306765c2d228be7be6b1b473eeee50d4e07f13549447cf37bba50d2278f695a8

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-21 18:24:08
Detected languages English - United States
Debug artifacts C:\Users\yggyu\Desktop\FairGame Permanent Spoofer\x64\Release\Pikao_custom_work.pdb

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
  • virus
Contains domain names:
  • github.com
  • http://www.zkysky.com.ar
  • http://www.zkysky.com.ar/Julieta
  • https://github.com
  • https://openfontlicense.orgThis
  • https://openfontlicense.orghttp
  • www.zkysky.com
  • zkysky.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Possibly launches other programs:
  • CreateProcessA
Uses Microsoft's cryptographic API:
  • CryptHashData
  • CryptReleaseContext
  • CryptDestroyHash
  • CryptCreateHash
  • CryptAcquireContextA
  • CryptGetHashParam
Has Internet access capabilities:
  • URLDownloadToFileA
  • WinHttpQueryDataAvailable
  • WinHttpReceiveResponse
  • WinHttpOpen
  • WinHttpReadData
  • WinHttpOpenRequest
  • WinHttpSetOption
  • WinHttpCloseHandle
  • WinHttpSendRequest
  • WinHttpConnect
Functions related to the privilege level:
  • OpenProcessToken
Manipulates other processes:
  • Process32NextW
  • Process32FirstW
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 16/68 (Scanned on 2026-07-26 05:10:36) APEX: Malicious
Antiy-AVL: Trojan/Win32.Sabsik
BitDefender: Gen:Variant.Yogi.36134
Bkav: W32.Malware.CE76C174
CTX: exe.unknown.yogi
CrowdStrike: win/malicious_confidence_90% (W)
Cylance: Unsafe
Cynet: Malicious (score: 100)
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Yogi.36134 (B)
GData: Gen:Variant.Yogi.36134
Google: Detected
McAfeeD: ti!306765C2D228
MicroWorld-eScan: Gen:Variant.Yogi.36134
SentinelOne: Static AI - Malicious PE
Symantec: ML.Attribute.HighConfidence

Hashes

MD5 264224f12d1715ca4b1dba404f12c9a3
SHA1 f000905953c10a603334160b2d471e080f5ad660
SHA256 306765c2d228be7be6b1b473eeee50d4e07f13549447cf37bba50d2278f695a8
SHA3 5f74dd86a5407f6f857ef5595f3d04627abf366862bb6469bca72d8495bbfe7f
SSDeep 49152:LQxZIJ2T/0Ervgn1MXXGfJoLuGNw/+HLXB/Pj:kuJ2TRkhoLaGr5b
Imports Hash 2ec9da10056ffa2ee2b0b924100b9f37

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jul-21 18:24:08
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xb8800
SizeOfInitializedData 0x19aa00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000054868 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x257000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 48f1521e9f94299d2a9479a85d76df16
SHA1 12c62c8805ea8343b29875a6c19d420bda7d30eb
SHA256 65c6e12748e500119140d14c99822788579b3d059244876f66d6110c70911913
SHA3 ac531265a60989d866cb4b4796bec2908ec9ff4e4aa2fc0086e077fa19de74fa
VirtualSize 0xb873f
VirtualAddress 0x1000
SizeOfRawData 0xb8800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.52627

.rdata

MD5 10e2e12191e4986a9717ebc0a2c76c48
SHA1 bb33de82c572a7c0f3b5a0623bae0d3d19edd9ea
SHA256 bea63a444b56721cf346064d26e1ccdbba4ab5389cb3e45d1181907dc60f175a
SHA3 fe744f5da597b536b341d1d370c69e1b5c8e4fcc4214641db99011e31100c9a1
VirtualSize 0x706c0
VirtualAddress 0xba000
SizeOfRawData 0x70800
PointerToRawData 0xb8c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.82465

