| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2023-May-14 11:50:28 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\DANYA\Downloads\menu d3d\Release\Zula Menu.pdb
|
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 22/71 (Scanned on 2026-03-27 06:08:33) |
APEX:
Malicious
Bkav: W32.AIDetectMalware CAT-QuickHeal: Trojan.Ghanarava.1690188153a98977 CTX: dll.trojan.emulevader CrowdStrike: win/malicious_confidence_60% (W) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS Fortinet: W32/PossibleThreat Google: Detected Kingsoft: Win32.Troj.EmulEvader.v Lionic: Trojan.Win32.EmulEvader.4!c McAfeeD: ti!58F80B42EDBC Panda: Trj/Chgt.AD Rising: Malware.Undefined!8.C (TFE:5:8YzeAt6dB) SentinelOne: Static AI - Suspicious PE Skyhigh: BehavesLike.Win32.Injector.bh Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence TrellixENS: Artemis!5736259C0DAA Varist: W32/ABTrojan.RCCL-2996 huorong: HVM:VirTool/EmulEvader.gen!A |
| MD5 | 5736259c0daa4be32ee3d5dee2a98977 🔍 |
|---|---|
| SHA1 | 6b5c3baa729bc9f4fc31366852e9a37adb2ad625 🔍 |
| SHA256 | 58f80b42edbc0c1574e039d90948a638041da578fbda47e4d6f4250f5fde936b 🔍 |
| SHA3 | 08f32a85ba00f5dff6d7bfe8b5e4bf2bba52a15d47ce5e4ce46e672d5c37c9fc 🔍 |
| SSDeep | 12288:S+2TVEbBBv4SmBiOzi91oT2GzoHlHVMwI0+TvNxu8uu5ZHQKbtU:S+2RqBuBiOzi9WT2GzodawId7jSutU 🔍 |
| Imports Hash | 460eb0051bdd9f3cf02c8733453e4d0d 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2023-May-14 11:50:28 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x84e00 |
| SizeOfInitializedData | 0x2f000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0002B3EE (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x86000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xb7000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | a6c2d8b936f77dd2d11625482694c05a 🔍 |
|---|---|
| SHA1 | b1105a8c61e2366a1b646b851ab2668626eb5df0 🔍 |
| SHA256 | a711dfda1e7e47c632156636ae163da6afcdfef5beba4fe535d1e8f659662aaa 🔍 |
| SHA3 | 51c32c3a2e44d3405586a89ec44c24276bdb5a6d3041f74603bcae5111d0b3d8 🔍 |
| VirtualSize | 0x84cec |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x84e00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.69454 |
| MD5 | 73c0c8e4c7cb46ad89fd0f1d471321b9 🔍 |
|---|---|
| SHA1 | ccded8478fd575a53a0a9a141419f2ba08550739 🔍 |
| SHA256 | 377da8e22f553949f0cd3b9bc4e295267d7d8ae3d6c6b7145ba973b832c1bd5a 🔍 |
| SHA3 | be864717fc8fd6f645cffbdad8a4ff973f01eb0a103e57579eb933648210272a 🔍 |
| VirtualSize | 0x166d2 |
| VirtualAddress | 0x86000 |
| SizeOfRawData | 0x16800 |
| PointerToRawData | 0x85200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.35027 |
| MD5 | 32f3da56ea107f196207872e08935a56 🔍 |
|---|---|
| SHA1 | 84f2cbed65dc4a47e51717a636f4f5fab0ae9fff 🔍 |
| SHA256 | 32cf3b0c4182c253931f943bcc2a226a0e92aeff31c4a92d2e98105880bca8aa 🔍 |
| SHA3 | 4e21c8d6f54b1c4b25904a845f5821a94285ba6104ba949d17fbf65663477a0e 🔍 |
| VirtualSize | 0x12e3c |
| VirtualAddress | 0x9d000 |
| SizeOfRawData | 0x11000 |
| PointerToRawData | 0x9ba00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 7.64447 |
| MD5 | f7b48f04eabeadec244d681290166017 🔍 |
|---|---|
| SHA1 | de4b87e137fddc18efc978e1c85051a7c56f0b86 🔍 |
| SHA256 | a6f0686382081d3d3f33dd3b4739f692d1bb84a3651bd491d24200e8f35517b8 🔍 |
| SHA3 | c16318f01bb5ce46aa17297e556f004f7ae3812ac8d1eef10ac80240cb8acf31 🔍 |
| VirtualSize | 0x1e0 |
| VirtualAddress | 0xb0000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0xaca00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.70855 |
| MD5 | be7985ae85958d4268585feaf783898c 🔍 |
|---|---|
| SHA1 | 24f470e947de51457d87402269d9978a561cea0c 🔍 |
