| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Mar-29 14:57:38 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\skeet\source\repos\skeetware\x64\Release\skeetware.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 29/71 (Scanned on 2026-05-01 14:26:18) |
ALYac:
Trojan.GenericKD.79935057
APEX: Malicious Antiy-AVL: Trojan/Win32.Agent Arcabit: Trojan.Generic.D4C3B651 BitDefender: Trojan.GenericKD.79935057 Bkav: W64.AIDetectMalware CTX: exe.trojan.wacatac CrowdStrike: win/malicious_confidence_70% (W) DeepInstinct: MALICIOUS ESET-NOD32: Win64/GameHack_AGen.BFQ potentially unsafe application Elastic: malicious (high confidence) Emsisoft: Trojan.GenericKD.79935057 (B) Fortinet: W32/PossibleThreat GData: Trojan.GenericKD.79935057 Google: Detected Ikarus: Trojan.Win64.Krypt Lionic: Trojan.Win32.Generic.4!c MaxSecure: Trojan.Malware.646166707.susgen McAfeeD: ti!39DC8D98A21A MicroWorld-eScan: Trojan.GenericKD.79935057 Microsoft: Trojan:Win32/Wacatac.B!ml Paloalto: generic.ml Symantec: ML.Attribute.HighConfidence TrellixENS: Artemis!BF47A6D947A2 TrendMicro-HouseCall: Trojan.Win64.Gen.TL0101DG26ZR VIPRE: Trojan.GenericKD.79935057 Varist: W64/ABTrojan.CLSB-4762 Webroot: Win.Hacktool.Gen alibabacloud: Trojan:Win/Wacatac.C9nj |
| MD5 | bf47a6d947a28ce3a6e1f3b67b182296 🔍 |
|---|---|
| SHA1 | 188ba19fe7846826aa439565b4574b3a74d20031 🔍 |
| SHA256 | 39dc8d98a21a1364458f84ae72bef47116f1e0445db1125e2763aee9109c2978 🔍 |
| SHA3 | 88f8131859859592f2c563b4caf41a380b631377c4ac2c309cf8c8f976a20d22 🔍 |
| SSDeep | 24576:mVcqfqHeqNP9ynsvvNyu+lTAV+snqHnlg+awqwUwExIPfA8OLhJ9yp/xCcTOuIr:ecqffHn4+qVt8h/qNwffAj3g/bTqSk6 🔍 |
| Imports Hash | e1c9fa402dfb21c9c2955f602b7d1835 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Mar-29 14:57:38 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x5ce00 |
| SizeOfInitializedData | 0x17f000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000005CE50 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1e0000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 3a1845683a593a1f96c24e5d657cbd58 🔍 |
|---|---|
| SHA1 | 4f2779a36ce7e93c4a04231452678d1c29d6e762 🔍 |
| SHA256 | 6fecc12ca129971046c1fc4d412426aa7b5d37dc341a83548ffdda945ecc21c6 🔍 |
| SHA3 | 9a90545d7da62bd85bb42b2f08ef74362d3a975be33d58ff6ab97558e757ea1a 🔍 |
| VirtualSize | 0x5ccd5 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x5ce00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.4965 |
| MD5 | 84906f2f19c8c2673745884399bd9f8c 🔍 |
|---|---|
| SHA1 | e10ad899033f6e81c24c1c041e64b2c5056ccb9e 🔍 |
| SHA256 | 72d7fdc342e708e69abc45be805754e18ddcec29700ec0125c97cdd86feb2c0a 🔍 |
| SHA3 | ac5bab71dd62d30afe023812aad2d755b89c4763e7cff92e187fc149901d080c 🔍 |
| VirtualSize | 0xf2e0 |
| VirtualAddress | 0x5e000 |
| SizeOfRawData | 0xf400 |
| PointerToRawData | 0x5d200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.1309 |
| MD5 | 37f51103a0d6c2139bc0e44c1fd44e8c 🔍 |
|---|---|
| SHA1 | 78ebbb44018189f2280a02da5277bbf7f3872a68 🔍 |
| SHA256 | e31dee97b63559c3af543e78e38b77707c255323b97cd89d92e3218606a460fa 🔍 |
| SHA3 | 8ffa82146c3023b82aa7a656dcb9387e1e351192ad46ec507e8991b1b1fe9b9a 🔍 |
| VirtualSize | 0x16b998 |
| VirtualAddress | 0x6e000 |
| SizeOfRawData | 0x165400 |
| PointerToRawData | 0x6c600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 6.76545 |
| MD5 | 8390d7c9879f79b10233c330e2fd1684 🔍 |
|---|---|
| SHA1 | 00400bcc9c55ffce6b23fc41e5561afc45c15fcc 🔍 |
| SHA256 | a80d1e1eb0c2094a8e02fb785fa37ccaa64736b8f3283eb9b4775ac7ae723b32 🔍 |
| SHA3 | 077b3bba21424fa002fa142907ef6cb873e8c3494687badea914c4e4fa273255 🔍 |
| VirtualSize | 0x3b88 |
| VirtualAddress | 0x1da000 |
| SizeOfRawData | 0x3c00 |
| PointerToRawData | 0x1d1a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.79998 |
| MD5 | dca12a632b1b4790453146cf7d02ce61 🔍 |
|---|---|
| SHA1 | 8dd5c062d221a42dee26e1ead45c825562a48913 🔍 |
| SHA256 | 48039499c9a31ed83ccf8166e4067d3867783da3ae913936d19b7830a682670d 🔍 |
