| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Nov-03 17:59:06 |
| Detected languages |
English - United States
|
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 13/72 (Scanned on 2025-11-04 16:14:16) |
APEX:
Malicious
CrowdStrike: win/grayware_confidence_70% (D) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS ESET-NOD32: a variant of Win32/GameHack_AGen.AHN potentially unsafe MaxSecure: Trojan.Malware.300983.susgen McAfeeD: Real Protect-LS!FB6A554FD7DE Microsoft: Trojan:Win32/Sabsik.EN.A!ml Paloalto: generic.ml Sangfor: Suspicious.Win32.Save.a Skyhigh: BehavesLike.Win32.Generic.jh Sophos: Mal/Generic-S |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2025-Nov-03 17:59:06 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x65a00 |
| SizeOfInitializedData | 0x30a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00064E6E (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x67000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x99000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GlobalLock
WideCharToMultiByte GlobalUnlock GetLocaleInfoA LoadLibraryA QueryPerformanceFrequency GetProcAddress QueryPerformanceCounter VirtualFree VirtualAlloc VirtualQuery HeapCreate VirtualProtect HeapFree Thread32Next Thread32First GetCurrentThreadId SuspendThread ResumeThread CreateToolhelp32Snapshot GlobalAlloc HeapReAlloc CloseHandle HeapAlloc GetThreadContext GetCurrentProcessId FlushInstructionCache SetThreadContext OpenThread Sleep InitializeSListHead GetSystemTimeAsFileTime IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess SetUnhandledExceptionFilter UnhandledExceptionFilter SleepConditionVariableSRW WakeAllConditionVariable AcquireSRWLockExclusive ReleaseSRWLockExclusive GlobalFree MultiByteToWideChar AllocConsole CreateThread GetModuleHandleA GetLastError GetCurrentProcess |
|---|---|
| USER32.dll |
GetKeyState
GetMessageExtraInfo LoadCursorA SetClipboardData ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow SetCapture SetCursor GetClientRect IsWindowUnicode ReleaseCapture SetCursorPos SetWindowLongA GetClipboardData EmptyClipboard CloseClipboard OpenClipboard GetCursorPos CallWindowProcA |
| SHELL32.dll |
ShellExecuteW
|
| MSVCP140.dll |
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@I@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@P6AAAVios_base@1@AAV21@@Z@Z ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UAE@XZ ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QAE@PAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?good@ios_base@std@@QBE_NXZ ?always_noconv@codecvt_base@std@@QBE_NXZ ??1_Lockit@std@@QAE@XZ ??0_Lockit@std@@QAE@H@Z ?_Getgloballocale@locale@std@@CAPAV_Locimp@12@XZ ?_Id_cnt@id@locale@std@@0HA ?_Xout_of_range@std@@YAXPBD@Z ?_Xlength_error@std@@YAXPBD@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QAEXH_N@Z ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAE@XZ ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IAE@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAE@XZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPBD_J@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UAE@XZ ?_Init@locale@std@@CAPAV_Locimp@12@_N@Z ?_Xbad_alloc@std@@YAXXZ ?id@?$numpunct@D@std@@2V0locale@2@A ??1facet@locale@std@@MAE@XZ ??0facet@locale@std@@IAE@I@Z ?_Decref@facet@locale@std@@UAEPAV_Facet_base@3@XZ ?_Incref@facet@locale@std@@UAEXXZ ?_Gettrue@_Locinfo@std@@QBEPBDXZ ?_Getfalse@_Locinfo@std@@QBEPBDXZ ?_Getlconv@_Locinfo@std@@QBEPBUlconv@@XZ ?_Getcvt@_Locinfo@std@@QBE?AU_Cvtvec@@XZ ??1_Locinfo@std@@QAE@XZ ??0_Locinfo@std@@QAE@PBD@Z ?uncaught_exceptions@std@@YAHXZ ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Fiopen@std@@YAPAU_iobuf@@PBDHH@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SAIPAPBVfacet@locale@2@PBV42@@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAE_JPBD_J@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHD@Z ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QBEHAAU_Mbstatet@@PAD1AAPAD@Z ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QBE?AVlocale@2@XZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAPAD0PAH001@Z ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEXXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@XZ ?in@?$codecvt@DDU_Mbstatet@@@std@@QBEHAAU_Mbstatet@@PBD1AAPBDPAD3AAPAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QBEHAAU_Mbstatet@@PBD1AAPBDPAD3AAPAD@Z |
| IMM32.dll |
ImmSetCandidateWindow
ImmReleaseContext ImmGetContext ImmSetCompositionWindow |
| VCRUNTIME140.dll |
memcpy
memset _CxxThrowException _except_handler4_common __std_type_info_destroy_list strchr strstr __std_terminate __std_exception_copy __std_exception_destroy memchr __CxxFrameHandler3 memmove |
| api-ms-win-crt-stdio-l1-1-0.dll |
__acrt_iob_func
_get_stream_buffer_pointers _fseeki64 freopen_s fsetpos ungetc setvbuf fgetpos fgetc fputc ftell __stdio_common_vsscanf fread __stdio_common_vsprintf _wfopen fwrite fflush fclose __stdio_common_vfprintf fseek |
| api-ms-win-crt-runtime-l1-1-0.dll |
_seh_filter_dll
_configure_narrow_argv _initialize_narrow_environment _initialize_onexit_table _register_onexit_function _execute_onexit_table _crt_atexit _invalid_parameter_noinfo_noreturn _initterm _initterm_e _cexit |
| api-ms-win-crt-convert-l1-1-0.dll |
strtoul
atof |
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
calloc free _callnewh |
| api-ms-win-crt-math-l1-1-0.dll |
_ldclass
_dsign _fdsign _libm_sse2_cos_precise _ldsign _CIatan2 _libm_sse2_pow_precise _CIfmod _dclass _libm_sse2_sin_precise _libm_sse2_sqrt_precise ceil _fdclass _libm_sse2_acos_precise _hypotf |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-string-l1-1-0.dll |
strncpy
strncmp isdigit |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_unlock_file
_lock_file |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Nov-03 17:59:06 |
| Version | 0.0 |
| SizeofData | 824 |
| AddressOfRawData | 0x90fac |
| PointerToRawData | 0x8fdac |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Nov-03 17:59:06 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x100912f4 |
|---|---|
| EndAddressOfRawData | 0x100912fc |
| AddressOfIndex | 0x100949e8 |
| AddressOfCallbacks | 0x10067364 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x10094040 |
| SEHandlerTable | 0x10090e44 |
| SEHandlerCount | 55 |
| XOR Key | 0x3a9095a8 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 16 |
| ASM objects (34321) | 7 |
| C objects (34321) | 10 |
| C++ objects (34321) | 25 |
| Imports (34321) | 4 |
| Imports (33140) | 13 |
| Total imports | 262 |
| C++ objects (LTCG) (34810) | 19 |
| Resource objects (34810) | 1 |
| Linker (34810) | 1 |
No comments yet.