.data

MD5 90eeebc2f05bee54f7a40758caced708
SHA1 380f46a30a7ca4a882c160178eb0a978afb0cbef
SHA256 c0e4c4a7fc07a5e1cc876755cc36f4324eb2e802a32033a22e97aefa1d4b5fe8
SHA3 9e70700c423d6a94b59d0b79d3de71065de754b3c47dab8cb97f2d19c8649166
VirtualSize 0x1208c8
VirtualAddress 0x12b000
SizeOfRawData 0x11f400
PointerToRawData 0x129400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.62926

.pdata

MD5 19b3af1f3d9743fe634f100eaaa3bbc5
SHA1 feb05eb71f1425d21bb5916f2a8357d8ca442aaf
SHA256 bf3f33f25e90b89abee985e3116a0ab92758fddbfb70de34255939a7b2058296
SHA3 91901adb84df47175d80027456f323fbfb716d86b76ffaca7f29952758fb1350
VirtualSize 0x864c
VirtualAddress 0x24c000
SizeOfRawData 0x8800
PointerToRawData 0x248800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.05638

.rsrc

MD5 2415fa659c2ed8448c1cb2e5bd9b35bb
SHA1 dddf35317297508a1b58cdf047fed20dbb23d431
SHA256 ae9c042b8bbffd674d4bd64ae5f0f8a7d977571f2388ea917e557d867964438d
SHA3 db7f7e9c1cb02010d5a49253183ccb7376b49bb44d351e609261f39c0b8236bf
VirtualSize 0x1e0
VirtualAddress 0x255000
SizeOfRawData 0x200
PointerToRawData 0x251000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.7123

.reloc

MD5 abff998fc3dbda47fa55f1cc48f7f9f3
SHA1 f53d98cd606843872e5c1a26017f6d5fa20e53b0
SHA256 2f2f6293856c2d3890c9766fd89c949ea370fd6b8e870a7683ebb01b8221e3d8
SHA3 2da4b4411d8c69ae74c1182a948d9447b179824ef9fbc1d3a7860972fb8a1ccf
VirtualSize 0xd0c
VirtualAddress 0x256000
SizeOfRawData 0xe00
PointerToRawData 0x251200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.2939

