| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Jun-08 22:51:54 |
| Detected languages |
English - United States
|
| TLS Callbacks | 2 callback(s) detected. |
| Suspicious | The PE is possibly packed. | Unusual section name found: .xdata |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/71 (Scanned on 2026-05-22 21:36:56) | APEX: Malicious |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 10 |
| TimeDateStamp | 2025-Jun-08 22:51:54 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x370c00 |
| SizeOfInitializedData | 0xe4600 |
| SizeOfUninitializedData | 0x12a00 |
| AddressOfEntryPoint | 0x00000000000013E0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x46d000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x462e07 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| msvcrt.dll |
___lc_codepage_func
___mb_cur_max_func __getmainargs __initenv __iob_func __set_app_type __setusermatherr _acmdln _amsg_exit _assert _beginthreadex _cexit _commode _endthreadex _errno _fmode _gmtime64 _i64toa _initterm _ismbblead _itoa _localtime64 _lock _ltoa _mktime64 _pclose _popen _setjmp _strrev _strtoui64 _strtoi64 _time64 _ui64toa _ultoa _unlock _wchdir _wfullpath _wmkdir _wstat abort acos asin atan atexit atof atoi calloc clearerr difftime clock exit fclose feof ferror fflush fgets fopen fprintf fputc fputs fread free freopen fseek ftell fwrite getc getenv isalnum isalpha iscntrl isdigit isgraph islower ispunct isspace isupper isxdigit localeconv log10 longjmp malloc memchr memcmp memcpy memmove memset qsort rand remove realloc rename setlocale setvbuf signal strcat strchr strcmp strcoll strcpy strerror strftime strlen strncmp strncpy strpbrk strrchr strspn strstr strtol strtoul system tan tmpfile tmpnam tolower ungetc toupper vfprintf wcscmp wcslen wcsncmp wcsstr wcstol |
|---|---|
| ADVAPI32.dll |
RegCloseKey
RegOpenKeyExW RegQueryValueExW |
| GDI32.dll |
BitBlt
ChoosePixelFormat CombineRgn CreateBitmap CreateCompatibleBitmap CreateCompatibleDC CreateDCW CreateDIBSection CreateFontIndirectW CreateRectRgn CreateSolidBrush DeleteDC DeleteObject DescribePixelFormat GetDIBits GetDeviceCaps GetICMProfileW GetPixelFormat GetTextExtentPoint32A GetTextMetricsW SelectObject SetPixel SetPixelFormat SwapBuffers |
| IMM32.dll |
ImmAssociateContext
ImmGetCandidateListW ImmGetCompositionFontW ImmGetCompositionStringW ImmGetContext ImmGetIMEFileNameA ImmNotifyIME ImmReleaseContext ImmSetCandidateWindow ImmSetCompositionStringW ImmSetCompositionWindow |
| KERNEL32.dll |
AddVectoredExceptionHandler
AttachConsole CancelIoEx CloseHandle CompareStringA CopyFileExW CreateDirectoryW CreateEventW CreateFileA CreateFileMappingA CreateFileW CreateNamedPipeA CreatePipe CreateProcessW CreateSemaphoreW CreateThread DebugBreakProcess DeleteCriticalSection DeleteFileW DuplicateHandle EnterCriticalSection EnumResourceNamesW ExitProcess FileTimeToSystemTime FindClose FindFirstFileExW FindNextFileW FlushFileBuffers FormatMessageA FormatMessageW FreeEnvironmentStringsW FreeLibrary GenerateConsoleCtrlEvent GetCommandLineW GetConsoleMode GetCurrentDirectoryW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableA GetExitCodeProcess GetFileAttributesExW GetFileSizeEx GetFileTime GetFileType GetLastError GetLocaleInfoA GetLocaleInfoW GetLogicalDrives GetModuleFileNameA GetModuleFileNameW GetModuleHandleExW GetModuleHandleW GetOverlappedResult GetProcAddress GetProcessHeap GetProcessId GetStartupInfoA GetStdHandle GetSystemInfo GetSystemTimeAsFileTime GetTickCount GlobalAlloc GlobalFree GlobalLock GlobalMemoryStatusEx GlobalSize GlobalUnlock HeapAlloc HeapFree HeapReAlloc InitializeCriticalSection InitializeCriticalSectionAndSpinCount IsDBCSLeadByteEx