| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jan-25 08:34:10 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
circles_server.pdb
|
| CompanyName | circles |
| FileDescription | Circles Server |
| FileVersion | 1.0.0 |
| ProductName | Circles Server |
| ProductVersion | 1.0.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 Uses constants related to RC5 or RC6 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .taubndl |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/64 (Scanned on 2026-02-09 06:52:07) |
Gridinsoft:
Trojan.Heur!.02016023
Trapmine: malicious.high.ml.score |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Jan-25 08:34:10 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x747c00 |
| SizeOfInitializedData | 0x2ba600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000072286C (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xa06000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ntdll.dll |
NtCancelIoFileEx
NtDeviceIoControlFile NtCreateFile NtWriteFile RtlGetVersion NtOpenFile NtQuerySystemInformation NtQueryInformationProcess RtlNtStatusToDosError NtCreateNamedPipeFile NtReadFile |
|---|---|
| kernel32.dll |
GetEnvironmentVariableW
GetCurrentDirectoryW RtlVirtualUnwind RtlCaptureContext FindClose K32GetPerformanceInfo GetEnvironmentStringsW FreeEnvironmentStringsW FindNextFileW lstrlenW WaitForSingleObject SetWaitableTimer QueryPerformanceCounter Sleep SetEnvironmentVariableW AddVectoredExceptionHandler GlobalMemoryStatusEx GetModuleHandleW GetCommandLineW GetCurrentThreadId ReleaseSRWLockExclusive AcquireSRWLockExclusive SwitchToThread LoadLibraryA GetProcAddress WakeAllConditionVariable SleepConditionVariableSRW GetFileAttributesW CreateProcessW ReadFileEx GetUserDefaultUILanguage LoadLibraryW GetModuleHandleA LCIDToLocaleName GetSystemTimeAsFileTime MultiByteToWideChar RtlLookupFunctionEntry WaitForSingleObjectEx GetCurrentProcess WideCharToMultiByte ReleaseMutex HeapAlloc FormatMessageW GetModuleFileNameW SetHandleInformation SleepEx ExitProcess CompareStringOrdinal GetSystemDirectoryW GetWindowsDirectoryW DuplicateHandle ReadProcessMemory GetProcessTimes OpenProcess GetSystemTimes GetProcessIoCounters VirtualQueryEx WriteFileEx LocalFree CreateThread GetFinalPathNameByHandleW GetTempPathW CloseHandle GetFileInformationByHandleEx GetFileInformationByHandle SetFileInformationByHandle CreateFileW GetFullPathNameW CreateDirectoryW CreateMutexA WriteConsoleW QueryPerformanceFrequency GetConsoleOutputCP GetConsoleMode GetStdHandle IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess InitializeSListHead GetLastError SetLastError GetSystemTimePreciseAsFileTime HeapReAlloc GetSystemInfo GetCurrentProcessId SetFileCompletionNotificationModes CreateIoCompletionPort GetCurrentThread SetThreadStackGuarantee GetQueuedCompletionStatusEx HeapFree LoadLibraryExA FreeLibrary CreateWaitableTimerExW GetProcessHeap PostQueuedCompletionStatus UnhandledExceptionFilter SetUnhandledExceptionFilter OutputDebugStringA OutputDebugStringW LoadLibraryExW FindFirstFileExW |
| api-ms-win-core-synch-l1-2-0.dll |
WakeByAddressSingle
WakeByAddressAll WaitOnAddress |
| user32.dll |
GetMenu
ToUnicodeEx MapVirtualKeyExW GetKeyboardLayout GetKeyState SetWindowLongW GetSystemMenu ClipCursor GetClipCursor ShowCursor GetWindowTextLengthW RegisterRawInputDevices GetMessageW GetWindowTextW RegisterWindowMessageA TranslateMessage IsProcessDPIAware TrackPopupMenu EnableMenuItem CheckMenuItem DispatchMessageW DestroyWindow DrawTextW GetWindowDC OffsetRect MapWindowPoints GetMenuBarInfo RedrawWindow GetClientRect SetParent SendMessageW PostQuitMessage GetCursorPos ShowWindow SystemParametersInfoA EnableWindow SetMenu RemoveMenu DrawIconEx ReleaseDC GetDC AppendMenuW InsertMenuW CreateIcon SetMenuItemInfoW DrawMenuBar CreatePopupMenu CreateMenu IsWindowVisible DestroyAcceleratorTable DestroyIcon SetWindowTextW GetKeyboardState GetAsyncKeyState SetPropW FindWindowExW DestroyMenu IsIconic GetParent SetWindowRgn KillTimer TranslateAcceleratorW MsgWaitForMultipleObjectsEx GetUpdateRect ValidateRect GetRawInputData GetMenuItemInfoW SetTimer MonitorFromWindow EnumDisplayMonitors ChangeWindowMessageFilterEx RegisterClassW GetWindowLongPtrW GetWindow EnumChildWindows DispatchMessageA GetMessageA MonitorFromPoint AdjustWindowRect IsWindowEnabled ClientToScreen GetWindowPlacement SetWindowPlacement ChangeDisplaySettingsExW LoadCursorW PostThreadMessageW PeekMessageW SetCursor GetActiveWindow CloseTouchInputHandle GetTouchInputInfo TrackMouseEvent SetCapture SystemParametersInfoW ReleaseCapture FillRect MonitorFromRect GetWindowLongW ScreenToClient FlashWindowEx DefWindowProcW SetWindowLongPtrW GetMonitorInfoW PostMessageW GetWindowRect SetWindowDisplayAffinity RegisterTouchWindow GetSystemMetrics IsWindow CreateWindowExW AdjustWindowRectEx RegisterClassExW UpdateWindow InvalidateRect SetFocus SetCursorPos SendInput MapVirtualKeyW SetForegroundWindow GetForegroundWindow InvalidateRgn SetWindowPos CreateAcceleratorTableW |
