| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Jun-25 05:51:31 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\Elon Musk\source\repos\valorant-injector-main\build\hookloader.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 42/71 (Scanned on 2026-09-23 16:36:54) |
ALYac:
Gen:Variant.Yogi.22715
APEX: Malicious AVG: Win64:MalwareX-gen [Misc] Alibaba: Trojan:Win64/GenKryptik.feff6f5b Antiy-AVL: Trojan/Win64.GenKryptik Arcabit: Trojan.Yogi.D58BB Avast: Win64:MalwareX-gen [Misc] Avira: TR/W64.Agent BitDefender: Gen:Variant.Yogi.22715 CTX: exe.trojan.genkryptik DeepInstinct: MALICIOUS ESET-NOD32: Win64/GenKryptik_AGen.BXX trojan Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Yogi.22715 (B) F-Secure: Trojan.TR/W64.Agent Fortinet: W64/GenKryptik_AGen.BXX!tr GData: Gen:Variant.Yogi.22715 Google: Detected Gridinsoft: Trojan.Win64.Kryptik.oa!s1 Ikarus: Trojan.Win64.Krypt K7AntiVirus: Trojan ( 006d989d1 ) K7GW: Trojan ( 006d989d1 ) Lionic: Trojan.Win32.Generic.4!c Malwarebytes: Trojan.Downloader MaxSecure: Trojan.Malware.695667561.susgen McAfeeD: ti!F8629C51BB0C MicroWorld-eScan: Gen:Variant.Yogi.22715 Microsoft: Trojan:Win32/Kepavll!rfn Paloalto: generic.ml Panda: Trj/PhxIK.A Rising: Downloader.Agent!8.B23 (TFE:5:WfbQgJLG5wK) Skyhigh: BehavesLike.Win64.RapSFXpacked.nm Sophos: Mal/Generic-S Symantec: Trojan Horse Tencent: Malware.Win32.Gencirc.14b14107 TrellixENS: Artemis!AD100E026561 TrendMicro: Trojan.Win32.ZYX.USBLG626 TrendMicro-HouseCall: Trojan.Win32.ZYX.USBLG626 VIPRE: Gen:Variant.Yogi.22715 Varist: W64/ABTrojan.KJLO-8529 ViRobot: Trojan.Win.Z.Yogi.34304 alibabacloud: Trojan:Win/GenKryptik_AGen.BDF |
| MD5 | ad100e026561d360de921a4baf47fdb7 🔍 |
|---|---|
| SHA1 | 3f3bf64f0824d81006535a72e29999d56ad92030 🔍 |
| SHA256 | f8629c51bb0c97c7848425705b59a8cb887b88225dbcf518228949ce263755df 🔍 |
| SHA3 | 4e39d73df05e0f225ea463e878d532405e5578f07d6b40d67b6863f50cab9fa2 🔍 |
| SSDeep | 384:Do9ZbonucNXW/KubqInO05XFIJTnCr31bRGJXRfWaY2RuZoijtBKYkOlCtNRuZo:c9Z2xNG/Kaq/AItA3dwJJWaYvL96x 🔍 |
| Imports Hash | 5654544fc4c95c8ddbff1c0577ac668b 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Jun-25 05:51:31 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x2c00 |
| SizeOfInitializedData | 0x5c00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000002DF8 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xd000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 0d4d779cccfd75433403b43ef07c29fa 🔍 |
|---|---|
| SHA1 | b1bcdfa65d7baf6435f27395d22cb56be3e7ea04 🔍 |
| SHA256 | 80aaa6edb857430f3754cccb0dc0f491eca459d5098ef431e8990ccb29834874 🔍 |
| SHA3 | 5a8e1928fb81c338825ea2d718f6f0d786f5bb5048a193199795a90ba9cc6947 🔍 |
| VirtualSize | 0x2bb9 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x2c00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.13673 |
| MD5 | 3397243df8c5823f1f41c334e37e9f9b 🔍 |
|---|---|
| SHA1 | 94e296b13f25f3d22d868aad3ade632c8a4ceca4 🔍 |
| SHA256 | 31f6d177b586231f69780e8b54a69bfaa89cccde4874305df2f68b57e8d2b5b4 🔍 |
| SHA3 | a3ef07bad776a3e7dc517822c0728aa68ef09c517839edd8c288cc70fea28021 🔍 |
| VirtualSize | 0x4b20 |
| VirtualAddress | 0x4000 |
| SizeOfRawData | 0x4c00 |
| PointerToRawData | 0x3000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.10649 |
| MD5 | 780f76ab5cf52c86296b2bdf1473c3bc 🔍 |
|---|---|
| SHA1 | c20493a5ca9207d14cda19a38beaa8d5aab67c50 🔍 |
| SHA256 | 0fe32acbb7b098f48c23337223b7c7d2d7ba77332c8495f21182c675ec3ed510 🔍 |
| SHA3 | 338c8fcae92a0f70dbcf9fbfad1f227caf90d45d58b45fa816a1f60d95f9e9b7 🔍 |
| VirtualSize | 0x768 |
| VirtualAddress | 0x9000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x7c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 2.10192 |
| MD5 | 46490e9657fdf348949d70f7bdfb0307 🔍 |
|---|---|
| SHA1 | 1e4d0d3f58d4fe78245d839de3cf7fa87cc4fbd3 🔍 |
| SHA256 | 99bf3f95a146d50e552a472b95f17e8b49c6672c004ee0ef3e5acc46fa08417e 🔍 |
| SHA3 | 0031d7e9d3bb9be88d730bf5d2fb60960ca932f0b9c36a8e1da296c244fd0890 🔍 |
| VirtualSize | 0x348 |
| VirtualAddress | 0xa000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x7e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 3.53504 |
