f35c5cd11a73e104e91d2327c1525e12abe10fda3ccae7ebec62b791ed4c160e

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2067-Oct-21 20:19:54
Comments
CompanyName Atlas Playbook v0.5.0
FileDescription celerity
FileVersion 1.0.0.0
InternalName celerity.exe
LegalCopyright Copyright © Atlas Playbook v0.5.0 2026
LegalTrademarks
OriginalFilename celerity.exe
ProductName celerity
ProductVersion 1.0.0.0
Assembly Version 1.0.0.0

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • virus
Contains domain names:
  • High-Logic.com
  • Logic.com
  • Z-google.golang.org
  • apple.com
  • fontawesome.com
  • golang.org
  • google.golang.org
  • googleapis.com
  • googleprod.com
  • http://schemas.microsoft.com
  • http://schemas.microsoft.com/expression/blend/2008
  • http://schemas.microsoft.com/winfx/2006/xaml
  • http://schemas.microsoft.com/winfx/2006/xaml/presentation
  • http://schemas.openxmlformats.org
  • http://schemas.openxmlformats.org/markup-compatibility/2006
  • http://scripts.sil.org
  • http://scripts.sil.org/OFLOpen
  • http://scripts.sil.org/OFLhttp
  • http://www.apple.com
  • http://www.apple.com/
  • http://www.apple.com/Copyright
  • http://www.apple.com/http
  • https://fontawesome.com
  • https://fontawesome.comFont
  • https://fontawesome.comSolid
  • https://fontawesome.comVersion
  • https://rsms.me
  • https://t.me
  • microsoft.com
  • openxmlformats.org
  • schemas.microsoft.com
  • schemas.openxmlformats.org
  • scripts.sil.org
  • type.googleapis.com
  • type.googleprod.com
  • www.apple.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to RC5 or RC6
Uses known Mersenne Twister constants
Suspicious The PE is possibly packed. The PE only has 0 import(s).
Malicious VirusTotal score: 16/70 (Scanned on 2026-07-30 15:03:14) ALYac: Generic.Dacic.18276.5483CCEC
Arcabit: Generic.Dacic.18276.5483CCEC
BitDefender: Generic.Dacic.18276.5483CCEC
Bkav: W32.Malware.4A1AB1CE
CTX: exe.unknown.dacic
CrowdStrike: win/malicious_confidence_70% (D)
ESET-NOD32: Win64/GameHack.ND potentially unsafe application
Elastic: malicious (moderate confidence)
Emsisoft: Generic.Dacic.18276.5483CCEC (B)
GData: Generic.Dacic.18276.5483CCEC
McAfeeD: ti!F35C5CD11A73
MicroWorld-eScan: Generic.Dacic.18276.5483CCEC
Microsoft: Trojan:Win32/Wacatac.B!ml
Rising: Trojan.Kryptik@AI.86 (RDML:QTRess+5oNZEs7xoyAvXbw)
SentinelOne: Static AI - Suspicious PE
VIPRE: Generic.Dacic.18276.5483CCEC

Hashes

MD5 65122b6fffb86e071079c4519e7507cf
SHA1 abb3ac4e8996c5d2678136f8b16d554ed4385c82
SHA256 f35c5cd11a73e104e91d2327c1525e12abe10fda3ccae7ebec62b791ed4c160e
SHA3 8e99470e64b39da921baf262b895110302b14aa1e30cd9a17f62b18d44123c75
SSDeep 98304:ytDGcpNdWqX35vkJdH20gezyRoDxE6u+ONpKzQ/dB5W8791S:XcpzRpG5eoVG+OSQ/vh98
Imports Hash d41d8cd98f00b204e9800998ecf8427e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 2
TimeDateStamp 2067-Oct-21 20:19:54
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 48.0
SizeOfCode 0x6d0000
SizeOfInitializedData 0x9c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000000000 (Section: ?)
BaseOfCode 0x2000
ImageBase 0x140000000
SectionAlignment 0x2000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x6dc000
SizeOfHeaders 0x200
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x400000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x2000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e7aaf54ff3b3ee71bbcffc8d9c5093c0
SHA1 a5bee0719265feb0c4033ea90c831650d682cf6e
SHA256 fb7aabc354184f033b6b71386abd4fe6c7e53a2ec557414f291fc2c7039a4c37
SHA3 90c0298624340bd2fb8d52781f7307e4f0e89a0bf154b64a9b2901685afdf7b9
VirtualSize 0x6cff94
VirtualAddress 0x2000
SizeOfRawData 0x6d0000
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.58778

.rsrc

MD5 f667fcb062a41d11f776930e47eb794d
SHA1 ea77df7303d2332f48f2a06f493b846a17e9df1f
SHA256 b5ae4f31b02f9a28017f5b14e1ee4a815ac4db4b07dc612e80cd717ec9e721df
SHA3 69ffcfe34dd9578c8d10d4835cf8a26cd1d3ed4df9bda031509b7e7fefd09525
VirtualSize 0x9b4c
VirtualAddress 0x6d2000
SizeOfRawData 0x9c00
PointerToRawData 0x6d0200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.29202

Imports

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.17341
MD5 12cca7c1bf287f53b9b344a28fa6f69e
SHA1 bb4e20fbfb5a385c03131d65af705e8cc392353f
SHA256 d9c7b6455db616ded87b2ee62032b11cd4865cc2127085cbd9daf5b6cd2c77a4
SHA3 ec1efa88f6dbe68e7f891dfaef70e34a909e08d37a865cf9cdba2eaedde01771

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Icon file
MD5 fcf5da4bc7867f13b4025ad65c455f48
SHA1 b2d8d91f2a4a2c3c504f8b87d417c382838e0f2f
SHA256 8b10bf294e8d3fe252a5488ea8ae69fe8f06837079a5c6a4e84312a5ec334dee
SHA3 6f3bc5d6f0ea376c2c039a4e19233fe2a6f6731b870dac96b33a0768bc563742

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x370
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28198
MD5 d826636c6bf2ce7cf20f4913ad79f6a6
SHA1 c51f8f65a553bf8dc03cfc2d8d458279c75e28b7
SHA256 ad13c5fd427a0c5e30e9ef52d6c84c553d67cf76075b76ae8b347321cfaece07
SHA3 32b241bd1ede0891608b5d598130f4b05c52e7a1a3d78172bb02bd450e7d2be7

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x1ea
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.00112
MD5 b7db84991f23a680df8e95af8946f9c9
SHA1 cac699787884fb993ced8d7dc47b7c522c7bc734
SHA256 539dc26a14b6277e87348594ab7d6e932d16aabb18612d77f29fe421a9f1d46a
SHA3 4f72877413d13a67b52b292a8524e2c43a15253c26aaf6b5d0166a65bc615cff

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments
CompanyName Atlas Playbook v0.5.0
FileDescription celerity
FileVersion (#2) 1.0.0.0
InternalName celerity.exe
LegalCopyright Copyright © Atlas Playbook v0.5.0 2026
LegalTrademarks
OriginalFilename celerity.exe
ProductName celerity
ProductVersion (#2) 1.0.0.0
Assembly Version 1.0.0.0
Resource LangID UNKNOWN

UNKNOWN

Characteristics 0
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

Load Configuration

RICH Header

Errors

Leave a comment

No comments yet.