| oleaut32.dll |
SysFreeString
GetErrorInfo SysStringLen SetErrorInfo |
| ole32.dll |
CoTaskMemAlloc
CoInitializeEx CoUninitialize CoCreateFreeThreadedMarshaler CoTaskMemFree CoCreateInstance OleInitialize RegisterDragDrop RevokeDragDrop |
| gdi32.dll |
BitBlt
GetDeviceCaps SetBkMode CombineRgn CreateRectRgn DeleteDC SelectObject SetTextColor CreateDIBSection DeleteObject CreateCompatibleDC CreateSolidBrush |
| dwmapi.dll |
DwmGetWindowAttribute
DwmEnableBlurBehindWindow DwmSetWindowAttribute |
| comctl32.dll |
DefSubclassProc
SetWindowSubclass RemoveWindowSubclass TaskDialogIndirect |
| shell32.dll |
Shell_NotifyIconGetRect
Shell_NotifyIconW DragFinish SHGetKnownFolderPath DragQueryFileW SHAppBarMessage CommandLineToArgvW ShellExecuteW |
| shlwapi.dll |
SHCreateMemStream
|
| bcryptprimitives.dll |
ProcessPrng
|
| crypt32.dll |
CertEnumCertificatesInStore
CertDuplicateStore CertAddCertificateContextToStore CertFreeCertificateContext CertDuplicateCertificateContext CertFreeCertificateChain CertOpenStore CertVerifyCertificateChainPolicy CertDuplicateCertificateChain CertCloseStore CertGetCertificateChain |
| ws2_32.dll |
bind
listen closesocket accept WSAGetLastError ioctlsocket getsockname WSAIoctl setsockopt WSASocketW connect getpeername WSASend shutdown send recv freeaddrinfo getaddrinfo getsockopt WSACleanup WSAStartup socket |
| bcrypt.dll |
BCryptGenRandom
|
| advapi32.dll |
OpenProcessToken
GetTokenInformation IsValidSid EventWriteTransfer SystemFunction036 EventUnregister RegGetValueW EventSetInformation GetLengthSid RegCloseKey RegQueryValueExW RegOpenKeyExW EventRegister CopySid |
| secur32.dll |
QueryContextAttributesW
AcquireCredentialsHandleA AcceptSecurityContext EncryptMessage DecryptMessage FreeCredentialsHandle InitializeSecurityContextW ApplyControlToken FreeContextBuffer DeleteSecurityContext |
| pdh.dll |
PdhCloseQuery
PdhCollectQueryData PdhAddEnglishCounterW PdhGetFormattedCounterValue PdhOpenQueryA PdhRemoveCounter |
| psapi.dll |
GetModuleFileNameExW
GetProcessMemoryInfo |
| powrprof.dll |
CallNtPowerInformation
|
| VCRUNTIME140.dll |
__CxxFrameHandler3
memcpy memmove memset __std_exception_destroy __std_exception_copy memcmp _CxxThrowException __current_exception_context wcsrchr _purecall __current_exception __C_specific_handler |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| api-ms-win-crt-math-l1-1-0.dll |
roundf
__setusermatherr floor pow trunc round |
| api-ms-win-crt-string-l1-1-0.dll |
wcslen
_wcsicmp wcscmp |
| api-ms-win-crt-convert-l1-1-0.dll |
wcstol
_ultow_s _wtoi |
| api-ms-win-crt-runtime-l1-1-0.dll |
_initialize_onexit_table
_initterm _get_initial_narrow_environment _initialize_narrow_environment exit _configure_narrow_argv _exit _set_app_type _register_thread_local_exe_atexit_callback _seh_filter_exe _crt_atexit _initterm_e __p___argc terminate __p___argv _c_exit _register_onexit_function _cexit |
| api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
_set_fmode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
free _set_new_mode _callnewh |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | circles |
| FileDescription | Circles Server |
| FileVersion (#2) | 1.0.0 |
| ProductName | Circles Server |
| ProductVersion (#2) | 1.0.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-25 08:34:10 |
| Version | 0.0 |
| SizeofData | 43 |
| AddressOfRawData | 0x819c54 |
| PointerToRawData | 0x818c54 |
| Referenced File | circles_server.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-25 08:34:10 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x819c80 |
| PointerToRawData | 0x818c80 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-25 08:34:10 |
| Version | 0.0 |
| SizeofData | 1028 |
| AddressOfRawData | 0x819c94 |
| PointerToRawData | 0x818c94 |
| StartAddressOfRawData | 0x14081a0b8 |
|---|---|
| EndAddressOfRawData | 0x14081a284 |
| AddressOfIndex | 0x14098dcd4 |
| AddressOfCallbacks | 0x140749de8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x0000000140614D80
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14098b780 |
| XOR Key | 0xddc92d72 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 14 |
| Imports (35207) | 4 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 30 |
| Imports (30151) | 7 |
| Total imports | 404 |
| Unmarked objects (#2) | 60 |
| Resource objects (35222) | 1 |
| Linker (35222) | 1 |