| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2023-Apr-18 22:40:23 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. |
333142 bytes of data starting at offset 0x14000.
Overlay data amounts for 80.2632% of the executable. |
| Malicious | VirusTotal score: 14/57 (Scanned on 2026-08-07 04:51:08) |
CrowdStrike:
win/malicious_confidence_90% (W)
Cylance: Unsafe Cynet: Malicious (score: 100) Fortinet: W32/PossibleThreat Gridinsoft: Trojan.Win32.Wacatac.oa!s1 Jiangmin: Trojan.BAT.azx Malwarebytes: Malware.Heuristic.2062 McAfeeD: ti!45A0FC414AD3 Paloalto: generic.ml SentinelOne: Static AI - Suspicious PE Tencent: Trojan-Dropper.Win32.Agent.hcb Trapmine: malicious.high.ml.score Varist: W32/Trojan.PAIE-8642 huorong: TrojanDropper/Agent.amc |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2023-Apr-18 22:40:23 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 6.0 |
| SizeOfCode | 0xf000 |
| SizeOfInitializedData | 0xb04000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000090C6 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x10000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xb14000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetTempPathA
GetModuleFileNameA GetStdHandle SetConsoleMode GetConsoleMode Sleep SetConsoleTextAttribute GetTickCount SetConsoleCursorInfo SetConsoleCursorPosition GetVolumeInformationA ReadConsoleInputA WriteConsoleA LCMapStringW LCMapStringA SetEnvironmentVariableA CompareStringW ExitProcess TerminateProcess GetCurrentProcess GetCommandLineA GetVersion SetHandleCount GetFileType GetStartupInfoA GetLastError ReadFile SetFilePointer HeapFree CloseHandle GetFileAttributesA GetProcAddress GetModuleHandleA WriteFile UnhandledExceptionFilter FreeEnvironmentStringsA FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStrings GetEnvironmentStringsW HeapDestroy HeapCreate VirtualFree RtlUnwind HeapAlloc SetStdHandle FlushFileBuffers VirtualAlloc HeapReAlloc CreateFileA GetExitCodeProcess WaitForSingleObject CreateProcessA MultiByteToWideChar GetStringTypeA GetStringTypeW GetCPInfo GetACP GetOEMCP LoadLibraryA SetEndOfFile CompareStringA |
|---|---|
| USER32.dll |
FindWindowA
GetDesktopWindow GetWindowRect SetWindowPos |
| WINMM.dll |
timeGetTime
|
| XOR Key | 0xa0b83448 |
|---|---|
| Unmarked objects | 0 |
| 12 (7291) | 2 |
| C++ objects (VS98 build 8168) | 1 |
| 14 (7299) | 15 |
| 19 (8034) | 7 |
| Total imports | 70 |
| C objects (VS98 build 8168) | 95 |
| Resource objects (VS98 cvtres build 1720) | 1 |
No comments yet.