| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jun-10 07:56:57 |
| Detected languages |
English - United States
Hebrew - Israel |
| CompanyName | NirSoft |
| FileDescription | WifiInfoView |
| FileVersion | 3.00 |
| InternalName | WifiInfoView |
| LegalCopyright | Copyright © 2012 - 2026 Nir Sofer |
| OriginalFilename | WifiInfoView.exe |
| ProductName | WifiInfoView |
| ProductVersion | 3.00 |
| Suspicious | The PE is packed with UPX |
Unusual section name found: UPX0
Section UPX0 is both writable and executable. Unusual section name found: UPX1 Section UPX1 is both writable and executable. |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Info | The PE's resources present abnormal characteristics. |
Resource 1 is possibly compressed or encrypted.
Resource 2 is possibly compressed or encrypted. Resource 110 is possibly compressed or encrypted. Resource 133 is possibly compressed or encrypted. Resource 134 is possibly compressed or encrypted. Resource 102 is possibly compressed or encrypted. Resource 104 is possibly compressed or encrypted. Resource 105 is possibly compressed or encrypted. Resource 107 is possibly compressed or encrypted. Resource 112 is possibly compressed or encrypted. Resource 115 is possibly compressed or encrypted. Resource 121 is possibly compressed or encrypted. Resource 1096 is possibly compressed or encrypted. Resource 1 is possibly compressed or encrypted. Resource 2 is possibly compressed or encrypted. Resource 32 is possibly compressed or encrypted. Resource 64 is possibly compressed or encrypted. Resource 65 is possibly compressed or encrypted. Resource 313 is possibly compressed or encrypted. Resource 314 is possibly compressed or encrypted. Resource 315 is possibly compressed or encrypted. Resource 316 is possibly compressed or encrypted. Resource 317 is possibly compressed or encrypted. Resource 318 is possibly compressed or encrypted. Resource 319 is possibly compressed or encrypted. Resource 320 is possibly compressed or encrypted. Resource 321 is possibly compressed or encrypted. Resource 322 is possibly compressed or encrypted. Resource 323 is possibly compressed or encrypted. Resource 324 is possibly compressed or encrypted. Resource 325 is possibly compressed or encrypted. |
| Malicious | VirusTotal score: 4/70 (Scanned on 2026-06-11 13:01:12) |
APEX:
Malicious
DeepInstinct: MALICIOUS MaxSecure: Trojan.Malware.300983.susgen Microsoft: Trojan:Win32/Wacatac.B!ml |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 3 |
| TimeDateStamp | 2026-Jun-10 07:56:57 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 8.0 |
| SizeOfCode | 0x63000 |
| SizeOfInitializedData | 0x5000 |
| SizeOfUninitializedData | 0x108000 |
| AddressOfEntryPoint | 0x000000000016A7C0 (Section: UPX1) |
| BaseOfCode | 0x109000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x171000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
RegCloseKey
|
|---|---|
| COMCTL32.dll |
#17
|
| comdlg32.dll |
FindTextW
|
| GDI32.dll |
PatBlt
|
| KERNEL32.DLL |
LoadLibraryA
ExitProcess GetProcAddress VirtualProtect |
| msvcrt.dll |
exit
|
| ole32.dll |
CoCreateInstance
|
| SHELL32.dll |
ShellExecuteW
|
| USER32.dll |
GetDC
|
| VERSION.dll |
VerQueryValueW
|
| Ѩ 涰 တ Ѩ 淄 တ Ѩ 淘 |