| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jul-25 13:24:48 |
| Detected languages |
English - United States
|
| TLS Callbacks | 2 callback(s) detected. |
| Debug artifacts |
C:\Program Files (x86)\Microsoft\Edge\Application\installer\MicrosoftEdgeUpdate.pdb
|
| CompanyName | |
| FileDescription | |
| FileVersion | |
| InternalName | |
| LegalCopyright | |
| OriginalFilename | |
| ProductName | |
| ProductVersion |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
| Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
| Suspicious | The PE contains functions most legitimate programs don't use. |
Possibly launches other programs:
|
| Malicious | The PE is possibly a dropper. |
Resource 740 is possibly compressed or encrypted.
Resource 2001 detected as a PE Executable. Resources amount for 98.4247% of the executable. |
| Malicious | The PE's digital signature is invalid. |
Signer: Microsoft Windows
Issuer: Microsoft Windows Production PCA 2011 The file was modified after it was signed. |
| Malicious | VirusTotal score: 19/70 (Scanned on 2026-07-31 11:36:51) |
ALYac:
Gen:Variant.Yogi.33607
AVG: Win64:MalwareX-gen [Misc] AhnLab-V3: Trojan/Win.MalwareX-gen.R785986 Antiy-AVL: Trojan[Packed]/Win64.VMProtect Arcabit: Trojan.Yogi.D8347 Avast: Win64:MalwareX-gen [Misc] BitDefender: Gen:Variant.Yogi.33607 Bkav: W32.Malware.345057C CTX: exe.unknown.yogi DeepInstinct: MALICIOUS ESET-NOD32: Win64/Packed.VMProtect.AM suspicious application Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Yogi.33607 (B) GData: Gen:Variant.Yogi.33607 Kaspersky: Trojan.Win64.Agent.smfizr MicroWorld-eScan: Gen:Variant.Yogi.33607 Microsoft: Trojan:Win32/Wacatac.B!ml Trapmine: malicious.moderate.ml.score VIPRE: Gen:Variant.Yogi.33607 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x78 |
| e_cp | 0x1 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0 |
| e_ss | 0 |
| e_sp | 0 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x78 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Jul-25 13:24:48 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x34000 |
| SizeOfInitializedData | 0x1192600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000001000 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x11cc000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x11cc922 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| USER32.dll |
GetDC
GetSystemMetrics ReleaseDC wsprintfA |
|---|---|
| SHELL32.dll |
ShellExecuteExA
|
| CRYPT32.dll |
CryptBinaryToStringA
CryptStringToBinaryA |
| WINHTTP.dll |
WinHttpAddRequestHeaders
WinHttpCloseHandle WinHttpConnect WinHttpOpen WinHttpOpenRequest WinHttpQueryDataAvailable WinHttpQueryHeaders WinHttpReadData WinHttpReceiveResponse WinHttpSendRequest WinHttpSetOption WinHttpSetTimeouts |
| gdiplus.dll |
GdipAlloc
GdipCloneImage GdipCreateBitmapFromHBITMAP GdipDisposeImage GdipFree GdipGetImageEncoders GdipGetImageEncodersSize GdipSaveImageToStream GdiplusShutdown GdiplusStartup |
| GDI32.dll |
BitBlt
CreateCompatibleBitmap CreateCompatibleDC DeleteDC DeleteObject SelectObject |
| ole32.dll |
CreateStreamOnHGlobal
|
| bcrypt.dll |
BCryptCloseAlgorithmProvider
BCryptCreateHash BCryptDecrypt BCryptDestroyHash BCryptDestroyKey BCryptFinishHash BCryptGenerateSymmetricKey BCryptGetProperty BCryptHashData BCryptOpenAlgorithmProvider BCryptSetProperty |
| api-ms-win-crt-stdio-l1-1-0.dll |
__acrt_iob_func
__p__commode __p__fmode __stdio_common_vfprintf __stdio_common_vfwprintf __stdio_common_vsprintf __stdio_common_vswprintf _fileno _setmode fflush fputc fputwc setvbuf |
| api-ms-win-crt-string-l1-1-0.dll |
isspace
memset strcat strcmp strlen strncmp strnlen wcscmp wcslen wcsnlen |
| api-ms-win-crt-runtime-l1-1-0.dll |
_assert
__p___argc __p___argv __p__acmdln _cexit _configure_narrow_argv _crt_atexit _errno _exit _initialize_narrow_environment _initterm _initterm_e _seh_filter_exe _set_app_type _set_invalid_parameter_handler abort exit strerror |
| api-ms-win-crt-locale-l1-1-0.dll |
___lc_codepage_func
___mb_cur_max_func _configthreadlocale localeconv |
| api-ms-win-crt-heap-l1-1-0.dll |
_aligned_free
_aligned_malloc _set_new_mode calloc free malloc realloc |
| api-ms-win-crt-private-l1-1-0.dll |
memchr
memcmp memcpy memmove strstr |
| api-ms-win-crt-utility-l1-1-0.dll |
rand
srand |
| ADVAPI32.dll |
GetUserNameA
|
| KERNEL32.dll |
AcquireSRWLockExclusive
CloseHandle CopyFileA CreateDirectoryA CreateEventW CreateFileA CreateMutexA CreateProcessA DeleteCriticalSection EnterCriticalSection ExitProcess FindResourceA GetCommandLineA GetComputerNameA GetEnvironmentVariableA GetLastError GetModuleFileNameA GetModuleHandleA GetModuleHandleW GetProcAddress GetStartupInfoA GetSystemInfo GetSystemTimeAsFileTime GetTempPathA GetTickCount GetVolumeInformationA GlobalMemoryStatusEx InitializeCriticalSection IsDBCSLeadByte LeaveCriticalSection LoadResource LockResource MultiByteToWideChar RaiseException ReleaseMutex ReleaseSRWLockExclusive RtlCaptureContext RtlLookupFunctionEntry RtlRestoreContext RtlUnwindEx RtlVirtualUnwind SetErrorMode SetThreadErrorMode SetUnhandledExceptionFilter SizeofResource Sleep SleepConditionVariableSRW TlsGetValue VirtualProtect VirtualQuery WaitForSingleObject WakeAllConditionVariable WideCharToMultiByte WriteFile |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
| api-ms-win-crt-environment-l1-1-0.dll |
__p__environ
getenv |
| api-ms-win-crt-convert-l1-1-0.dll |
mbrtowc
strtof wcrtomb |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_lock_file
_unlock_file |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 10.0.26200.1 |
| ProductVersion | 10.0.26200.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | |
| FileDescription | |
| FileVersion (#2) | |
| InternalName | |
| LegalCopyright | |
| OriginalFilename | |
| ProductName | |
| ProductVersion (#2) |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| SizeofData | 108 |
| AddressOfRawData | 0x41778 |
| PointerToRawData | 0x40b78 |
| Referenced File | C:\Program Files (x86)\Microsoft\Edge\Application\installer\MicrosoftEdgeUpdate.pdb |
| StartAddressOfRawData | 0x140046000 |
|---|---|
| EndAddressOfRawData | 0x140046018 |
| AddressOfIndex | 0x140042314 |
| AddressOfCallbacks | 0x14003d2b0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x000000014000D720
0x000000014000D7A0 |
| Size | 0x138 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0 |
No comments yet.