1ba1241e24a02addddadbcae307a7c61fc7b7081e48592c2bff9afe166bedc5a

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Aug-24 13:05:42
Detected languages English - United States
TLS Callbacks 1 callback(s) detected.
CompanyName vanator
FileDescription Strafe Macro
FileVersion 1.1.0
ProductName Strafe Macro
ProductVersion 1.1.0

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Tries to detect virtualized environments:
  • HARDWARE\DESCRIPTION\System
Looks for VMWare presence:
  • VMTools
  • VMware
  • vmware
Looks for VirtualBox presence:
  • SOFTWARE\Oracle\VirtualBox Guest Additions
  • VBoxGuest
  • VBoxMouse
  • VBoxService
Looks for Qemu presence:
  • qemu
May have dropper capabilities:
  • CurrentControlSet\Services
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • birthpopuptypesapplyImagebeinguppernoteseveryshowsmeansextramatchtrackknownearlybegansuperpapernorthlearngivennamedendedTermspartsGroupbrandusingwomanfalsereadyaudiotakeswhile.com
  • developer.microsoft.com
  • genretrucklooksValueFrame.net
  • github.com
  • http://dummy.testC
  • http://www.C
  • http://www.a
  • http://www.css
  • http://www.hortcut
  • http://www.icon
  • http://www.interpretation
  • http://www.language
  • http://www.style
  • http://www.text-decoration
  • http://www.w3.org
  • http://www.w3.org/shortcut
  • http://www.wencodeURIComponent
  • http://www.years
  • https://developer.microsoft.com
  • https://developer.microsoft.com/en-us/microsoft-edge/webview2
  • https://github.com
  • https://www.World
  • https://www.recent
  • microsoft.com
  • thing.org
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to RC5 or RC6
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryExA
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegQueryValueExW
  • RegGetValueW
  • RegCloseKey
  • RegOpenKeyExW
Possibly launches other programs:
  • ShellExecuteW
  • CreateProcessW
Uses Windows's Native API:
  • NtCreateNamedPipeFile
  • NtOpenFile
  • NtWriteFile
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
  • MapVirtualKeyW
Can take screenshots:
  • CreateCompatibleDC
  • BitBlt
  • GetDC
Suspicious VirusTotal score: 1/71 (Scanned on 2026-08-24 13:53:24) DeepInstinct: MALICIOUS

Hashes

MD5 f2d2b1c9d5da0aeba4e8ca03f9f25bd9 🔍
SHA1 bad91183528c4ac3ef381d62712c687ad39e6266 🔍
SHA256 1ba1241e24a02addddadbcae307a7c61fc7b7081e48592c2bff9afe166bedc5a 🔍
SHA3 72ac93510a16ad0d0782d2eb384ffaa798fc4d3cf5479111cbc0d698ce5b856d 🔍
SSDeep 49152:lON15/VMV5an9C+Q56cTFrwUgWdCcYlU8AXgtAwOt2XeNIz35VN5Ns8WcieEZx7:I5/VqafQ5g+rDL9lX2gl0 🔍
Imports Hash 5367f47c9ba4669d06a2046f6a326481 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-24 13:05:42
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x1e4800
SizeOfInitializedData 0xa9800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000001D65C0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x293000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 19d89a512ccc8da083cc27b4cf8082ba 🔍
SHA1 1e1f721e46f053febef08f6bb20c687a790c73e4 🔍
SHA256 b352e1c9237aced0a40609ae1e9c058a1d9bbc4e6549d8f60a6ee50eeae3324c 🔍
SHA3 3ea74063671c558b7216a4fda0ef4b49fdcd650595b7149317b2e5071e626db1 🔍
VirtualSize 0x1e47e0
VirtualAddress 0x1000
SizeOfRawData 0x1e4800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.27122