| SHA256 | 9b95d6c570824e60f1df41b250fe1c2856dd767774e802e0a26c2669282f7f0a 🔍 |
| SHA3 | 3889a9b71dd03fb4d47f860d1f7f2b6938830a0220a05d64b88db366c9b74942 🔍 |
| VirtualSize | 0x55c0 |
| VirtualAddress | 0xb1000 |
| SizeOfRawData | 0x5600 |
| PointerToRawData | 0xacc00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.67244 |
| d3dx9_43.dll |
D3DXCreateLine
D3DXCreateFontA D3DXMatrixTranspose D3DXVec4Transform D3DXVec3Project |
|---|---|
| KERNEL32.dll |
GetCurrentThreadId
WriteConsoleW CreateFileW HeapSize SetStdHandle GetProcessHeap Sleep GetCurrentProcess CreateThread GetSystemInfo VirtualProtect VirtualQuery ReadProcessMemory WriteProcessMemory GetModuleHandleA GetProcAddress LoadLibraryA IsBadReadPtr K32GetModuleInformation SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetOEMCP GetACP IsValidCodePage FindNextFileW FindFirstFileExW FindClose GetTimeZoneInformation SetLastError FlushInstructionCache FreeLibrary FormatMessageA WideCharToMultiByte EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection LocalFree EncodePointer DecodePointer MultiByteToWideChar LCMapStringEx GetLocaleInfoEx GetStringTypeW CompareStringEx GetCPInfo IsProcessorFeaturePresent IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW GetModuleHandleW TerminateProcess QueryPerformanceCounter GetCurrentProcessId OutputDebugStringW GetSystemTimeAsFileTime InitializeSListHead RaiseException RtlUnwind InterlockedPushEntrySList InterlockedFlushSList GetLastError InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree LoadLibraryExW ExitProcess GetModuleHandleExW GetModuleFileNameW GetCurrentThread HeapAlloc HeapFree GetStdHandle GetFileType GetDateFormatW GetTimeFormatW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW CloseHandle FlushFileBuffers WriteFile GetConsoleOutputCP GetConsoleMode ReadFile GetFileSizeEx SetFilePointerEx ReadConsoleW HeapReAlloc SetConsoleCtrlHandler |
| USER32.dll |
GetSystemMetrics
GetAsyncKeyState DefWindowProcA SendInput GetDesktopWindow SetRect |
| d3d9.dll |
Direct3DCreate9
|
| WINMM.dll |
timeGetTime
|
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-May-14 11:50:28 |
| Version | 0.0 |
| SizeofData | 80 |
| AddressOfRawData | 0x9714c |
| PointerToRawData | 0x9634c |
| Referenced File | C:\Users\DANYA\Downloads\menu d3d\Release\Zula Menu.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-May-14 11:50:28 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x9719c |
| PointerToRawData | 0x9639c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-May-14 11:50:28 |
| Version | 0.0 |
| SizeofData | 952 |
| AddressOfRawData | 0x971b0 |
| PointerToRawData | 0x963b0 |
| StartAddressOfRawData | 0x10097578 |
|---|---|
| EndAddressOfRawData | 0x10097579 |
| AddressOfIndex | 0x100aea68 |
| AddressOfCallbacks | 0x10086258 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_1BYTES
|
| Callbacks | (EMPTY) |
| Size | 0xbc |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x100ac634 |
| SEHandlerTable | 0 |
| SEHandlerCount | 0 |
| XOR Key | 0x26cfaa0f |
|---|---|
| Unmarked objects | 0 |
| ASM objects (28900) | 25 |
| C++ objects (28900) | 163 |
| C objects (28900) | 23 |
| C objects (30034) | 17 |
| ASM objects (30034) | 22 |
| C++ objects (30034) | 68 |
| C++ objects (9254) | 2 |
| Imports (28900) | 8 |
| Imports (21202) | 3 |
| Total imports | 112 |
| C++ objects (VS2019 Update 11 (16.11.14-15) compiler 30145) | 1 |
| Resource objects (VS2019 Update 11 (16.11.14-15) compiler 30145) | 1 |
| Linker (VS2019 Update 11 (16.11.14-15) compiler 30145) | 1 |
No comments yet.