565432f375223704c560e11e441c194e06ce7c5c0a40a9ea74e524f927c20edb

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Aug-07 20:22:58
Detected languages English - United States
Debug artifacts C:\Users\Han3\Desktop\Legit\x64\Release\Internal MAGIC BULLET.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • Exploit
Malicious The PE contains functions mostly used by malware. Uses functions commonly found in keyloggers:
  • MapVirtualKeyW
  • CallNextHookEx
  • GetAsyncKeyState
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Reads the contents of the clipboard:
  • GetClipboardData
Info The PE is digitally signed. Signer: Henan Pushitong Intelligent Technology Co.
Issuer: VeriSign Class 3 Code Signing 2010 CA
Malicious VirusTotal score: 23/71 (Scanned on 2026-08-07 22:04:50) ALYac: Gen:Variant.Zusy.606381
AVG: Win64:MalwareX-gen [Cryp]
Arcabit: Trojan.Zusy.D940AD
Avast: Win64:MalwareX-gen [Cryp]
Avira: TR/W64.MalwareX
BitDefender: Gen:Variant.Zusy.606381
CTX: dll.unknown.zusy
Cynet: Malicious (score: 99)
ESET-NOD32: Win32/GenCBL.FRW trojan
Elastic: Windows.Generic.MalCert
Emsisoft: Gen:Variant.Zusy.606381 (B)
F-Secure: Trojan.TR/W64.MalwareX
Fortinet: W32/GenCBL.FRW!tr
GData: Gen:Variant.Zusy.606381
Ikarus: Trojan.Win64.Krypt
K7AntiVirus: Trojan ( 006d9bf01 )
K7GW: Trojan ( 006d9bf01 )
Kaspersky: HEUR:Trojan.Win32.Generic
Malwarebytes: Malware.AI.2853650554
McAfeeD: ti!565432F37522
MicroWorld-eScan: Gen:Variant.Zusy.606381
Rising: Trojan.MalCert!1.101B3 (CLASSIC)
VIPRE: Gen:Variant.Zusy.606381

Hashes

MD5 0dbf84c4c0e4b084edb9ab33e2d011ad
SHA1 4c1133f79cd8cbcc362986354ad8a3bc964c56e7
SHA256 565432f375223704c560e11e441c194e06ce7c5c0a40a9ea74e524f927c20edb
SHA3 e7ca9b4de171b9a868e6518be55b777d2199087c8349347679ab858d19bb1345
SSDeep 12288:cRzJbWAlnaRh7oeHg65hVMguacmxX4QQKA:ih8X5hV9uGgK
Imports Hash 20aaebf511d4c6d32883f2cda657e103

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-07 20:22:58
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x5d200
SizeOfInitializedData 0x2d000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000005B360 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x8f000
SizeOfHeaders 0x400
Checksum 0x848d0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e298c038055fb0876903a8b486e0467b
SHA1 712754441565ec02c61f3c554c14b2fee9693019
SHA256 6e0cccee2907be2b4f5b7dfefcf3aa0d26d9af8e8fd5d846f465a0624015cac7
SHA3 67adb0830e3dfda573c8d526257ab5968969537b57e79e1d282296e6287df1d6
VirtualSize 0x5d070
VirtualAddress 0x1000
SizeOfRawData 0x5d200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.49309

.rdata

MD5 49bec219a3b6b1144f6aa98183be4a71
SHA1 d65e2fe58f2d0654248c7c879c4f49fec4dd7bd0
SHA256 d7f5ddd5b223390b59b60412ecb13d3d1d704ec6bebd68d4a4e782f3f9eead7c
SHA3 0786c49f0ff84f750bf845ddbd722fcab1d6a32d0eaf41f6686f69c0c9dd2d58
VirtualSize 0x1792a
VirtualAddress 0x5f000
SizeOfRawData 0x17a00
PointerToRawData 0x5d600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.14151

