtualAddress 0x113000
SizeOfRawData 0xcae00
PointerToRawData 0x10d600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.21204

.reloc

MD5 7e09631b0636c6545b6b070bb2e9325c 🔍
SHA1 66ecafee15ce4d069e2039968ec77512f6c890c3 🔍
SHA256 e06a728e2574512c09ed793375a3911c99b44e7fc3bb1ba98936956dcac4b204 🔍
SHA3 32fc4e6bf1f43aaa7d8b349d48e0c14c659a65e22f99269703210849c187b625 🔍
VirtualSize 0xf24
VirtualAddress 0x1de000
SizeOfRawData 0x1000
PointerToRawData 0x1d8400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.3485

Imports

USER32.dll IsWindowVisible
GetWindowThreadProcessId
GetClassNameW
EnumWindows
bcrypt.dll BCryptHash
BCryptCloseAlgorithmProvider
BCryptOpenAlgorithmProvider
SHELL32.dll SHGetKnownFolderPath
ole32.dll CoTaskMemFree
dbghelp.dll ImageDirectoryEntryToData
KERNEL32.dll WideCharToMultiByte
SetEndOfFile
WriteConsoleW
HeapSize
SetStdHandle
OutputDebugStringW
GetProcessHeap
SetEnvironmentVariableW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetOEMCP
GetACP
IsValidCodePage
GetTimeZoneInformation
HeapReAlloc
GetStdHandle
CreateFileW
FlushFileBuffers
GetFileSizeEx
ReadFile
WriteFile
GetTempPathA
CloseHandle
GetLastError
SetLastError
CreateMutexW
OpenMutexW
Sleep
GetCurrentProcessId
GetLocalTime
GetTickCount64
FreeLibrary
GetModuleHandleW
GetProcAddress
LoadLibraryExW
LoadResource
LockResource
SizeofResource
FindResourceW
GetConsoleMode
SetConsoleCtrlHandler
SetConsoleTitleW
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
ReadConsoleW
LocalFree
FormatMessageA
GetLocaleInfoEx
SetCurrentDirectoryW
GetCurrentDirectoryW
CreateDirectoryW
FindClose
FindFirstFileW
FindFirstFileExW
FindNextFileW
GetDiskFreeSpaceExW
GetFileAttributesW
GetFileAttributesExW
GetFileInformationByHandle
GetFinalPathNameByHandleW
GetFullPathNameW
SetFileAttributesW
SetFileInformationByHandle
SetFileTime
GetTempPathW
AreFileApisANSI
DeviceIoControl
CreateDirectoryExW
CopyFileW
MoveFileExW
CreateHardLinkW
GetFileInformationByHandleEx
CreateSymbolicLinkW
MultiByteToWideChar
RtlUnwind
GetStringTypeW
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
EncodePointer
DecodePointer
LCMapStringEx
CompareStringEx
GetCPInfo
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetCurrentProcess
TerminateProcess
QueryPerformanceCounter
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlPcToFileHeader
RaiseException
RtlUnwindEx
InterlockedPushEntrySList
InterlockedFlushSList
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
ExitProcess
GetModuleHandleExW
GetModuleFileNameW
GetCommandLineA
GetCommandLineW
GetCurrentThread
HeapAlloc
HeapFree
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
IsThreadAFiber
VirtualProtect
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetFileType
GetConsoleOutputCP
SetFilePointerEx

Delayed Imports

101

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0xca7a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.21621
Detected Filetype PE Executable
MD5 2583d4f374a4949fb6a090a7514fa243 🔍
SHA1 83cd58142053253f009db07da1977568dcfd4104 🔍
SHA256 cebdb845effdca26e843e74187bf9223d2de53de6ddee27b811d732dc01f8e52 🔍
SHA3 4ea1a8ad5d83b0cae8ea19477b133427fff1029e57e7fe4d2e00080553c71e8b 🔍

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x270
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.21484
MD5 65ec1ffeec327d05db5b62265557b264 🔍
SHA1 c13c73da66bdda2c0ef70f97dbd4482cf42e2349 🔍
SHA256 80e6a84f976e0dac109fb32cdb4f8365e77d2f5b03a4105210b2d4f1cb3a2808 🔍
SHA3 cfbde85ca53d6af332221b7722aabf3582bca52dd10488325856b2cbf4a64487 🔍

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName preazy.cc
FileDescription preazy.cc launcher
FileVersion (#2) 1.0.0.0
InternalName preazy.cc
OriginalFilename preazy.cc.exe
ProductName preazy.cc
ProductVersion (#2) 1.0.0.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Sep-04 22:27:30
Version 0.0
SizeofData 104
AddressOfRawData 0xef5d8
PointerToRawData 0xee5d8
Referenced File C:\Users\ghait\Downloads\SRC\P1XEL\build\bin\x64\Preazy-ESP-Audit\preazy.cc.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Sep-04 22:27:30
Version 0.0
SizeofData 20
AddressOfRawData 0xef640
PointerToRawData 0xee640

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Sep-04 22:27:30
Version 0.0
SizeofData 1012
AddressOfRawData 0xef654
PointerToRawData 0xee654

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140102200

RICH Header

XOR Key 0xf12789db
Unmarked objects 0
C++ objects (33145) 174
C objects (33145) 17
ASM objects (33145) 8
ASM objects (35207) 10
C objects (35207) 16
C++ objects (35207) 85
C objects (CVTCIL) (33145) 1
Imports (33145) 13
Total imports 145
C++ objects (35227) 1
Resource objects (35227) 1
151 1
Linker (35227) 1

Errors

Leave a comment

No comments yet.