| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Feb-28 10:22:10 |
| Detected languages |
English - United States
Korean - Korea |
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to RC5 or RC6 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 3/61 (Scanned on 2026-04-04 04:07:01) |
APEX:
Malicious
CrowdStrike: win/malicious_confidence_70% (W) Trapmine: suspicious.low.ml.score |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Feb-28 10:22:10 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x60e00 |
| SizeOfInitializedData | 0x78200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000033C74 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xdd000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
FindResourceA
WaitForSingleObject GetCurrentThreadId ResumeThread GetModuleHandleA CreateToolhelp32Snapshot Sleep GetLastError TerminateThread LockResource QueryPerformanceFrequency Process32Next LoadResource GetProcAddress GetCurrentProcessId QueryPerformanceCounter GetTickCount WriteConsoleW HeapSize HeapReAlloc GetProcessHeap FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetOEMCP GetACP IsValidCodePage FlushFileBuffers GetFileSizeEx EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW GetConsoleOutputCP SetStdHandle ReadConsoleW GetConsoleMode GetFileType HeapFree HeapAlloc GetStdHandle FreeLibraryAndExitThread ExitThread CreateThread FindFirstFileExW FindClose SetEndOfFile GetModuleHandleExW ExitProcess LoadLibraryExW FreeLibrary TlsFree TlsSetValue TlsGetValue TlsAlloc SetLastError RaiseException RtlPcToFileHeader RtlUnwindEx GetCPInfo LCMapStringEx DecodePointer EncodePointer GetModuleFileNameW TerminateProcess GetCurrentProcess FindNextFileW Process32First SizeofResource UnmapViewOfFile WideCharToMultiByte SystemTimeToFileTime GetCurrentDirectoryW CloseHandle LocalFileTimeToFileTime MultiByteToWideChar CreateFileW SetFilePointer FlsFree FlsSetValue FlsGetValue FlsAlloc TryEnterCriticalSection InitializeCriticalSectionEx AcquireSRWLockExclusive ReleaseSRWLockExclusive InitializeSRWLock GetStringTypeW InitializeSListHead GetSystemTimeAsFileTime GetStartupInfoW IsDebuggerPresent IsProcessorFeaturePresent SetUnhandledExceptionFilter UnhandledExceptionFilter GetModuleHandleW CreateEventW WaitForSingleObjectEx ResetEvent SetEvent DeleteCriticalSection InitializeCriticalSectionAndSpinCount LeaveCriticalSection EnterCriticalSection WriteFile ReadFile SetFilePointerEx RtlUnwind |
|---|---|
| USER32.dll |
UpdateLayeredWindow
PeekMessageA GetClientRect PrintWindow SetCursor SendMessageA TranslateMessage ChangeWindowMessageFilter DefWindowProcA EnumWindows GetForegroundWindow ReleaseDC SetForegroundWindow RegisterClassW SetClassLongPtrA GetWindowTextA GetAsyncKeyState IsWindow ShowWindow GetActiveWindow TrackPopupMenu WindowFromPoint GetSystemMetrics CreateWindowExW PostMessageA EnumChildWindows MessageBoxW SetWindowPos GetDC GetCursorPos MessageBoxA LoadCursorA GetWindowThreadProcessId GetKeyState GetClassLongPtrA LoadImageA SetProcessDpiAwarenessContext DispatchMessageA |
| GDI32.dll |
GetCurrentObject
CreateBitmap DeleteObject BitBlt CreateCompatibleBitmap SelectObject CreateCompatibleDC GdiAlphaBlend StretchBlt GetBitmapBits GetDeviceCaps DeleteDC SetBitmapBits SetStretchBltMode GetObjectA |
| SHELL32.dll |
Shell_NotifyIconW
|
| ole32.dll |
CreateStreamOnHGlobal
|
| gdiplus.dll |
GdipDeleteFontFamily
GdipGetImageHeight GdipSetCompositingQuality GdipDrawRectangleI GdipCreateFontFamilyFromName GdipDrawLineI GdipCreatePen1 GdipCreateBitmapFromScan0 GdipDeletePen GdipGetImageWidth GdipGetFontSize GdipDeleteGraphics GdipGetImageGraphicsContext GdipMeasureString GdipStringFormatGetGenericTypographic GdipSetTextRenderingHint GdipCreateFromHDC GdipDrawString GdipFree GdipGetGenericFontFamilySansSerif GdipCreateHBITMAPFromBitmap GdipGraphicsClear GdipCreateSolidFill GdipSetInterpolationMode GdipCreateFont GdipSetSmoothingMode GdipDisposeImage GdipAlloc GdipCreateBitmapFromStream GdipDeleteBrush GdipCloneImage GdiplusStartup |
| ntdll.dll |
RtlCaptureContext
RtlLookupFunctionEntry RtlVirtualUnwind |
| IMM32.dll |
ImmReleaseContext
ImmGetContext ImmSetConversionStatus |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Feb-28 10:22:10 |
| Version | 0.0 |
| SizeofData | 1008 |
| AddressOfRawData | 0x78194 |
| PointerToRawData | 0x77394 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Feb-28 10:22:10 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1400785a8 |
|---|---|
| EndAddressOfRawData | 0x1400785b0 |
| AddressOfIndex | 0x140083528 |
| AddressOfCallbacks | 0x1400627d0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x138 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140080010 |
| XOR Key | 0x87b3c424 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (29395) | 11 |
| C++ objects (29395) | 203 |
| 253 (28518) | 3 |
| C++ objects (30034) | 87 |
| C objects (30034) | 18 |
| ASM objects (30034) | 10 |
| C objects (29395) | 20 |
| Imports (29395) | 23 |
| Total imports | 367 |
| C++ objects (LTCG) (VS2019 Update 11 (16.11.13) compiler 30143) | 3 |
| Resource objects (VS2019 Update 11 (16.11.13) compiler 30143) | 1 |
| 151 | 1 |
| Linker (VS2019 Update 11 (16.11.13) compiler 30143) | 1 |
No comments yet.