| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jun-04 17:38:09 |
| Detected languages |
English - United States
|
| TLS Callbacks | 4 callback(s) detected. |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x128 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Jun-04 17:38:09 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xfec00 |
| SizeOfInitializedData | 0x458800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000FC300 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x55a000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| D3DCOMPILER_47.dll |
D3DCompile
|
| KERNEL32.dll |
Process32NextW
LoadLibraryA TlsAlloc Process32FirstW VirtualProtectEx GetProcAddress VirtualAllocEx ReadProcessMemory CreateRemoteThread VirtualFreeEx IsWow64Process GetExitCodeProcess CreateDirectoryW VirtualProtect TerminateProcess GetModuleFileNameW Thread32Next Thread32First GetCurrentThreadId SuspendThread ResumeThread GetModuleHandleA GetTickCount64 ReleaseSRWLockExclusive GetCurrentThread AcquireSRWLockExclusive QueryPerformanceFrequency ReleaseSRWLockShared Module32FirstW GetThreadContext SetFilePointerEx AcquireSRWLockShared GetFileSize ExitProcess GetCurrentProcessId GetModuleHandleW GetProcessHeap Module32NextW QueryFullProcessImageNameW Sleep GetTickCount OpenThread IsDebuggerPresent GetComputerNameA CheckRemoteDebuggerPresent DeviceIoControl GetComputerNameW SetThreadPriority VirtualAlloc SetProcessWorkingSetSize VirtualFree OutputDebugStringA FlushInstructionCache DebugBreak SetThreadContext FreeLibrary GlobalAlloc GlobalFree GlobalLock GlobalUnlock GetLocaleInfoA SetUnhandledExceptionFilter GetLocalTime MapViewOfFile UnmapViewOfFile CreateFileMappingA SleepConditionVariableSRW WakeAllConditionVariable GetStartupInfoW GetSystemTimeAsFileTime InitializeSListHead LocalFree CreateToolhelp32Snapshot OpenProcess RtlAddFunctionTable GetCurrentProcess WriteProcessMemory HeapAlloc CreateThread GetLastError ReadFile QueryPerformanceCounter CloseHandle DeleteFileW MultiByteToWideChar SetFileAttributesW CreateFileW GetVolumeInformationA GetTempPathW SetFilePointer WriteFile HeapFree FlushFileBuffers GetFileSizeEx CreateFileA WideCharToMultiByte |
| USER32.dll |
MoveWindow
EnumWindows GetWindowLongW DefWindowProcW DispatchMessageA DestroyWindow CreateWindowExW UnregisterClassW RegisterClassExW ShowWindow SetLayeredWindowAttributes TranslateMessage LoadIconW SetWindowLongW PeekMessageA UpdateWindow GetKeyState GetMessageExtraInfo EnumDesktopWindows ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow SetCapture SetCursor GetClientRect IsWindowUnicode GetClassNameW PostQuitMessage GetDesktopWindow GetAsyncKeyState SetClipboardData GetClipboardData EmptyClipboard CloseClipboard GetWindowRect SendMessageTimeoutW RedrawWindow OpenClipboard GetCursorPos SetCursorPos ReleaseCapture SystemParametersInfoW GetWindowTextW LoadCursorA GetSystemMetrics |
| ADVAPI32.dll |
RegSetValueExW
RegEnumKeyExA RegCloseKey RegQueryValueExA GetUserNameA OpenProcessToken AdjustTokenPrivileges LookupPrivilegeValueW RegOpenKeyExA GetUserNameW RegCreateKeyExW |
| SHELL32.dll |
SHGetFolderPathW
SHCreateDirectoryExW |
| ole32.dll |
CoInitializeEx
CoUninitialize CoCreateInstance CoSetProxyBlanket |
| OLEAUT32.dll |
VariantInit
SysFreeString SysAllocString VariantClear |
| MSVCP140.dll |