.data

MD5 c877e7ccef4186e9e37aa81d34a9631e
SHA1 378f414181188a5bdcba633958ff639cd0292c26
SHA256 340b3af2873ad59287a3d8ebfa7694a2efa0bf51f79c93b79c35114cfd95b450
SHA3 d0487eff7b5edf8d7084d8871e340382d13d41f5bd93b2a7425ebfaef1b31523
VirtualSize 0x11f38
VirtualAddress 0x77000
SizeOfRawData 0xe00
PointerToRawData 0x75000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.41417

.pdata

MD5 e23a3b4e69c24142228081b3a154d4e2
SHA1 718dda1fc56cc4a6d75578c09a4e9f03d1cbe134
SHA256 75e83b7c1f23863854117a9e9ecbdfac4c528730fa257e09757595a7852ce069
SHA3 fe39de5d3c1ee2ac792f4f55961890c454494ae6e08a6d835c0cbda141485f73
VirtualSize 0x3060
VirtualAddress 0x89000
SizeOfRawData 0x3200
PointerToRawData 0x75e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.59893

.rsrc

MD5 f4342c239dab36caec376a4ba0a8ab79
SHA1 d75111d15e8ffc8a2add894c829e0339ce311023
SHA256 635dd3a1e247137a4e5eb24d4f3285907009d0ceddcc295375d04f0a082e37fd
SHA3 87f5305039d078b257a94f2933f8b3fac1cce30d2f697d86f831979091792d48
VirtualSize 0x1e0
VirtualAddress 0x8d000
SizeOfRawData 0x200
PointerToRawData 0x79000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.72473

.reloc

MD5 a98a58eb65b6d846825d0725324a6c3b
SHA1 1b9c5120c74711dca0e6e5f2e3365a8d5069cd57
SHA256 bd4434538ca6f9e6bcb289c3e4750e30063d8cd9333cc02040ee18b4f29f9b14
SHA3 ffe93145b10b6f0f8b46ea6e85a3157de26b297d1f8164f1b8f3aba43138509d
VirtualSize 0x200
VirtualAddress 0x8e000
SizeOfRawData 0x200
PointerToRawData 0x79200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.03808