.rdata

MD5 506f31e8addf5a71b3485859fe5e0f82 🔍
SHA1 eb0d48d416399c8a94fcfeabc82a91cd83c4ffd8 🔍
SHA256 b599bd0427c8adc40760d020c726c6d2f04b58f7c5a7771f64b0aabe5c98230e 🔍
SHA3 a91cbf7c1739927785635a537a15730a7f83ec2079eb7223274d94168637931d 🔍
VirtualSize 0x96ea2
VirtualAddress 0x1e6000
SizeOfRawData 0x97000
PointerToRawData 0x1e4c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.03225

.data

MD5 5f7fe832ae7e7d616c4302b819fa7104 🔍
SHA1 fc81c321e5aa0aa0e62de9b079116210371b06ab 🔍
SHA256 8f81042d6cbd073bb3209ad7c4d61733000e815da3f08cfd1b8138610793e980 🔍
SHA3 ee551f88c73a1f4084d60f1192d1a9b88aa4013f6e3e1f94de0100985c31ee06 🔍
VirtualSize 0x2e98
VirtualAddress 0x27d000
SizeOfRawData 0xa00
PointerToRawData 0x27bc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.6886

.pdata

MD5 6854abb40ad713e9f4acb3a2a78fbb4c 🔍
SHA1 13aebe588fc0f064ed7651eca29db0d8c4ae96c1 🔍
SHA256 a92f4a1a168bdaaebd7557569b821028a87f8917a7376cd23a5555232feaa900 🔍
SHA3 5151839a738fef1406f1b9708586d5f63007923cfde71044272c202b7305366f 🔍
VirtualSize 0xe640
VirtualAddress 0x280000
SizeOfRawData 0xe800
PointerToRawData 0x27c600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.09917

.rsrc

MD5 2999bd66d07426c1f8e016f237905137 🔍
SHA1 eceb4a38519705dad19164c258e52104d5ac7608 🔍
SHA256 2b9ddd0e18739102e3cdd1cde58f6cd08fea79414008a738aba869abccee2f67 🔍
SHA3 568c0c4d59adc3f8c6e256b28957603a092aa594901ea44b4feef86b746a172c 🔍
VirtualSize 0x4a4
VirtualAddress 0x28f000
SizeOfRawData 0x600
PointerToRawData 0x28ae00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.83803

.reloc

MD5 08c88c38097a72d435bf3dca27042964 🔍
SHA1 5491f003e977937780dcc92ff780ed8f642601fc 🔍
SHA256 8564efdea80db80d698c3b1ab6227aa0e32a300c1248a818c0e5f10a808b2e33 🔍
SHA3 b3efbd42d1a8835a8f86d492d3b1cb5173315821485e4353b284d1172fc536d9 🔍
VirtualSize 0x2ed4
VirtualAddress 0x290000
SizeOfRawData 0x3000
PointerToRawData 0x28b400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.41995