| SHA3 | 2d1dd31c006dec220e9577679b236c206b9f9f1d314a2fc656abf4974520df96 🔍 |
| VirtualSize | 0x1e0 |
| VirtualAddress | 0x1de000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x1d5600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.71768 |
| MD5 | 56fdff75cbfb4e56989ce2a13f636b63 🔍 |
|---|---|
| SHA1 | 815d10b1144a0b5cdb98dca0738da057df0d4721 🔍 |
| SHA256 | 3d88685aafa1c30ad34ba7533697822f5aaed9c7f69b89a0a72a269be1856eb3 🔍 |
| SHA3 | f594bade45c61ad66298b30573a0eba3c7c3da9aa984a5c9c861235bbd06b9c0 🔍 |
| VirtualSize | 0x248 |
| VirtualAddress | 0x1df000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x1d5800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 3.69488 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| KERNEL32.dll |
QueryPerformanceFrequency
GetProcAddress FreeLibrary QueryPerformanceCounter GetModuleHandleW MultiByteToWideChar GetCurrentThreadId GetCurrentProcessId SetUnhandledExceptionFilter SleepConditionVariableSRW WakeAllConditionVariable AcquireSRWLockExclusive GetLocaleInfoA LoadLibraryA ReleaseSRWLockExclusive GetSystemTimeAsFileTime InitializeSListHead |
| USER32.dll |
LoadCursorA
GetMessageExtraInfo GetKeyState UpdateWindow PostQuitMessage TranslateMessage ClientToScreen DispatchMessageW ShowWindow RegisterClassExW UnregisterClassW DestroyWindow DefWindowProcW ScreenToClient TrackMouseEvent GetKeyboardLayout GetForegroundWindow SetCapture SetCursor GetCursorPos GetClientRect IsWindowUnicode ReleaseCapture CreateWindowExW GetCapture SetCursorPos PeekMessageW |
| D3DCOMPILER_43.dll |
D3DCompile
|
| MSVCP140.dll |
?_Xlength_error@std@@YAXPEBD@Z
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__std_exception_destroy
__std_exception_copy __current_exception __current_exception_context strchr memset __std_terminate _CxxThrowException __C_specific_handler strstr memchr memcmp memcpy memmove |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vsprintf
__stdio_common_vsscanf _set_fmode __p__commode |
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
_set_new_mode free _callnewh |
| api-ms-win-crt-convert-l1-1-0.dll |
atof
|
| api-ms-win-crt-string-l1-1-0.dll |
strncmp
strncpy strcmp strlen strcpy_s |
| api-ms-win-crt-runtime-l1-1-0.dll |
_register_thread_local_exe_atexit_callback
__p___argv __p___argc terminate _configure_narrow_argv _exit exit _initialize_narrow_environment _initialize_onexit_table _c_exit _initterm_e _initterm _get_initial_narrow_environment _set_app_type _seh_filter_exe _cexit _crt_atexit _register_onexit_function |
| api-ms-win-crt-math-l1-1-0.dll |
sqrtf
fmodf cosf log logf ceilf sinf atan2f __setusermatherr powf acosf pow |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-29 14:57:38 |
| Version | 0.0 |
| SizeofData | 88 |
| AddressOfRawData | 0x65a8c |
| PointerToRawData | 0x64c8c |
| Referenced File | C:\Users\skeet\source\repos\skeetware\x64\Release\skeetware.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-29 14:57:38 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x65ae4 |
| PointerToRawData | 0x64ce4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-29 14:57:38 |
| Version | 0.0 |
| SizeofData | 892 |
| AddressOfRawData | 0x65af8 |
| PointerToRawData | 0x64cf8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-29 14:57:38 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x140065e98 |
|---|---|
| EndAddressOfRawData | 0x140065ea0 |
| AddressOfIndex | 0x1401d3298 |
| AddressOfCallbacks | 0x14005e458 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14006e040 |
| XOR Key | 0x3f316b34 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 16 |
| Imports (35403) | 6 |
| ASM objects (35403) | 4 |
| C objects (35403) | 10 |
| C++ objects (35403) | 29 |
| Imports (33145) | 8 |
| Imports (21202) | 5 |
| Total imports | 125 |
| C++ objects (LTCG) (35728) | 14 |
| Resource objects (35728) | 1 |
| Linker (35728) | 1 |
No comments yet.