Imports

KERNEL32.dll Sleep
GetLastError
DisableThreadLibraryCalls
Beep
DeleteCriticalSection
VirtualQuery
GetTickCount64
GetFileAttributesA
GetLocalTime
GlobalLock
WideCharToMultiByte
GlobalUnlock
FormatMessageA
InitializeSListHead
GetSystemTimeAsFileTime
GetCurrentThreadId
GetCurrentProcessId
QueryPerformanceCounter
IsProcessorFeaturePresent
TerminateProcess
GetCurrentProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
SleepConditionVariableSRW
WakeAllConditionVariable
InitializeCriticalSectionEx
VirtualAlloc
GetModuleHandleExW
GetTickCount
VirtualProtect
GetLocaleInfoEx
CreateDirectoryW
CreateFileW
FindClose
FindFirstFileW
GetFileAttributesExW
AreFileApisANSI
CloseHandle
GetFileInformationByHandleEx
MultiByteToWideChar
IsDebuggerPresent
OutputDebugStringW
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
LocalFree
USER32.dll MapVirtualKeyW
GetDC
CallNextHookEx
MessageBoxA
GetCursorPos
ReleaseDC
ToUnicode
GetSystemMetrics
GetClipboardData
CloseClipboard
OpenClipboard
GetAsyncKeyState
GetKeyNameTextA
GetKeyboardState
GDI32.dll GetTextExtentPoint32W
MSVCP140.dll ?always_noconv@codecvt_base@std@@QEBA_NXZ
?uncaught_exceptions@std@@YAHXZ
?_Xinvalid_argument@std@@YAXPEBD@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?setprecision@std@@YA?AU?$_Smanip@_J@1@_J@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@M@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@N@Z
?good@ios_base@std@@QEBA_NXZ
?_Throw_Cpp_error@std@@YAXH@Z
?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?id@?$ctype@_W@std@@2V0locale@2@A
?_Winerror_map@std@@YAHH@Z
?id@?$ctype@D@std@@2V0locale@2@A
?_Syserror_map@std@@YAPEBDH@Z
_Cnd_do_broadcast_at_thread_exit
_Thrd_detach
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAM@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
?getloc@ios_base@std@@QEBA?AVlocale@2@XZ
??7ios_base@std@@QEBA_NXZ
??Bios_base@std@@QEBA_NXZ
?_Getcat@?$ctype@_W@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?narrow@?$ctype@_W@std@@QEBAPEB_WPEB_W0DPEAD@Z
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?_Xlength_error@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z
?_Id_cnt@id@locale@std@@0HA
?_Xbad_alloc@std@@YAXXZ
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
??0_Lockit@std@@QEAA@H@Z
??1_Lockit@std@@QEAA@XZ
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll _CxxThrowException
__std_type_info_destroy_list
__C_specific_handler
memmove
__current_exception_context
memset
__std_exception_destroy
__std_exception_copy
__std_terminate
memcpy
memcmp
__current_exception
api-ms-win-crt-heap-l1-1-0.dll _callnewh
malloc
free
api-ms-win-crt-runtime-l1-1-0.dll _initterm_e
_initterm
_cexit
_crt_atexit
_execute_onexit_table
_register_onexit_function
_initialize_onexit_table
_initialize_narrow_environment
_configure_narrow_argv
_invoke_watson
_errno
_beginthreadex
abort
terminate
_seh_filter_dll
api-ms-win-crt-stdio-l1-1-0.dll fgetc
__stdio_common_vfprintf
_get_stream_buffer_pointers
__stdio_common_vsprintf_s
_fseeki64
fputc
__acrt_iob_func
fsetpos
fflush
__stdio_common_vswprintf_s
fread
ungetc
fclose
fwrite
fgetpos
setvbuf
api-ms-win-crt-utility-l1-1-0.dll rand
srand
api-ms-win-crt-filesystem-l1-1-0.dll _lock_file
_unlock_file
api-ms-win-crt-convert-l1-1-0.dll strtod
strtol
mbstowcs
strtof
api-ms-win-crt-string-l1-1-0.dll tolower
iswprint
toupper
isdigit
api-ms-win-crt-math-l1-1-0.dll ceilf
cos
cosf
atan2f
powf
fmod
acos
fmodf
roundf
fmax
fmin
sin
atan
sinf
sqrt
sqrtf
atan2
api-ms-win-crt-environment-l1-1-0.dll getenv
api-ms-win-crt-locale-l1-1-0.dll ___lc_codepage_func

Delayed Imports

sfsqofsjqjfsqdnsqnfdsqoif

Ordinal 1
Address 0x3730

2

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-07 20:22:58
Version 0.0
SizeofData 90
AddressOfRawData 0x6e75c
PointerToRawData 0x6cd5c
Referenced File C:\Users\Han3\Desktop\Legit\x64\Release\Internal MAGIC BULLET.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-07 20:22:58
Version 0.0
SizeofData 20
AddressOfRawData 0x6e7b8
PointerToRawData 0x6cdb8

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-07 20:22:58
Version 0.0
SizeofData 868
AddressOfRawData 0x6e7cc
PointerToRawData 0x6cdcc

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-07 20:22:58
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x18006eb50
EndAddressOfRawData 0x18006eb58
AddressOfIndex 0x18007836c
AddressOfCallbacks 0x18005f910
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x180077140

RICH Header

XOR Key 0xfc357326
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 20
ASM objects (35207) 4
C objects (35207) 8
C++ objects (35207) 31
Imports (35207) 6
Imports (33145) 9
Total imports 314
C++ objects (LTCG) (35228) 4
ASM objects (35228) 2
Exports (35228) 1
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.