Imports

bcryptprimitives.dll ProcessPrng
ntdll.dll NtCreateNamedPipeFile
RtlGetVersion
NtOpenFile
NtWriteFile
RtlNtStatusToDosError
kernel32.dll ReleaseSRWLockExclusive
SetThreadStackGuarantee
GetCurrentThread
lstrlenW
GetProcessHeap
HeapFree
HeapReAlloc
SwitchToThread
WakeAllConditionVariable
SleepConditionVariableSRW
GetSystemTimeAsFileTime
GetModuleFileNameW
GetWindowsDirectoryW
RtlPcToFileHeader
RaiseException
FlsAlloc
LoadLibraryA
FlsGetValue
LCIDToLocaleName
GetUserDefaultUILanguage
FlsSetValue
FlsFree
EncodePointer
GetModuleHandleA
GetCurrentThreadId
RtlLookupFunctionEntry
SetLastError
WaitForSingleObjectEx
GetCurrentProcess
GetCurrentProcessId
WideCharToMultiByte
ReleaseMutex
WaitForSingleObject
MultiByteToWideChar
HeapAlloc
SleepEx
GetFinalPathNameByHandleW
FindNextFileW
GetTempPathW
GetFileAttributesW
GetFileInformationByHandleEx
GetFileInformationByHandle
FindClose
FindFirstFileExW
SetFileInformationByHandle
GetSystemDirectoryW
SetFileTime
GetFullPathNameW
WriteConsoleW
GetConsoleOutputCP
CompareStringOrdinal
Sleep
GetConsoleMode
GetStdHandle
GetModuleHandleW
GetProcAddress
DuplicateHandle
CloseHandle
AcquireSRWLockExclusive
FormatMessageW
FreeLibrary
GetLastError
LoadLibraryExW
OutputDebugStringW
OutputDebugStringA
GetSystemTimePreciseAsFileTime
ExitProcess
LoadLibraryExA
SetWaitableTimer
LoadLibraryW
GetSystemInfo
shell32.dll DragQueryFileW
DragFinish
SHAppBarMessage
SHGetKnownFolderPath
ShellExecuteW
ole32.dll CoInitializeEx
CoUninitialize
CoTaskMemAlloc
CoCreateFreeThreadedMarshaler
CoCreateInstance
RevokeDragDrop
CoTaskMemFree
OleInitialize
RegisterDragDrop
api-ms-win-core-synch-l1-2-0.dll WaitOnAddress
WakeByAddressSingle
WakeByAddressAll
gdi32.dll CreateDIBSection
CreateCompatibleDC
SetTextColor
SetBkMode
CombineRgn
GetDeviceCaps
DeleteDC
CreateSolidBrush
CreateRectRgn
BitBlt
SelectObject
DeleteObject
comctl32.dll DefSubclassProc
TaskDialogIndirect
RemoveWindowSubclass
SetWindowSubclass
user32.dll GetForegroundWindow
IsWindowEnabled
SetCursorPos
SetWindowTextW
IsWindowVisible
GetWindowTextLengthW
EnableWindow
SetParent
SetPropW
GetKeyboardState
EnumDisplayMonitors
MonitorFromPoint
SetWindowDisplayAffinity
InvalidateRect
ToUnicodeEx
GetKeyState
MapVirtualKeyExW
GetKeyboardLayout
ShowCursor
ClipCursor
GetSystemMetrics
GetParent
GetClipCursor
IsWindow
SetWindowLongW
GetSystemMenu
GetWindowPlacement
GetMonitorInfoW
MonitorFromRect
SetWindowPlacement
ChangeDisplaySettingsExW
DefWindowProcW
RegisterRawInputDevices
IsProcessDPIAware
MonitorFromWindow
TrackPopupMenu
SetForegroundWindow
ClientToScreen
GetCursorPos
EnableMenuItem
AdjustWindowRectEx
GetMenu
DrawIconEx
SetWindowRgn
ScreenToClient
FindWindowExW
GetWindowLongW
RegisterTouchWindow
GetDC
ReleaseCapture
VkKeyScanW
AppendMenuW
InsertMenuW
SetCapture
SendInput
CheckMenuItem
DrawTextW
IsIconic
SetCursor
ReleaseDC
FillRect
GetWindowDC
OffsetRect
GetWindowRect
MapWindowPoints
GetClientRect
GetMenuBarInfo
GetMenuItemInfoW
ShowWindow
SendMessageW
PostQuitMessage
SystemParametersInfoA
PostMessageW
GetActiveWindow
SetFocus
SetMenu
RegisterWindowMessageA
RemoveMenu
CreateIcon
SetMenuItemInfoW
DrawMenuBar
CreatePopupMenu
CreateMenu
CreateAcceleratorTableW
DestroyAcceleratorTable
DestroyIcon
DestroyMenu
keybd_event
GetAsyncKeyState
TranslateAcceleratorW
MsgWaitForMultipleObjectsEx
MapVirtualKeyW
GetUpdateRect
PeekMessageW
PostThreadMessageW
GetWindow
LoadCursorW
ValidateRect
GetRawInputData
GetTouchInputInfo
SetWindowLongPtrW
DispatchMessageW
GetMessageW
UpdateWindow
FlashWindowEx
SystemParametersInfoW
EnumChildWindows
DispatchMessageA
TranslateMessage
GetMessageA
SetWindowPos
CreateWindowExW
RegisterClassExW
TrackMouseEvent
GetWindowLongPtrW
RedrawWindow
AdjustWindowRect
DestroyWindow
InvalidateRgn
CloseTouchInputHandle
GetWindowTextW
shlwapi.dll SHCreateMemStream
dwmapi.dll DwmSetWindowAttribute
DwmEnableBlurBehindWindow
DwmGetWindowAttribute
advapi32.dll RegQueryValueExW
RegGetValueW
RegCloseKey
RegOpenKeyExW
oleaut32.dll SysFreeString
GetErrorInfo
SetErrorInfo
SysStringLen
KERNEL32.dll RtlUnwindEx
SetUnhandledExceptionFilter
InitializeSListHead
AddVectoredExceptionHandler
RtlCaptureContext
RtlVirtualUnwind
GetCurrentDirectoryW
InitializeCriticalSectionEx
GetEnvironmentVariableW
ReadFileEx
WriteFileEx
QueryPerformanceFrequency
QueryPerformanceCounter
CreateThread
CreateFileW
CreateDirectoryW
GetEnvironmentStringsW
FreeEnvironmentStringsW
CreateProcessW
CreateWaitableTimerExW
SetEnvironmentVariableW
GetCommandLineW
CreateMutexA
DeleteCriticalSection
ADVAPI32.dll EventUnregister
EventSetInformation
EventWriteTransfer
EventRegister
api-ms-win-crt-string-l1-1-0.dll _wcsicmp
wcslen
wcscmp
strcpy_s
api-ms-win-crt-math-l1-1-0.dll roundf
__setusermatherr
pow
trunc
floor
round
api-ms-win-crt-convert-l1-1-0.dll _ultow_s
_wtoi
wcstol
api-ms-win-crt-runtime-l1-1-0.dll _set_app_type
_register_thread_local_exe_atexit_callback
_initialize_narrow_environment
_get_initial_narrow_environment
_initialize_onexit_table
_register_onexit_function
_crt_atexit
terminate
_initterm
_initterm_e
exit
_exit
abort
__p___argc
__p___argv
_seh_filter_exe
_cexit
_c_exit
_configure_narrow_argv
api-ms-win-crt-stdio-l1-1-0.dll _set_fmode
__p__commode
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
api-ms-win-crt-heap-l1-1-0.dll calloc
malloc
_callnewh
free
_set_new_mode

