| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jan-14 18:47:07 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\sunny\Desktop\imgui-1.92.5\imgui-1.92.5\examples\example_win32_directx11\Release\hope.pdb
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses known Mersenne Twister constants |
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE is possibly a dropper. | Resource 101 detected as a PE Executable. |
| Info | The PE is digitally signed. |
Signer: Ofradr.Inc
Issuer: Ofradr.Inc |
| Malicious | VirusTotal score: 38/72 (Scanned on 2026-01-31 12:02:07) |
ALYac:
Trojan.GenericKD.78371664
AVG: Win64:MalwareX-gen [Trj] AhnLab-V3: Trojan/Win.Agent.C5838517 Antiy-AVL: Trojan/Win32.Sabsik Arcabit: Trojan.Generic.D4ABDB50 Avast: Win64:MalwareX-gen [Trj] BitDefender: Trojan.GenericKD.78371664 Bkav: W64.AIDetectMalware CAT-QuickHeal: Trojan.Ghanarava.17696885544ca6a6 CTX: exe.trojan.generic Cynet: Malicious (score: 99) Elastic: malicious (high confidence) Emsisoft: Trojan.GenericKD.78371664 (B) Fortinet: W32/PossibleThreat GData: Trojan.GenericKD.78371664 Google: Detected Ikarus: Trojan.Win64.Krypt K7AntiVirus: Riskware ( 00584baa1 ) K7GW: Riskware ( 00584baa1 ) Kaspersky: Trojan.Win32.Agent.xcbywh Kingsoft: Win32.Trojan.Agent.xcbywh Lionic: Trojan.Win32.Agent.Y!c Malwarebytes: Malware.AI.1410446724 McAfeeD: ti!FF2D976705B2 MicroWorld-eScan: Trojan.GenericKD.78371664 Microsoft: Trojan:Win32/Wacatac.B!ml Paloalto: generic.ml Sangfor: Trojan.Win32.Agent.Vpse Skyhigh: Artemis!Trojan Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence Tencent: Malware.Win32.Gencirc.11e3c0a7 TrellixENS: Artemis!5FAD59654841 TrendMicro-HouseCall: TROJ_GEN.R002H09AH26 VBA32: Trojan.Agent VIPRE: Trojan.GenericKD.78371664 Varist: W64/ABTrojan.KDPJ-0270 alibabacloud: Trojan:Win/Agent.xzqcvk |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Jan-14 18:47:07 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xe9400 |
| SizeOfInitializedData | 0x84a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000AFB64 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x172000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x173ff0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| D3DCOMPILER_47.dll |
D3DCompile
|
| KERNEL32.dll |
GetModuleFileNameW
WaitForSingleObject GetCurrentThreadId UnmapViewOfFile OpenProcess CreateToolhelp32Snapshot Sleep GetTickCount64 Process32NextW Process32FirstW CloseHandle VirtualAllocEx CreateFileMappingA ExitProcess GetCurrentProcessId CreateProcessW GetModuleHandleW CreateRemoteThread VirtualFreeEx MapViewOfFile GetTickCount GetFileSizeEx GetConsoleOutputCP FlushFileBuffers EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW VirtualProtect FlsFree FlsSetValue FlsGetValue FlsAlloc HeapFree HeapAlloc ReadConsoleW GetConsoleMode GetCurrentProcess SetFilePointerEx WriteFile FreeLibraryAndExitThread ExitThread CreateThread TerminateProcess CreateFileW WriteConsoleW GetModuleHandleExW GetFileType GetStdHandle ReadFile LoadLibraryExW TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount SetLastError GetLastError RaiseException RtlPcToFileHeader RtlUnwindEx WriteProcessMemory QueryPerformanceCounter FreeLibrary GetProcAddress QueryPerformanceFrequency LoadLibraryA GetLocaleInfoA GlobalUnlock WideCharToMultiByte GlobalLock GlobalFree GetCPInfo GetStringTypeW SetEndOfFile GetProcessHeap SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GlobalAlloc MultiByteToWideChar HeapSize RtlUnwind GetCommandLineW GetCommandLineA GetOEMCP GetACP OutputDebugStringW IsValidCodePage FindNextFileW FindFirstFileExW FindClose HeapReAlloc GetTimeZoneInformation SetStdHandle ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent GetSystemTimeAsFileTime InitializeSListHead TryAcquireSRWLockExclusive EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection EncodePointer DecodePointer LCMapStringEx |
