| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Sep-04 04:44:39 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE is possibly packed. |
Unusual section name found: .hipFatB
Unusual section name found: .hip_fat Unusual section name found: .retarc Unusual section name found: .retard |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 4/70 (Scanned on 2026-09-04 07:30:06) |
APEX:
Malicious
Cynet: Malicious (score: 100) Microsoft: Trojan:Win32/Wacatac.B!ml Trapmine: suspicious.low.ml.score |
| MD5 | 4e6ad7911aea1ec866d78a95ef16b2e7 🔍 |
|---|---|
| SHA1 | 7876654b7371afaa7442112e66d45b7fc5f57e80 🔍 |
| SHA256 | 26fe30c10c719f491acb75002bed0e84c1e8793fe93ca1590e1cd8d4144a510e 🔍 |
| SHA3 | 822fbe9c97c10d8bbd5e324b71af38f61a3ef9735a32816d7ea19cd88d2e2b6a 🔍 |
| SSDeep | 24576:eypZgVZ1cGNtNI7ZyK5k1c7NLshWfLcKLY6cfNCO3x6XtVseKuNzqN5ti3Lu:tufIOhh8cgq7RFti3Lu 🔍 |
| Imports Hash | d6cab66436e83e07443420b26012e0e6 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x78 |
| e_cp | 0x1 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0 |
| e_ss | 0 |
| e_sp | 0 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x78 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 12 |
| TimeDateStamp | 2026-Sep-04 04:44:39 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x53400 |
| SizeOfInitializedData | 0x403400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000002B67C (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x463000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 7eaee59e991375eac63c72fa7e33139e 🔍 |
|---|---|
| SHA1 | c1f11b308ac59ea0bebd40c185efc429f9554682 🔍 |
| SHA256 | f37b52c892fbf0669a24e5a385329c7e9338e0447898946537208bb2516c678c 🔍 |
| SHA3 | 7454c698ada40b280772515df1b37cbb53a38e810092d235dc1deb54b725b0b8 🔍 |
| VirtualSize | 0x532b6 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x53400 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.39717 |
| MD5 | 7c3ece140f93c8619b1e9ab11f414025 🔍 |
|---|---|
| SHA1 | b3de68a7da98eb9cc3a7ae1a26d4fd9f887e1311 🔍 |
| SHA256 | 493a560669199325fdc08d345ab748d1ee113f3814bc05bc93988d263ddf1561 🔍 |
| SHA3 | 8605615774455993e1f43c30998d031bc7c3a855fe7ea2994379199bb10b48f3 🔍 |
| VirtualSize | 0x1c554 |
| VirtualAddress | 0x55000 |
| SizeOfRawData | 0x1c600 |
| PointerToRawData | 0x53800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.48789 |
| MD5 | 0bf6916eca840641cf51e66668b40e73 🔍 |
|---|---|
| SHA1 | c07ed9289ea7db365bba78b6024e55d44fcc504a 🔍 |
| SHA256 | 7826f6c8e7ddb81a9457afa0f35add81cb6ad5f6fa65cb24bdb6be7d7d88821f 🔍 |
| SHA3 | 668c735945bb900bc50b6d4593917069506125d016dda23589e609626d33eaf5 🔍 |
| VirtualSize | 0x4330 |
| VirtualAddress | 0x72000 |
| SizeOfRawData | 0x2200 |
| PointerToRawData | 0x6fe00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.95736 |
| MD5 | f6c308fcf7ae0d9c54ff056daaa1e706 🔍 |
|---|---|
| SHA1 | f644ff5efd097cf8708d37e6380bc134607667e8 🔍 |
| SHA256 | 6b18b411974c18929b59316568162bbd68b3f00bd9e76e53d1ae0abdf660d87e 🔍 |
| SHA3 | 8fc0c799d2cfe234ac120dc2d53ca93997ae64839c1dbda535dd87ee2607c08b 🔍 |
| VirtualSize | 0x3648 |
| VirtualAddress | 0x77000 |
| SizeOfRawData | 0x3800 |
| PointerToRawData | 0x72000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.65288 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x100 |
| VirtualAddress | 0x7b000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x75800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 9f81c16e36b56d16a46daf11bde218c5 🔍 |
|---|---|
| SHA1 | f787ae7a97820c91e4574492ce346f245cddaf56 🔍 |
| SHA256 | b3d6bdc277b05f5f84a88356b9fc7cc78796865b27ae96832f6435b743b2ff34 🔍 |