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
D3DCOMPILER_43.dll D3DCompile
ADVAPI32.dll CryptHashData
CryptReleaseContext
CryptDestroyHash
CryptCreateHash
GetTokenInformation
OpenProcessToken
GetUserNameA
CryptAcquireContextA
CryptGetHashParam
KERNEL32.dll GetCurrentProcess
GetEnvironmentVariableA
WaitForSingleObject
CreateToolhelp32Snapshot
Sleep
GetTempPathA
GetLastError
GetFileAttributesA
Process32NextW
DeleteFileA
Process32FirstW
CloseHandle
ExitProcess
CreateProcessA
CreateDirectoryA
GetExitCodeProcess
GetModuleFileNameW
LoadLibraryW
GetModuleHandleW
MultiByteToWideChar
LoadLibraryA
FreeLibrary
WideCharToMultiByte
GlobalLock
SetThreadPriority
CreateThread
GetTickCount
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
QueryPerformanceCounter
GetProcAddress
GlobalUnlock
QueryPerformanceFrequency
GlobalAlloc
GlobalFree
USER32.dll GetWindowLongW
DefWindowProcW
DestroyWindow
CreateWindowExW
GetSystemMetrics
UnregisterClassW
RegisterClassExW
ShowWindow
SetClipboardData
DispatchMessageW
SetWindowLongA
GetClientRect
PeekMessageW
SetLayeredWindowAttributes
TranslateMessage
PostQuitMessage
UpdateWindow
GetClipboardData
EmptyClipboard
CloseClipboard
OpenClipboard
GetCursorPos
SetCursorPos
ReleaseCapture
IsWindowUnicode
GetWindowRect
MoveWindow
SetCursor
SetCapture
LoadCursorW
GetForegroundWindow
TrackMouseEvent
ClientToScreen
GetCapture
ScreenToClient
GetKeyState
MSVCP140.dll ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
??Bios_base@std@@QEBA_NXZ
?_Xlength_error@std@@YAXPEBD@Z
?_Xbad_alloc@std@@YAXXZ
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?uncaught_exceptions@std@@YAHXZ
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Id_cnt@id@locale@std@@0HA
?_Xout_of_range@std@@YAXPEBD@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?good@ios_base@std@@QEBA_NXZ
?always_noconv@codecvt_base@std@@QEBA_NXZ
?_Xinvalid_argument@std@@YAXPEBD@Z
?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
IMM32.dll ImmSetCandidateWindow
ImmReleaseContext
ImmGetContext
ImmSetCompositionWindow
dwmapi.dll DwmSetWindowAttribute
DwmExtendFrameIntoClientArea
d3dx11_43.dll D3DX11CreateShaderResourceViewFromMemory
urlmon.dll URLDownloadToFileA
WINHTTP.dll WinHttpQueryDataAvailable
WinHttpReceiveResponse
WinHttpOpen
WinHttpReadData
WinHttpOpenRequest
WinHttpSetOption
WinHttpCloseHandle
WinHttpSendRequest
WinHttpConnect
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll strstr
memchr
memcmp
memcpy
memset
__current_exception
__current_exception_context
__C_specific_handler
_CxxThrowException
strrchr
longjmp
memmove
__intrinsic_setjmp
__std_exception_copy
__std_exception_destroy
__std_terminate
api-ms-win-crt-stdio-l1-1-0.dll fflush
fopen
_popen
fclose
__p__commode
ftell
fseek
fgets
__stdio_common_vfprintf
_set_fmode
_pclose
fwrite
_wfopen
__stdio_common_vsprintf
_get_stream_buffer_pointers
_fseeki64
fsetpos
ungetc
setvbuf
fgetpos
fgetc
fread
__stdio_common_vsscanf
fputc
__acrt_iob_func
api-ms-win-crt-runtime-l1-1-0.dll _configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_cexit
_seh_filter_exe
_set_app_type
terminate
_get_narrow_winmain_command_line
_initterm
_initterm_e
exit
_exit
_c_exit
_register_thread_local_exe_atexit_callback
_errno
_invoke_watson
api-ms-win-crt-utility-l1-1-0.dll srand
qsort
rand
api-ms-win-crt-string-l1-1-0.dll strcmp
_wcsicmp
isalnum
strncpy
strncmp
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
_callnewh
free
malloc
api-ms-win-crt-convert-l1-1-0.dll strtol
strtoll
api-ms-win-crt-math-l1-1-0.dll sqrtf
fmodf
sinf
roundf
ceilf
acosf
powf
cosf
__setusermatherr
api-ms-win-crt-filesystem-l1-1-0.dll _lock_file
_unlock_file
api-ms-win-crt-time-l1-1-0.dll _time64
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jul-21 18:24:08
Version 0.0
SizeofData 108
AddressOfRawData 0x11b1e8
PointerToRawData 0x119de8
Referenced File C:\Users\yggyu\Desktop\FairGame Permanent Spoofer\x64\Release\Pikao_custom_work.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jul-21 18:24:08
Version 0.0
SizeofData 20
AddressOfRawData 0x11b254
PointerToRawData 0x119e54

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-21 18:24:08
Version 0.0
SizeofData 912
AddressOfRawData 0x11b268
PointerToRawData 0x119e68

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jul-21 18:24:08
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x14011b618
EndAddressOfRawData 0x14011b620
AddressOfIndex 0x14024a850
AddressOfCallbacks 0x1400baad8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14012b040

RICH Header

XOR Key 0x294581c0
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 22
253 (35207) 1
C objects (VS2022 Update 6 (17.6.4) compiler 32537) 24
ASM objects (35207) 4
C objects (35207) 10
C++ objects (35207) 32
Imports (35207) 6
Imports (33145) 16
Imports (21202) 7
Total imports 312
C++ objects (LTCG) (35228) 11
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.