| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Apr-07 15:22:04 |
| TLS Callbacks | 3 callback(s) detected. |
| Debug artifacts |
Embedded COFF debugging symbols
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to RC5 or RC6 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .xdata |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. | 416536 bytes of data starting at offset 0x42d600. |
| Malicious | VirusTotal score: 3/71 (Scanned on 2026-04-16 16:34:29) |
APEX:
Malicious
CrowdStrike: win/malicious_confidence_70% (D) Symantec: ML.Attribute.HighConfidence |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 10 |
| TimeDateStamp | 2026-Apr-07 15:22:04 |
| PointerToSymbolTable | 0x42d600 |
| NumberOfSymbols | 6030 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x22f400 |
| SizeOfInitializedData | 0x1fde00 |
| SizeOfUninitializedData | 0x400 |
| AddressOfEntryPoint | 0x00000000000013D0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x434000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x4a1e4b |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| advapi32.dll |
ImpersonateAnonymousToken
RevertToSelf SystemFunction036 |
|---|---|
| bcrypt.dll |
BCryptGenRandom
|
| dwmapi.dll |
DwmEnableBlurBehindWindow
DwmSetWindowAttribute |
| gdi32.dll |
ChoosePixelFormat
CreateRectRgn DeleteObject DescribePixelFormat GetDeviceCaps SetPixelFormat SwapBuffers |
| imm32.dll |
ImmAssociateContextEx
ImmGetCompositionStringW ImmGetContext ImmReleaseContext ImmSetCandidateWindow ImmSetCompositionWindow |
| kernel32.dll |
AddVectoredExceptionHandler
CompareStringOrdinal CreateFileMappingA CreateFileW CreateProcessW CreateThread CreateToolhelp32Snapshot CreateWaitableTimerExW DuplicateHandle ExitProcess FindClose FindFirstFileExW FormatMessageW FreeEnvironmentStringsW GetConsoleMode GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentThread GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFullPathNameW GetModuleHandleW GetProcessHeap GetStdHandle GetSystemDirectoryW GetSystemTimePreciseAsFileTime GetWindowsDirectoryW GlobalAlloc GlobalFree GlobalLock GlobalSize GlobalUnlock HeapAlloc HeapFree HeapReAlloc InitOnceBeginInitialize InitOnceComplete LoadLibraryA LoadLibraryExA LoadLibraryW MapViewOfFile Module32FirstW Module32NextW MultiByteToWideChar QueryPerformanceCounter QueryPerformanceFrequency ReadFileEx RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind SetFileInformationByHandle SetFilePointerEx SetFileTime SetLastError SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread TlsAlloc TlsFree TlsGetValue TlsSetValue UnmapViewOfFile WaitForSingleObject WideCharToMultiByte WriteConsoleW WriteFileEx |
| ntdll.dll |
NtOpenFile
NtReadFile NtWriteFile RtlNtStatusToDosError |
| ole32.dll |
CoCreateInstance
CoInitializeEx CoTaskMemFree CoUninitialize OleInitialize RegisterDragDrop RevokeDragDrop |
| oleaut32.dll |
GetErrorInfo
SafeArrayCreateVector SafeArrayPutElement SetErrorInfo SysAllocStringLen SysFreeString SysStringLen VariantClear |
| opengl32.dll |
wglCreateContext
wglDeleteContext wglGetCurrentContext wglGetCurrentDC wglGetProcAddress wglMakeCurrent wglShareLists |
| shell32.dll |
DragFinish
DragQueryFileW SHCreateItemFromParsingName |
| shlwapi.dll |
AssocQueryStringW
|
| uiautomationcore.dll |
UiaGetReservedNotSupportedValue
UiaHostProviderFromHwnd UiaLookupId UiaRaiseAutomationEvent UiaRaiseAutomationPropertyChangedEvent UiaReturnRawElementProvider |
| user32.dll |
AdjustWindowRectEx
