| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Aug-04 20:34:37 |
| Detected languages |
English - United States
|
| CompanyName | Madium |
| FileDescription | Madium Installer |
| FileVersion | 1.0.7 |
| InternalName | Madium Installer |
| OriginalFilename | Installer-1.0.7.exe |
| ProductName | Madium Installer |
| ProductVersion | 1.0.7 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for Qemu presence:
|
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE is possibly a dropper. |
Resource PAYLOAD_CAB detected as a CAB Installer file.
Resources amount for 98.3359% of the executable. |
| Malicious | VirusTotal score: 6/69 (Scanned on 2026-08-05 18:02:52) |
APEX:
Malicious
Gridinsoft: Trojan.Win64.Wacatac.bot Microsoft: Trojan:Win32/Wacatac.B!ml Rising: Trojan.Kryptik!8.8 (CLOUD) Trapmine: malicious.high.ml.score TrellixENS: Artemis!32E6C794181E |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Aug-04 20:34:37 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x17000 |
| SizeOfInitializedData | 0x9b0a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000008C90 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x9cc000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ole32.dll |
CoTaskMemFree
CoCreateGuid StringFromGUID2 |
|---|---|
| SETUPAPI.dll |
SetupIterateCabinetW
|
| SHELL32.dll |
SHGetKnownFolderPath
|
| KERNEL32.dll |
RaiseException
WriteConsoleW SetFilePointerEx GetConsoleMode GetConsoleOutputCP CreateFileW WriteFile GetTempPathW CloseHandle GetLastError SetLastError WaitForSingleObject GetExitCodeProcess CreateProcessW GetModuleHandleW LoadResource LockResource SizeofResource FindResourceW LocalFree FormatMessageW FlushFileBuffers HeapReAlloc HeapSize FormatMessageA GetLocaleInfoEx CreateDirectoryW FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesExW SetFileInformationByHandle CreateFile2 GetProcAddress GetFileInformationByHandleEx MultiByteToWideChar WideCharToMultiByte QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead SetUnhandledExceptionFilter GetStartupInfoW RtlPcToFileHeader RtlLookupFunctionEntry RtlUnwindEx FlsAlloc FlsGetValue FlsSetValue FlsFree EncodePointer EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection GetCPInfo IsProcessorFeaturePresent GetStdHandle GetModuleFileNameW GetCurrentProcess ExitProcess TerminateProcess FreeLibrary GetModuleHandleExW RtlCaptureContext RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter HeapAlloc HeapFree GetStringTypeW IsValidCodePage GetACP GetOEMCP GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW SetStdHandle GetFileType VirtualProtect LoadLibraryExW LCMapStringW GetProcessHeap |
| USER32.dll |
MessageBoxW
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.7.0 |
| ProductVersion | 1.0.7.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Madium |
| FileDescription | Madium Installer |
| FileVersion (#2) | 1.0.7 |
| InternalName | Madium Installer |
| OriginalFilename | Installer-1.0.7.exe |
| ProductName | Madium Installer |
| ProductVersion (#2) | 1.0.7 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-04 20:34:37 |
| Version | 0.0 |
| SizeofData | 840 |
| AddressOfRawData | 0x24410 |
| PointerToRawData | 0x23810 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140028040 |
| XOR Key | 0x2757c31e |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 142 |
| C objects (33145) | 12 |
| ASM objects (33145) | 7 |
| ASM objects (35721) | 10 |
| C objects (35721) | 16 |
| C++ objects (35721) | 47 |
| C objects (CVTCIL) (33145) | 1 |
| Imports (33145) | 11 |
| Total imports | 126 |
| C++ objects (36252) | 1 |
| Resource objects (36252) | 1 |
| 151 | 1 |
| Linker (36252) | 1 |
No comments yet.