IsWow64Process LeaveCriticalSection LoadLibraryA LoadLibraryExA LoadLibraryExW LoadLibraryW LocalFree MapViewOfFile MoveFileExW MulDiv MultiByteToWideChar OutputDebugStringW QueryPerformanceCounter QueryPerformanceFrequency RaiseException ReadDirectoryChangesW ReadFile ReleaseSemaphore RemoveDirectoryW RemoveVectoredExceptionHandler SetEnvironmentVariableA SetErrorMode SetEvent SetFilePointer SetFilePointerEx SetHandleInformation SetLastError SetNamedPipeHandleState SetThreadExecutionState SetThreadPriority SetUnhandledExceptionFilter Sleep SystemTimeToFileTime SystemTimeToTzSpecificLocalTime TerminateProcess TlsAlloc TlsFree TlsGetValue TlsSetValue TryEnterCriticalSection UnmapViewOfFile VerSetConditionMask VerifyVersionInfoW VirtualProtect VirtualQuery WaitForMultipleObjects WaitForSingleObject WaitForSingleObjectEx WideCharToMultiByte WinExec WriteConsoleW WriteFile __C_specific_handler |
| ole32.dll |
CoInitializeEx
CoUninitialize OleInitialize OleUninitialize RegisterDragDrop ReleaseStgMedium RevokeDragDrop |
| SETUPAPI.dll |
SetupDiDestroyDeviceInfoList
SetupDiEnumDeviceInfo SetupDiGetClassDevsA SetupDiGetDeviceInstanceIdA SetupDiGetDeviceRegistryPropertyW |
| SHELL32.dll |
CommandLineToArgvW
DragAcceptFiles DragFinish DragQueryFileW SHGetFolderPathW ShellExecuteW Shell_NotifyIconW |
| USER32.dll |
AdjustWindowRectEx
AttachThreadInput BeginPaint CallNextHookEx CallWindowProcW ChangeDisplaySettingsExW CheckMenuItem ClientToScreen ClipCursor CloseClipboard CreateIconFromResource CreateIconIndirect CreatePopupMenu CreateWindowExW DefWindowProcW DeleteMenu DestroyCursor DestroyIcon DestroyMenu DestroyWindow DialogBoxIndirectParamW DispatchMessageW DrawTextW EmptyClipboard EnableMenuItem EnableWindow EndDialog EndPaint EnumClipboardFormats EnumDisplayDevicesW EnumDisplayMonitors EnumDisplaySettingsW FillRect FlashWindowEx GetAsyncKeyState GetClassInfoExW GetClientRect GetClipCursor GetClipboardData GetClipboardFormatNameA GetClipboardSequenceNumber GetCursorPos GetDC GetDlgItem GetDoubleClickTime GetFocus GetForegroundWindow GetKeyState GetKeyboardLayout GetKeyboardState GetMenu GetMenuItemInfoW GetMessageExtraInfo GetMessagePos GetMessageTime GetMonitorInfoW GetPropW GetQueueStatus GetRawInputBuffer GetRawInputDeviceInfoA GetRawInputDeviceList GetSystemMetrics GetUpdateRect GetWindowLongPtrW GetWindowLongW GetWindowPlacement GetWindowRect GetWindowTextLengthW GetWindowTextW GetWindowThreadProcessId InsertMenuW IntersectRect InvalidateRect IsClipboardFormatAvailable IsIconic IsZoomed KillTimer LoadCursorW LoadIconW MapVirtualKeyW MessageBoxA MonitorFromPoint MonitorFromWindow MsgWaitForMultipleObjects OpenClipboard PeekMessageW PostMessageW PtInRect RegisterClassExW RegisterClassW RegisterClipboardFormatW RegisterRawInputDevices RegisterWindowMessageA ReleaseCapture ReleaseDC RemovePropW ScreenToClient SendMessageW SetActiveWindow SetCapture SetClipboardData SetCursor SetCursorPos SetFocus SetForegroundWindow SetLayeredWindowAttributes SetMenuItemInfoW SetParent SetPropW SetRectEmpty SetTimer SetWindowLongPtrW SetWindowLongW SetWindowPos SetWindowRgn SetWindowTextW SetWindowsHookExW ShowWindow SystemParametersInfoA SystemParametersInfoW ToUnicode TrackMouseEvent TrackPopupMenu TranslateMessage UnhookWindowsHookEx UnregisterClassW ValidateRect |
| VERSION.dll |
GetFileVersionInfoA
GetFileVersionInfoSizeA VerQueryValueA |
| WINMM.dll |
timeBeginPeriod
timeEndPeriod |
| StartAddressOfRawData | 0x14044c000 |
|---|---|
| EndAddressOfRawData | 0x14044c008 |
| AddressOfIndex | 0x140445dcc |
| AddressOfCallbacks | 0x14040f620 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x000000014035FA40
0x000000014035FA20 |
No comments yet.