2c9d63bd1a3c30934890028d68204cf1e55ed9aa77e27ec9b4ac16996d666a8d

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2025-Dec-21 15:09:59
Detected languages English - United States
Debug artifacts C:\Users\mquem\Desktop\dovyl menu\examples\example_win32_directx11\Release\example_win32_directx11.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Interesting strings found in the binary: Contains domain names:
  • github.com
  • https://github.com
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Possibly launches other programs:
  • ShellExecuteW
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 6/66 (Scanned on 2026-07-24 04:29:26) APEX: Malicious
CrowdStrike: win/malicious_confidence_60% (W)
Elastic: malicious (moderate confidence)
McAfeeD: ti!2C9D63BD1A3C
Symantec: ML.Attribute.HighConfidence
TrendMicro-HouseCall: Trojan.Win64.Gen.TL0101FI26YE

Hashes

MD5 92302e950cd628a30266afc3c9ce33ae
SHA1 007086625970e0be57e41f6551e94c72e94a8464
SHA256 2c9d63bd1a3c30934890028d68204cf1e55ed9aa77e27ec9b4ac16996d666a8d
SHA3 b695454ecf983660eec9cba5b3ec72e5b6d9aa0b9b9fb63e4dbce0d20aaa2981
SSDeep 12288:CwTlu+xApO+Qe4g+mfr2BWQ9l0iHnrEoFV:Cwhu+WpOXeyma0iHnr
Imports Hash 30caa1a0756102b52075a45a8d4b0214

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2025-Dec-21 15:09:59
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x6a800
SizeOfInitializedData 0x21a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000006AD00 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x91000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 84cab62d47ff9054f4c5c601a71d4657
SHA1 325dd8b5fc73b02579892dbebfb69ff248d09aeb
SHA256 42e41f7329715579a5584cc680462012c2095608806a0a5ad17ba85a6ff9779e
SHA3 e4a63a3afe4551154add0e331d1ab41040b9e61d46b17faebdd68ebb69ebf2f6
VirtualSize 0x6a6df
VirtualAddress 0x1000
SizeOfRawData 0x6a800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.51823

.rdata

MD5 f5bb4d523a13583f832431acccd24143
SHA1 4d03a6e74643dae6aec226c94f0b74be3efe6ec3
SHA256 5a9ed829456800f18e031a2aba7f628a39960ea3e60fcfdbb39335c052a4f6c5
SHA3 554ee54b251c0beff3be4fed4415c49ea5c5114625c7ee3fdbfbeb8302f7f8ab
VirtualSize 0x1c194
VirtualAddress 0x6c000
SizeOfRawData 0x1c200
PointerToRawData 0x6ac00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.25433

.data

MD5 0ff43d7223bf586879a7e8cff5327f7c
SHA1 ca79ba8e35bda4b4232b3da64b93517da4608512
SHA256 08b805419c19ac4a7787e58a00b42d28d020d3fa6ac17c6a224d781c63c3ae2b
SHA3 230cd41d83e15c3f3b0259dce10fc75df6e87e6d01d9d0e0872d5fc3a22d09ba
VirtualSize 0x498
VirtualAddress 0x89000
SizeOfRawData 0x400
PointerToRawData 0x86e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.41291

.pdata

MD5 84a62249e41f7062c0cd9fc64b690199
SHA1 6b825d0eb2478e58915e1989759d073945db3abe
SHA256 0ecb17fd5d8cdecd0a97f4af676969b7407dbe32cf031e53fe488c0404426e0d
SHA3 499a0a4f040a089d06b695eb568897e77dfa20702baecf0ce7bdfbeed3d1106e
VirtualSize 0x4a1c
VirtualAddress 0x8a000
SizeOfRawData 0x4c00
PointerToRawData 0x87200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.77035

.rsrc

MD5 770dc0cfd5c43c4c579d5319651b6651
SHA1 2ecb03e67427a7f6e90b9843b64860693f5d7e5b
SHA256 192f759e575c9dbaa1fd770e514f87add6ab066e1c59be1008bf98cb244fe896
SHA3 261d614a5950c88ecf77f2317f42f018d0c7ce9313775ac8c192dc3450cca76f
VirtualSize 0x1e0
VirtualAddress 0x8f000
SizeOfRawData 0x200
PointerToRawData 0x8be00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.71768

