| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2025-Dec-21 15:09:59 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\mquem\Desktop\dovyl menu\examples\example_win32_directx11\Release\example_win32_directx11.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 6/66 (Scanned on 2026-07-24 04:29:26) |
APEX:
Malicious
CrowdStrike: win/malicious_confidence_60% (W) Elastic: malicious (moderate confidence) McAfeeD: ti!2C9D63BD1A3C Symantec: ML.Attribute.HighConfidence TrendMicro-HouseCall: Trojan.Win64.Gen.TL0101FI26YE |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2025-Dec-21 15:09:59 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x6a800 |
| SizeOfInitializedData | 0x21a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000006AD00 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x91000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| D3DCOMPILER_47.dll |
D3DCompile
|
| KERNEL32.dll |
GetLocaleInfoA
LoadLibraryA QueryPerformanceFrequency GetProcAddress VerSetConditionMask FreeLibrary QueryPerformanceCounter Sleep GetModuleHandleW MultiByteToWideChar GlobalUnlock SetUnhandledExceptionFilter UnhandledExceptionFilter IsDebuggerPresent RtlVirtualUnwind GetSystemTimeAsFileTime InitializeSListHead RtlLookupFunctionEntry RtlCaptureContext SleepConditionVariableSRW GetModuleHandleA WideCharToMultiByte GlobalLock GlobalFree IsProcessorFeaturePresent GlobalAlloc AcquireSRWLockExclusive GetCurrentProcessId ReleaseSRWLockExclusive WakeAllConditionVariable GetCurrentThreadId |
| USER32.dll |
TranslateMessage
PeekMessageW DispatchMessageW ShowWindow RegisterClassExW UnregisterClassW CreateWindowExW DestroyWindow MonitorFromPoint DefWindowProcW ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout UpdateWindow GetDC GetForegroundWindow LoadCursorW SetCapture SetCursor GetClientRect SetProcessDPIAware IsWindowUnicode ReleaseCapture SetCursorPos GetKeyState GetMessageExtraInfo ReleaseDC GetCursorPos OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData PostQuitMessage |
| GDI32.dll |
GetDeviceCaps
|
| SHELL32.dll |
ShellExecuteW
|
| IMM32.dll |
ImmSetCompositionWindow
ImmReleaseContext ImmGetContext ImmSetCandidateWindow |
| MSVCP140.dll |
?_Xlength_error@std@@YAXPEBD@Z
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
_CxxThrowException
memmove __current_exception_context __current_exception __std_exception_copy __std_exception_destroy strchr strstr __std_terminate memchr memcmp memcpy memset __C_specific_handler |
| api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vsprintf
fwrite __stdio_common_vfprintf fseek fclose fflush __acrt_iob_func ftell __stdio_common_vsscanf __p__commode _set_fmode _wfopen __stdio_common_vsprintf_s fread |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-string-l1-1-0.dll |
strncpy
strncmp strcmp |
| api-ms-win-crt-heap-l1-1-0.dll |
free
malloc _callnewh _set_new_mode |
| api-ms-win-crt-runtime-l1-1-0.dll |
_initterm
_initterm_e exit _exit __p___argc __p___argv _c_exit _register_thread_local_exe_atexit_callback _set_app_type _seh_filter_exe _configure_narrow_argv _invoke_watson _cexit _crt_atexit _initialize_narrow_environment _get_initial_narrow_environment _register_onexit_function _initialize_onexit_table _wassert terminate |
| api-ms-win-crt-convert-l1-1-0.dll |
atof
|
| api-ms-win-crt-math-l1-1-0.dll |
sinf
sqrtf powf acosf cosf fmodf atan2f ceilf __setusermatherr |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-21 15:09:59 |
| Version | 0.0 |
| SizeofData | 127 |
| AddressOfRawData | 0x7f96c |
| PointerToRawData | 0x7e56c |
| Referenced File | C:\Users\mquem\Desktop\dovyl menu\examples\example_win32_directx11\Release\example_win32_directx11.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-21 15:09:59 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x7f9ec |
| PointerToRawData | 0x7e5ec |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-21 15:09:59 |
| Version | 0.0 |
| SizeofData | 892 |
| AddressOfRawData | 0x7fa00 |
| PointerToRawData | 0x7e600 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-21 15:09:59 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x14007fda0 |
|---|---|
| EndAddressOfRawData | 0x14007fda8 |
| AddressOfIndex | 0x140089318 |
| AddressOfCallbacks | 0x14006c590 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140089040 |
| XOR Key | 0xd27a87a2 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 16 |
| Imports (35207) | 6 |
| ASM objects (35207) | 3 |
| C objects (35207) | 9 |
| C++ objects (35207) | 28 |
| Imports (33145) | 17 |
| Total imports | 159 |
| C++ objects (LTCG) (35222) | 8 |
| Resource objects (35222) | 1 |
| Linker (35222) | 1 |
No comments yet.