Delayed Imports

1

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x1e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15472
MD5 77e21bec0aa74b672fece63941063222 🔍
SHA1 a5979ce116bbb9d4c769c6afe4b03e3d62f36abc 🔍
SHA256 597cd497a1e70984120d9e2b6770fc168d2cf33fa50a19208144d75db96c5954 🔍
SHA3 8992b0194947f90f33505c7910a59200bbfcaab6974493cac390dfa26cf8169f 🔍

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x21b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.95944
MD5 1a612cfba86f4ea55d053f343c3569cf 🔍
SHA1 a84e67b829da52b99096346735d26272cfd01812 🔍
SHA256 9920a6d1ed420b051304a871bae1054954d09c2f502ab37b8a78e6872724bf6c 🔍
SHA3 4d2d22d3647050ee3179c3a82338d224a9ccce30b63d3b9a09116afd4b29eb38 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.1.0.0
ProductVersion 1.1.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName vanator
FileDescription Strafe Macro
FileVersion (#2) 1.1.0
ProductName Strafe Macro
ProductVersion (#2) 1.1.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-24 13:05:42
Version 0.0
SizeofData 1048
AddressOfRawData 0x2725c4
PointerToRawData 0x2711c4

TLS Callbacks

StartAddressOfRawData 0x140272a28
EndAddressOfRawData 0x140272bb4
AddressOfIndex 0x14027fd34
AddressOfCallbacks 0x1401e6af0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x00000001400517B0

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14027d840

RICH Header

XOR Key 0x85f84c14
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 14
ASM objects (35721) 9
C objects (35721) 13
C++ objects (35721) 46
Imports (33145) 5
Total imports 323
Unmarked objects (#2) 47
Resource objects (36243) 1
Linker (36243) 1

Errors

Leave a comment

No comments yet.