| MD5 | ae46018e2eb1721187fc1aeee8663872 🔍 |
|---|---|
| SHA1 | bed55c6c4e207dfc859421b181d7e2e87adee5e7 🔍 |
| SHA256 | 52107afac0fedd9b1320a4a153a8f9aea34925aa43b039839dedcf44e55843f6 🔍 |
| SHA3 | 30588b77ae212fba5738bbf96aa465ab6e30cbb5c1aa0453ec285f01bb07ca46 🔍 |
| VirtualSize | 0x1e0 |
| VirtualAddress | 0xb000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x8200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.7015 |
| MD5 | 57e330b3368aac15c1b081ebddb2d562 🔍 |
|---|---|
| SHA1 | 4f866f7985e85645ae5fe309d07ea45dd2c174ff 🔍 |
| SHA256 | 58523d9e59cc4c0ab6335c56bcf5ed5a7ce536a0176358fbf1ce8e4072750ba5 🔍 |
| SHA3 | 5faa87779bc94c120aead84b6d792ceb4fa40102314dd2bd14d9915f186ee7db 🔍 |
| VirtualSize | 0x60 |
| VirtualAddress | 0xc000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x8400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 1.24296 |
| KERNEL32.dll |
GetProcAddress
GetFileAttributesW SetConsoleScreenBufferSize GetStdHandle SetConsoleWindowInfo LoadLibraryW GetConsoleWindow SetConsoleTitleW LoadLibraryExW RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId RtlLookupFunctionEntry FreeLibrary GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetModuleHandleW RtlCaptureContext |
|---|---|
| USER32.dll |
SetWindowsHookExW
UnhookWindowsHookEx FindWindowW GetWindowThreadProcessId GetWindowLongPtrW SetWindowLongPtrW SetWindowPos PostThreadMessageW |
| COMDLG32.dll |
GetOpenFileNameW
|
| MSVCP140.dll |
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ?good@ios_base@std@@QEBA_NXZ ?wcout@std@@3V?$basic_ostream@_WU?$char_traits@_W@std@@@1@A ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ ?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z ?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAA_JPEB_W_J@Z ?widen@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEBA_WD@Z ?put@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@_W@Z ?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?_Xlength_error@std@@YAXPEBD@Z ?uncaught_exceptions@std@@YAHXZ ?_Xout_of_range@std@@YAXPEBD@Z |
| dbghelp.dll |
ImageDirectoryEntryToData
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__std_exception_copy
__current_exception_context __current_exception _CxxThrowException __C_specific_handler memset memcpy __std_exception_destroy __std_terminate memmove |
| api-ms-win-crt-runtime-l1-1-0.dll |
__p___argc
_initialize_onexit_table _register_thread_local_exe_atexit_callback _crt_atexit terminate _get_initial_wide_environment exit _c_exit __p___wargv _invoke_watson _exit _initialize_wide_environment _configure_wide_argv _cexit _set_app_type _seh_filter_exe _initterm_e _initterm _register_onexit_function system |
| api-ms-win-crt-string-l1-1-0.dll |
_wcsicmp
|
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
free malloc _set_new_mode |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
| api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
_set_fmode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-25 05:51:31 |
| Version | 0.0 |
| SizeofData | 100 |
| AddressOfRawData | 0x7260 |
| PointerToRawData | 0x6260 |
| Referenced File | C:\Users\Elon Musk\source\repos\valorant-injector-main\build\hookloader.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-25 05:51:31 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x72c4 |
| PointerToRawData | 0x62c4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-25 05:51:31 |
| Version | 0.0 |
| SizeofData | 720 |
| AddressOfRawData | 0x72d8 |
| PointerToRawData | 0x62d8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-25 05:51:31 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140009040 |
| XOR Key | 0x7ab5066c |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 12 |
| ASM objects (35207) | 3 |
| C objects (35207) | 10 |
| C++ objects (35207) | 27 |
| Imports (35207) | 6 |
| Imports (33145) | 9 |
| Total imports | 115 |
| C++ objects (LTCG) (35228) | 5 |
| Resource objects (35228) | 1 |
| Linker (35228) | 1 |
No comments yet.