CallWindowProcW ChangeDisplaySettingsExW ClientToScreen ClipCursor CloseClipboard CloseTouchInputHandle CreateIcon CreateIconFromResourceEx CreateWindowExW DefWindowProcW DestroyCursor DestroyIcon DestroyWindow DispatchMessageW EmptyClipboard EnableMenuItem EnumDisplayMonitors FlashWindowEx GetActiveWindow GetAsyncKeyState GetClassInfoExW GetClassNameW GetClientRect GetClipCursor GetClipboardData GetCursorPos GetDC GetForegroundWindow GetKeyState GetKeyboardLayout GetKeyboardState GetMenu GetMonitorInfoW GetPropW GetRawInputData GetSystemMenu GetSystemMetrics GetTouchInputInfo GetWindowLongPtrW GetWindowLongW GetWindowPlacement GetWindowRect GetWindowTextLengthW GetWindowTextW InvalidateRgn IsClipboardFormatAvailable IsIconic IsProcessDPIAware LoadCursorW MapVirtualKeyExW MapVirtualKeyW MonitorFromPoint MonitorFromRect MonitorFromWindow MsgWaitForMultipleObjectsEx OpenClipboard PeekMessageW PostMessageW RedrawWindow RegisterClassExW RegisterRawInputDevices RegisterTouchWindow RegisterWindowMessageA ReleaseCapture ReleaseDC RemovePropW ScreenToClient SendInput SendMessageW SetCapture SetClipboardData SetCursor SetCursorPos SetForegroundWindow SetPropW SetWindowDisplayAffinity SetWindowLongPtrW SetWindowLongW SetWindowPlacement SetWindowPos SetWindowTextW ShowCursor ShowWindow SystemParametersInfoA ToUnicodeEx TrackMouseEvent TranslateMessage ValidateRect |
| uxtheme.dll |
SetWindowTheme
|
| KERNEL32.dll |
DeleteCriticalSection
EnterCriticalSection InitializeCriticalSection LeaveCriticalSection RaiseException RtlUnwindEx VirtualProtect VirtualQuery __C_specific_handler |
| msvcrt.dll |
__getmainargs
__initenv __iob_func __set_app_type __setusermatherr _amsg_exit _cexit _commode _errno _exit _fmode _fpreset _hypot _initterm _onexit abort calloc exit exp fprintf free frexp fwrite ldexp malloc memcmp memcpy memmove memset pow signal strlen strncmp vfprintf wcslen |
| ntdll.dll (#2) |
NtOpenFile
NtReadFile NtWriteFile RtlNtStatusToDosError |
| kernel32.dll (#2) |
AddVectoredExceptionHandler
CompareStringOrdinal CreateFileMappingA CreateFileW CreateProcessW CreateThread CreateToolhelp32Snapshot CreateWaitableTimerExW DuplicateHandle ExitProcess FindClose FindFirstFileExW FormatMessageW FreeEnvironmentStringsW GetConsoleMode GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentThread GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFullPathNameW GetModuleHandleW GetProcessHeap GetStdHandle GetSystemDirectoryW GetSystemTimePreciseAsFileTime GetWindowsDirectoryW GlobalAlloc GlobalFree GlobalLock GlobalSize GlobalUnlock HeapAlloc HeapFree HeapReAlloc InitOnceBeginInitialize InitOnceComplete LoadLibraryA LoadLibraryExA LoadLibraryW MapViewOfFile Module32FirstW Module32NextW MultiByteToWideChar QueryPerformanceCounter QueryPerformanceFrequency ReadFileEx RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind SetFileInformationByHandle SetFilePointerEx SetFileTime SetLastError SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread TlsAlloc TlsFree TlsGetValue TlsSetValue UnmapViewOfFile WaitForSingleObject WideCharToMultiByte WriteConsoleW WriteFileEx |
| kernel32.dll (#3) |
AddVectoredExceptionHandler
CompareStringOrdinal CreateFileMappingA CreateFileW CreateProcessW CreateThread CreateToolhelp32Snapshot CreateWaitableTimerExW DuplicateHandle ExitProcess FindClose FindFirstFileExW FormatMessageW FreeEnvironmentStringsW GetConsoleMode GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentThread GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFullPathNameW GetModuleHandleW GetProcessHeap GetStdHandle GetSystemDirectoryW GetSystemTimePreciseAsFileTime GetWindowsDirectoryW GlobalAlloc GlobalFree GlobalLock GlobalSize GlobalUnlock HeapAlloc HeapFree HeapReAlloc InitOnceBeginInitialize InitOnceComplete LoadLibraryA LoadLibraryExA LoadLibraryW MapViewOfFile Module32FirstW Module32NextW MultiByteToWideChar QueryPerformanceCounter QueryPerformanceFrequency ReadFileEx RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind SetFileInformationByHandle SetFilePointerEx SetFileTime SetLastError SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread TlsAlloc TlsFree TlsGetValue TlsSetValue UnmapViewOfFile WaitForSingleObject WideCharToMultiByte WriteConsoleW WriteFileEx |
| api-ms-win-core-synch-l1-2-0.dll |
WaitOnAddress
WakeByAddressAll WakeByAddressSingle |
| bcryptprimitives.dll |
ProcessPrng
|
| StartAddressOfRawData | 0x140431000 |
|---|---|
| EndAddressOfRawData | 0x140431008 |
| AddressOfIndex | 0x14042c1fc |
| AddressOfCallbacks | 0x140430040 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x00000001401B6490
0x000000014022F210 0x000000014022F1E0 |
No comments yet.