| USER32.dll |
ReleaseDC
OpenClipboard ReleaseCapture IsWindowUnicode SetProcessDPIAware CloseClipboard EmptyClipboard GetClipboardData GetCursorPos SetCursorPos SetWindowDisplayAffinity GetClientRect DefWindowProcW PostMessageW MapVirtualKeyW GetWindowRect SetWindowPos CreateWindowExW CallNextHookEx GetSystemMetrics GetClassNameA RegisterClassExW WindowFromPoint GetThreadDesktop ShowWindow GetKeyNameTextA GetAsyncKeyState CloseDesktop DispatchMessageW PeekMessageW SetCursor UnhookWindowsHookEx SetLayeredWindowAttributes OpenInputDesktop TranslateMessage SetWindowsHookExW ToUnicode GetUserObjectInformationW PostQuitMessage PtInRect GetAncestor GetKeyState GetMessageExtraInfo GetDC ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow LoadCursorW SetCapture SetClipboardData |
| GDI32.dll |
DeleteDC
DeleteObject CreateCompatibleDC BitBlt CreateCompatibleBitmap SelectObject |
| ADVAPI32.dll |
OpenProcessToken
LookupPrivilegeValueW AdjustTokenPrivileges |
| SHELL32.dll |
ShellExecuteW
ShellExecuteA |
| ole32.dll |
CoCreateInstance
CoUninitialize CreateStreamOnHGlobal CoInitializeEx |
| OLEAUT32.dll |
SysStringLen
SysFreeString |
| IMM32.dll |
ImmSetCompositionWindow
ImmReleaseContext ImmGetContext ImmSetCandidateWindow |
| WINHTTP.dll |
WinHttpQueryDataAvailable
WinHttpConnect WinHttpSendRequest WinHttpCloseHandle WinHttpOpenRequest WinHttpReadData WinHttpQueryHeaders WinHttpAddRequestHeaders WinHttpOpen WinHttpReceiveResponse WinHttpCrackUrl |
| gdiplus.dll |
GdipBitmapUnlockBits
GdipAlloc GdipCreateBitmapFromHBITMAP GdipGetImageEncoders GdipFree GdipBitmapLockBits GdipSaveImageToStream GdipCloneImage GdiplusShutdown GdiplusStartup GdipDisposeImage GdipGetImageEncodersSize |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-14 18:47:07 |
| Version | 0.0 |
| SizeofData | 123 |
| AddressOfRawData | 0x119f1c |
| PointerToRawData | 0x11871c |
| Referenced File | C:\Users\sunny\Desktop\imgui-1.92.5\imgui-1.92.5\examples\example_win32_directx11\Release\hope.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-14 18:47:07 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x119f98 |
| PointerToRawData | 0x118798 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-14 18:47:07 |
| Version | 0.0 |
| SizeofData | 1052 |
| AddressOfRawData | 0x119fac |
| PointerToRawData | 0x1187ac |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-14 18:47:07 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x14011a410 |
|---|---|
| EndAddressOfRawData | 0x14011a418 |
| AddressOfIndex | 0x1401484a8 |
| AddressOfCallbacks | 0x1400eb8b8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14012c040 |
| XOR Key | 0x7df3f722 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 196 |
| C objects (33145) | 35 |
| ASM objects (33145) | 25 |
| ASM objects (35207) | 10 |
| C objects (35207) | 18 |
| C++ objects (35207) | 93 |
| Imports (33145) | 27 |
| Total imports | 272 |
| C++ objects (LTCG) (35221) | 8 |
| Resource objects (35221) | 1 |
| 151 | 1 |
| Linker (35221) | 1 |