| SHA3 | f8fc231a6f7d9c05dfef37d2fe4e742982b9c3463b723d07228041ff91456dff 🔍 |
| VirtualSize | 0x18 |
| VirtualAddress | 0x7c000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x75a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 0.179433 |
| MD5 | 4452afe16a52721bd6d4e333ffe1c4ba 🔍 |
|---|---|
| SHA1 | b10945b33a5b107999d14ba1c8cb9174114fa82a 🔍 |
| SHA256 | f9d96a641a6aa4623fcd2041e3e4497f11c91f5e51ccf6d140e8bdebe30f891e 🔍 |
| SHA3 | fd344ab58cf56b984358665b7cb9f1f4b34f15c6a8eb7c53ce326952682e68d6 🔍 |
| VirtualSize | 0x3dd508 |
| VirtualAddress | 0x7d000 |
| SizeOfRawData | 0x3dd600 |
| PointerToRawData | 0x75c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.24311 |
| MD5 | 219468c4363f4e9f31e84bbd35354da8 🔍 |
|---|---|
| SHA1 | 0ffabac6e03588d8463fc92a0af06db51f2b6a21 🔍 |
| SHA256 | 7ede32503a91db882ea46fb2e66a568db0d3b74f52ce2824fe59c01f6aa1af91 🔍 |
| SHA3 | badb23b49ded3686e98849899da62c613b3a302a772630be76965fc7c436c87d 🔍 |
| VirtualSize | 0x21f0 |
| VirtualAddress | 0x45b000 |
| SizeOfRawData | 0x2200 |
| PointerToRawData | 0x453200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 2.161 |
| MD5 | edda25907019e5cc74c177f6952e5e4b 🔍 |
|---|---|
| SHA1 | 7a4f78401ecb1ae9f682732465ae6077089ebb13 🔍 |
| SHA256 | 67edb63255622d74f26750550ba3dd665fbccf95fd0ab08e4a26ba7d8ac3a162 🔍 |
| SHA3 | f4a44987a5bb73b0e511a980a6e46723e30252562c97bcd39a080b05991cde7d 🔍 |
| VirtualSize | 0x18 |
| VirtualAddress | 0x45e000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x455400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0.116115 |
| MD5 | 1f354d76203061bfdd5a53dae48d5435 🔍 |
|---|---|
| SHA1 | aa0d33a0c854e073439067876e932688b65cb6a9 🔍 |
| SHA256 | 4c6474903705cb450bb6434c29e8854f17d8324efca1fdb9ee9008599060883a 🔍 |
| SHA3 | 991fbbd46bbd69198269fe6c247d440e0f8a7d38259b7a1e04b74790301d1d2b 🔍 |
| VirtualSize | 0x9 |
| VirtualAddress | 0x45f000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x455600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0.0203931 |
| MD5 | 84c69e75a091280e2bf8e61e01a218b7 🔍 |
|---|---|
| SHA1 | 754d5548ad0d3c9cb31e12598b258d6c98757e6a 🔍 |
| SHA256 | e049e850123f53d83daa5477053b383008755cb2cb396a66a2ad58e724bdf422 🔍 |
| SHA3 | 1c4e8035f883e632f7362abed33ba7f9f41f9add1e142c834716b7378cac6ca1 🔍 |
| VirtualSize | 0x1f4 |
| VirtualAddress | 0x460000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x455800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.1823 |
| MD5 | 6e3b4cbab8ad63ff6b5d290f0200e502 🔍 |
|---|---|
| SHA1 | 6dce8a4a0c6bf39011132a210c3e5d7c26f7969b 🔍 |
| SHA256 | 334f7eb58a52ee75e7b4ecbcb09b1f4d155e85d48d08dd40c61a0f457db1f954 🔍 |
| SHA3 | 0397e9e2737a6f68f39463fddcd526f5c49e9005fae84317f5d8c75c9ac3de43 🔍 |
| VirtualSize | 0x1094 |
| VirtualAddress | 0x461000 |
| SizeOfRawData | 0x1200 |
| PointerToRawData | 0x455a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.31967 |
| d3d12.dll |
D3D12SerializeRootSignature
|
|---|---|
| dxgi.dll |
CreateDXGIFactory1
|
| D3DCOMPILER_47.dll |
D3DCompile
|
| USER32.dll |
CallWindowProcW
ClipCursor CreateWindowExA DefWindowProcA DefWindowProcW DestroyWindow DrawTextA FillRect GetAsyncKeyState GetForegroundWindow GetRawInputData MessageBoxA RegisterClassA SetWindowLongPtrW ShowCursor |
| GDI32.dll |
CreateCompatibleDC
CreateDIBSection CreateFontA DeleteDC DeleteObject GdiFlush GetStockObject SelectObject SetBkColor SetTextColor |
| COMDLG32.dll |
GetOpenFileNameW
|
| amdhip64_7.dll |
