| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2025-Dec-01 04:10:30 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\anett\source\repos\ACTUALIZADOR CALLEJERO\x64\Release\ACTUALIZADOR CALLEJERO.pdb
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 29/72 (Scanned on 2026-02-06 02:45:45) |
ALYac:
Gen:Variant.Application.Tedy.41798
APEX: Malicious Antiy-AVL: Trojan/Win32.Yomal Arcabit: Trojan.Application.Tedy.DA346 BitDefender: Gen:Variant.Application.Tedy.41798 Bkav: W64.AIDetectMalware CAT-QuickHeal: Trojan.Ghanarava.17696915292ab4f2 CTX: exe.trojan.yomal CrowdStrike: win/malicious_confidence_90% (W) DeepInstinct: MALICIOUS Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Application.Tedy.41798 (B) GData: Gen:Variant.Application.Tedy.41798 Google: Detected Lionic: Trojan.Win32.Yomal.4!c MaxSecure: Trojan.Malware.325937538.susgen McAfeeD: ti!DC9F905C0168 MicroWorld-eScan: Gen:Variant.Application.Tedy.41798 Microsoft: Trojan:Win32/Yomal!rfn Paloalto: generic.ml Sangfor: Trojan.Win32.Agent.Vapg Symantec: ML.Attribute.HighConfidence Trapmine: suspicious.low.ml.score TrellixENS: Artemis!549776BBA0A9 TrendMicro-HouseCall: Trojan.Win32.Gen.TL0101AO26 VIPRE: Gen:Variant.Application.Tedy.41798 Varist: W64/ABTrojan.OCHJ-8427 ViRobot: Trojan.Win.Z.Agent.546304.AE alibabacloud: Trojan:Win/Yomal.Gen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2025-Dec-01 04:10:30 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x61600 |
| SizeOfInitializedData | 0x25600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000032F5C (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x8c000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetModuleFileNameW
SetErrorMode GetVolumeInformationA FillConsoleOutputCharacterW CreateFileA GetDriveTypeA CloseHandle FillConsoleOutputAttribute SetConsoleOutputCP SetConsoleCursorPosition MultiByteToWideChar WriteConsoleW DeviceIoControl GetStdHandle SetVolumeLabelA GetConsoleScreenBufferInfo HeapSize SetEndOfFile GetProcessHeap SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetOEMCP GetACP IsValidCodePage GetCurrentDirectoryW CreateDirectoryW CreateFileW FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesW GetFileAttributesExW GetFileInformationByHandle GetFinalPathNameByHandleW SetFileInformationByHandle SetFileTime GetTempPathW AreFileApisANSI GetLastError GetModuleHandleW GetProcAddress CopyFileW CreateHardLinkW GetFileInformationByHandleEx CreateSymbolicLinkW WideCharToMultiByte LocalFree FormatMessageA GetLocaleInfoEx QueryPerformanceCounter QueryPerformanceFrequency Sleep GetCurrentThreadId LCMapStringEx InitializeCriticalSectionEx GetSystemTimeAsFileTime EnterCriticalSection LeaveCriticalSection DeleteCriticalSection EncodePointer DecodePointer CompareStringEx GetCPInfo GetStringTypeW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent GetCurrentProcessId InitializeSListHead IsDebuggerPresent GetStartupInfoW RtlUnwindEx RtlPcToFileHeader RaiseException SetLastError InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW GetFileType ReadFile TzSpecificLocalTimeToSystemTime SystemTimeToFileTime WriteFile ExitProcess GetModuleHandleExW GetCommandLineA GetCommandLineW GetFileSizeEx SetFilePointerEx HeapAlloc GetTimeZoneInformation FlushFileBuffers GetConsoleOutputCP GetConsoleMode HeapFree HeapReAlloc WaitForSingleObject GetExitCodeProcess CreateProcessW FlsAlloc FlsGetValue FlsSetValue FlsFree VirtualProtect GetDateFormatW GetTimeFormatW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW ReadConsoleW SetStdHandle RtlUnwind |
|---|---|
| ADVAPI32.dll |
FreeSid
CheckTokenMembership AllocateAndInitializeSid |
| SHELL32.dll |
ShellExecuteExW
SHChangeNotify |
| WININET.dll |
InternetReadFile
InternetOpenUrlA InternetOpenA HttpQueryInfoA InternetCloseHandle |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-01 04:10:30 |
| Version | 0.0 |
| SizeofData | 114 |
| AddressOfRawData | 0x766f4 |
| PointerToRawData | 0x750f4 |
| Referenced File | C:\Users\anett\source\repos\ACTUALIZADOR CALLEJERO\x64\Release\ACTUALIZADOR CALLEJERO.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-01 04:10:30 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x76768 |
| PointerToRawData | 0x75168 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-01 04:10:30 |
| Version | 0.0 |
| SizeofData | 920 |
| AddressOfRawData | 0x7677c |
| PointerToRawData | 0x7517c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-01 04:10:30 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140080080 |
| XOR Key | 0x37382ed6 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33140) | 194 |
| C objects (33140) | 17 |
| ASM objects (33140) | 8 |
| ASM objects (35207) | 10 |
| C objects (35207) | 17 |
| C++ objects (35207) | 91 |
| Imports (33140) | 9 |
| Total imports | 174 |
| C++ objects (LTCG) (35216) | 2 |
| Resource objects (35216) | 1 |
| Linker (35216) | 1 |
No comments yet.