.reloc

MD5 72a05e8b3863905e7d7eac78b4b7f49c
SHA1 5574ea5051928c4754b79f359406416ef874f70e
SHA256 918920826408d02ff8584347b5f28b8984bbf61c54cc7407208b65c3ff74b123
SHA3 3ea057cfafe753eb29b00dc8297ba557921cfef00abe7295f9cc2fe7f254ce0f
VirtualSize 0x260
VirtualAddress 0x90000
SizeOfRawData 0x400
PointerToRawData 0x8c000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 3.84592

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
D3DCOMPILER_47.dll D3DCompile
KERNEL32.dll GetLocaleInfoA
LoadLibraryA
QueryPerformanceFrequency
GetProcAddress
VerSetConditionMask
FreeLibrary
QueryPerformanceCounter
Sleep
GetModuleHandleW
MultiByteToWideChar
GlobalUnlock
SetUnhandledExceptionFilter
UnhandledExceptionFilter
IsDebuggerPresent
RtlVirtualUnwind
GetSystemTimeAsFileTime
InitializeSListHead
RtlLookupFunctionEntry
RtlCaptureContext
SleepConditionVariableSRW
GetModuleHandleA
WideCharToMultiByte
GlobalLock
GlobalFree
IsProcessorFeaturePresent
GlobalAlloc
AcquireSRWLockExclusive
GetCurrentProcessId
ReleaseSRWLockExclusive
WakeAllConditionVariable
GetCurrentThreadId
USER32.dll TranslateMessage
PeekMessageW
DispatchMessageW
ShowWindow
RegisterClassExW
UnregisterClassW
CreateWindowExW
DestroyWindow
MonitorFromPoint
DefWindowProcW
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
UpdateWindow
GetDC
GetForegroundWindow
LoadCursorW
SetCapture
SetCursor
GetClientRect
SetProcessDPIAware
IsWindowUnicode
ReleaseCapture
SetCursorPos
GetKeyState
GetMessageExtraInfo
ReleaseDC
GetCursorPos
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
PostQuitMessage
GDI32.dll GetDeviceCaps
SHELL32.dll ShellExecuteW
IMM32.dll ImmSetCompositionWindow
ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow
MSVCP140.dll ?_Xlength_error@std@@YAXPEBD@Z
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll _CxxThrowException
memmove
__current_exception_context
__current_exception
__std_exception_copy
__std_exception_destroy
strchr
strstr
__std_terminate
memchr
memcmp
memcpy
memset
__C_specific_handler
api-ms-win-crt-stdio-l1-1-0.dll __stdio_common_vsprintf
fwrite
__stdio_common_vfprintf
fseek
fclose
fflush
__acrt_iob_func
ftell
__stdio_common_vsscanf
__p__commode
_set_fmode
_wfopen
__stdio_common_vsprintf_s
fread
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-string-l1-1-0.dll strncpy
strncmp
strcmp
api-ms-win-crt-heap-l1-1-0.dll free
malloc
_callnewh
_set_new_mode
api-ms-win-crt-runtime-l1-1-0.dll _initterm
_initterm_e
exit
_exit
__p___argc
__p___argv
_c_exit
_register_thread_local_exe_atexit_callback
_set_app_type
_seh_filter_exe
_configure_narrow_argv
_invoke_watson
_cexit
_crt_atexit
_initialize_narrow_environment
_get_initial_narrow_environment
_register_onexit_function
_initialize_onexit_table
_wassert
terminate
api-ms-win-crt-convert-l1-1-0.dll atof
api-ms-win-crt-math-l1-1-0.dll sinf
sqrtf
powf
acosf
cosf
fmodf
atan2f
ceilf
__setusermatherr
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Dec-21 15:09:59
Version 0.0
SizeofData 127
AddressOfRawData 0x7f96c
PointerToRawData 0x7e56c
Referenced File C:\Users\mquem\Desktop\dovyl menu\examples\example_win32_directx11\Release\example_win32_directx11.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Dec-21 15:09:59
Version 0.0
SizeofData 20
AddressOfRawData 0x7f9ec
PointerToRawData 0x7e5ec

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Dec-21 15:09:59
Version 0.0
SizeofData 892
AddressOfRawData 0x7fa00
PointerToRawData 0x7e600

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2025-Dec-21 15:09:59
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x14007fda0
EndAddressOfRawData 0x14007fda8
AddressOfIndex 0x140089318
AddressOfCallbacks 0x14006c590
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140089040

RICH Header

XOR Key 0xd27a87a2
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 16
Imports (35207) 6
ASM objects (35207) 3
C objects (35207) 9
C++ objects (35207) 28
Imports (33145) 17
Total imports 159
C++ objects (LTCG) (35222) 8
Resource objects (35222) 1
Linker (35222) 1

Errors

Leave a comment

No comments yet.