__hipPopCallConfiguration
__hipPushCallConfiguration __hipRegisterFatBinary __hipRegisterFunction __hipRegisterVar __hipUnregisterFatBinary hipDestroyExternalMemory hipDeviceSynchronize hipDriverGetVersion hipEventCreate hipEventElapsedTime hipEventRecord hipEventSynchronize hipExternalMemoryGetMappedBuffer hipFree hipGetDeviceCount hipGetDevicePropertiesR0600 hipGetErrorString hipGetLastError hipImportExternalMemory hipLaunchKernel hipMalloc hipMemcpy hipMemcpyAsync hipMemcpyToSymbol hipMemset hipMemsetAsync hipRuntimeGetVersion hipSetDevice |
| bcrypt.dll |
BCryptCloseAlgorithmProvider
BCryptCreateHash BCryptDestroyHash BCryptFinishHash BCryptHashData BCryptOpenAlgorithmProvider |
| KERNEL32.dll |
AcquireSRWLockExclusive
AddVectoredExceptionHandler CloseHandle CompareStringW CreateDirectoryA CreateEventA CreateFileW CreateThread DecodePointer DeleteCriticalSection DisableThreadLibraryCalls EncodePointer EnterCriticalSection EnumSystemLocalesW ExitProcess ExitThread FindClose FindFirstFileExW FindNextFileW FindResourceW FlsAlloc FlsFree FlsGetValue FlsSetValue FlushFileBuffers FlushInstructionCache FreeEnvironmentStringsW FreeLibrary FreeLibraryAndExitThread GetACP GetCPInfo GetCommandLineA GetCommandLineW GetConsoleMode GetConsoleOutputCP GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableA GetExitCodeThread GetFileAttributesW GetFileSizeEx GetFileType GetLastError GetLocaleInfoW GetModuleFileNameA GetModuleFileNameW GetModuleHandleA GetModuleHandleExW GetModuleHandleW GetOEMCP GetPrivateProfileIntA GetPrivateProfileStringA GetProcAddress GetProcessHeap GetStartupInfoW GetStdHandle GetStringTypeW GetSystemDirectoryA GetSystemTimeAsFileTime GetSystemTimePreciseAsFileTime GetTempPathA GetThreadContext GetTickCount64 GetUserDefaultLCID HeapAlloc HeapFree HeapReAlloc HeapSize InitializeCriticalSectionEx InitializeSListHead InterlockedFlushSList IsDebuggerPresent IsProcessorFeaturePresent IsValidCodePage IsValidLocale LCMapStringEx LCMapStringW LeaveCriticalSection LoadLibraryA LoadLibraryExW LoadResource LockResource MultiByteToWideChar QueryPerformanceCounter QueryPerformanceFrequency RaiseException ReadConsoleW ReadFile ReleaseSRWLockExclusive ResumeThread RtlCaptureContext RtlLookupFunctionEntry RtlPcToFileHeader RtlUnwind RtlUnwindEx RtlVirtualUnwind SetEndOfFile SetEnvironmentVariableW SetFilePointerEx SetLastError SetStdHandle SetThreadContext SetUnhandledExceptionFilter SizeofResource Sleep SleepConditionVariableSRW SuspendThread TerminateProcess TryAcquireSRWLockExclusive UnhandledExceptionFilter VirtualAlloc VirtualFree VirtualProtect VirtualQuery WaitForSingleObject WaitForSingleObjectEx WakeAllConditionVariable WideCharToMultiByte WriteConsoleW WriteFile WritePrivateProfileStringA |
| Ordinal | 1 |
|---|---|
| Address | 0x19d0 |
| Ordinal | 2 |
|---|---|
| Address | 0x19e0 |
| Ordinal | 3 |
|---|---|
| Address | 0x19f0 |
| Ordinal | 4 |
|---|---|
| Address | 0x1a00 |
| Ordinal | 5 |
|---|---|
| Address | 0x1a10 |
| Ordinal | 6 |
|---|---|
| Address | 0x1a20 |
| Ordinal | 7 |
|---|---|
| Address | 0x1a30 |
| Ordinal | 8 |
|---|---|
| Address | 0x1a40 |
| Ordinal | 9 |
|---|---|
| Address | 0x1a50 |
| Ordinal | 10 |
|---|---|
| Address | 0x1a60 |
| Ordinal | 11 |
|---|---|
| Address | 0x1a70 |
| Ordinal | 12 |
|---|---|
| Address | 0x1a80 |
| Ordinal | 13 |
|---|---|
| Address | 0x1a90 |
| Ordinal | 14 |
|---|---|
| Address | 0x1aa0 |
| Ordinal | 15 |
|---|---|
| Address | 0x1ab0 |
| Ordinal | 16 |
|---|---|
| Address | 0x1ac0 |
| Ordinal | 17 |
|---|---|
| Address | 0x1ad0 |
| StartAddressOfRawData | 0x18045f000 |
|---|---|
| EndAddressOfRawData | 0x18045f008 |
| AddressOfIndex | 0x180075748 |
| AddressOfCallbacks | 0x1800698d8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x180073380 |
No comments yet.