| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-May-15 21:28:22 |
| Detected languages |
English - United States
|
| Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. | 6440 bytes of data starting at offset 0x3be00. |
| Malicious | VirusTotal score: 44/69 (Scanned on 2026-03-17 05:57:31) |
ALYac:
Trojan.GenericKD.77040213
APEX: Malicious AhnLab-V3: Trojan/Win.Generic.C5789004 Antiy-AVL: Trojan/Win32.Agent Arcabit: Trojan.Generic.D4978A55 Avira: TR/PSW.Agent.jqsix BitDefender: Trojan.GenericKD.77040213 Bkav: W64.AIDetectMalware CAT-QuickHeal: Trojan.Ghanarava.17735785178de34f CTX: dll.trojan.generic CrowdStrike: win/malicious_confidence_100% (D) Cylance: Unsafe Cynet: Malicious (score: 99) DeepInstinct: MALICIOUS ESET-NOD32: Win64/PSW.Agent.PR trojan Elastic: malicious (high confidence) Emsisoft: Trojan.GenericKD.77040213 (B) F-Secure: Trojan.TR/PSW.Agent.jqsix Fortinet: W64/Agent.PR!tr.pws GData: Trojan.GenericKD.77040213 Google: Detected Ikarus: Trojan-PSW.Agent K7AntiVirus: Riskware ( 00584baa1 ) K7GW: Riskware ( 00584baa1 ) Kaspersky: Trojan.Win32.Agent.xbzkbu Lionic: Trojan.Win32.Agent.Y!c Malwarebytes: Malware.AI.80050476 MaxSecure: Trojan.Malware.411251904.susgen McAfeeD: ti!5A65621791CD MicroWorld-eScan: Trojan.GenericKD.77040213 Microsoft: Trojan:Win32/Alevaul!rfn Paloalto: generic.ml Panda: Trj/Chgt.AD Rising: Stealer.Agent!8.C2 (CLOUD) Sophos: Mal/Generic-S Symantec: Trojan.Gen.MBT Tencent: Malware.Win32.Gencirc.149ba41b TrellixENS: Artemis!D51B0B861641 TrendMicro-HouseCall: TROJ_GEN.R002H09CD26 VIPRE: Trojan.GenericKD.77040213 Varist: W64/ABTrojan.ZFXZ-1286 ViRobot: Trojan.Win.Z.Agent.251688 Zillya: Trojan.Agent.Win64.100278 alibabacloud: Trojan:Win/Agent.xhwuyv |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2025-May-15 21:28:22 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x27200 |
| SizeOfInitializedData | 0x16000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000000B0F8 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x42000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetCurrentDirectoryW
ReadFile WriteFile WriteConsoleW GetFileSizeEx CreateFileA GetLastError CloseHandle CreateFileW GetConsoleMode GetConsoleOutputCP FlushFileBuffers HeapSize SetStdHandle SetFilePointerEx GetProcessHeap FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW WideCharToMultiByte MultiByteToWideChar GetStringTypeW EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection EncodePointer DecodePointer LCMapStringEx GetCPInfo RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW GetModuleHandleW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead RtlUnwindEx RtlPcToFileHeader RaiseException InterlockedFlushSList SetLastError InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary GetProcAddress LoadLibraryExW ExitProcess GetModuleHandleExW GetModuleFileNameW HeapFree HeapAlloc GetStdHandle GetFileType FlsAlloc FlsGetValue FlsSetValue FlsFree LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW HeapReAlloc FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCommandLineA |
|---|---|
| ADVAPI32.dll |
CryptGetHashParam
CryptDestroyHash CryptHashData CryptReleaseContext CryptCreateHash CryptAcquireContextW GetUserNameW |
| SHELL32.dll |
SHGetKnownFolderPath
SHGetFolderPathA |
| ole32.dll |
CoUninitialize
CoTaskMemFree CoCreateInstance CoSetProxyBlanket CoInitializeEx |
| OLEAUT32.dll |
SysAllocStringByteLen
SysFreeString SysStringByteLen |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-May-15 21:28:22 |
| Version | 0.0 |
| SizeofData | 860 |
| AddressOfRawData | 0x359f4 |
| PointerToRawData | 0x33ff4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-May-15 21:28:22 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x18003a040 |
| XOR Key | 0xbed3ddf1 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 5 |
| C++ objects (30795) | 154 |
| C objects (30795) | 16 |
| ASM objects (34321) | 10 |
| C objects (34321) | 14 |
| C++ objects (34321) | 75 |
| C objects (CVTCIL) (30795) | 1 |
| Imports (30795) | 11 |
| Total imports | 119 |
| C++ objects (LTCG) (34436) | 2 |
| Resource objects (34436) | 1 |
| Linker (34436) | 1 |
No comments yet.