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z ?good@ios_base@std@@QEBA_NXZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ _Xtime_get_ticks ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z ?uncaught_exceptions@std@@YAHXZ _Mtx_unlock _Query_perf_frequency ?_Throw_Cpp_error@std@@YAXH@Z ?_Xout_of_range@std@@YAXPEBD@Z ?_Xlength_error@std@@YAXPEBD@Z _Mtx_lock _Cnd_do_broadcast_at_thread_exit _Query_perf_counter _Thrd_detach |
| WINHTTP.dll |
WinHttpQueryDataAvailable
WinHttpCrackUrl WinHttpConnect WinHttpQueryOption WinHttpReceiveResponse WinHttpOpen WinHttpQueryHeaders WinHttpReadData WinHttpOpenRequest WinHttpSetOption WinHttpCloseHandle WinHttpSendRequest WinHttpSetTimeouts |
| bcrypt.dll |
BCryptGetProperty
BCryptOpenAlgorithmProvider BCryptFinishHash BCryptCloseAlgorithmProvider BCryptDestroyHash BCryptHashData BCryptCreateHash |
| IPHLPAPI.DLL |
GetAdaptersAddresses
GetAdaptersInfo |
| CRYPT32.dll |
CertFreeCertificateContext
|
| VERSION.dll |
GetFileVersionInfoSizeW
VerQueryValueW GetFileVersionInfoW |
| IMM32.dll |
ImmSetCandidateWindow
ImmSetCompositionWindow ImmReleaseContext ImmGetContext |
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| d3dx11_43.dll |
D3DX11CreateShaderResourceViewFromMemory
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__std_terminate
__C_specific_handler wcsstr strstr strrchr longjmp __std_exception_destroy wcschr memmove memset memchr memcmp __current_exception __current_exception_context __intrinsic_setjmp _CxxThrowException memcpy __std_exception_copy |
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
_set_new_mode free _callnewh |
| api-ms-win-crt-time-l1-1-0.dll |
_time64
_localtime64 _mkgmtime64 |
| api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vsprintf_s
fflush __stdio_common_vfprintf _set_fmode _wfopen_s fclose fread _wfopen fwrite fseek __acrt_iob_func ftell __stdio_common_vsprintf __stdio_common_vsscanf __stdio_common_vswprintf_s __p__commode |
| api-ms-win-crt-runtime-l1-1-0.dll |
_beginthreadex
terminate _register_thread_local_exe_atexit_callback exit _c_exit _exit _initterm_e _initterm _get_narrow_winmain_command_line _configure_narrow_argv _set_app_type _seh_filter_exe _cexit _crt_atexit _register_onexit_function _initialize_onexit_table _initialize_narrow_environment _wassert |
| api-ms-win-crt-convert-l1-1-0.dll |
atoi
_wtoi strtol _wcstoui64 |
| api-ms-win-crt-string-l1-1-0.dll |
strlen
_wcslwr_s strncpy_s iswdigit wcsncpy_s strncpy strcmp strncmp wcslen _wcsicmp wcsncmp wcscmp |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
roundf acosf pow sin ceilf sinf cosf fmodf sqrtf |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-04 17:38:09 |
| Version | 0.0 |
| SizeofData | 1012 |
| AddressOfRawData | 0x190814 |
| PointerToRawData | 0x18f814 |
| StartAddressOfRawData | 0x140190c30 |
|---|---|
| EndAddressOfRawData | 0x140190d80 |
| AddressOfIndex | 0x1405394d8 |
| AddressOfCallbacks | 0x140100bd8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks |
0x000000014002E9B0
0x00000001400FBE10 0x000000014002CC00 0x00000001400FBE80 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1401a4040 |
| XOR Key | 0x18770b06 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 20 |
| Imports (21202) | 2 |
| C objects (33145) | 1 |
| 253 (35721) | 1 |
| ASM objects (35721) | 4 |
| C objects (35721) | 10 |
| C++ objects (35721) | 41 |
| Imports (35721) | 6 |
| C objects (VS2022 Update 1 (17.1.6) compiler 31107) | 26 |
| Imports (33145) | 33 |
| Total imports | 370 |
| C++ objects (LTCG) (36241) | 27 |
| Resource objects (36241) | 1 |
| 151 | 1 |
| Linker (36241) | 1 |
No comments yet.