| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Mar-11 02:57:57 |
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
voice_2.pdb
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to Blowfish |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 35/71 (Scanned on 2026-08-14 06:03:27) |
ALYac:
Trojan.GenericKD.79762549
AVG: Win64:MalwareX-gen [Misc] Antiy-AVL: Trojan/Win32.Agent Arcabit: Trojan.Generic.D4C11475 Avast: Win64:MalwareX-gen [Misc] Avira: TR/W64.Agent BitDefender: Trojan.GenericKD.79762549 CTX: exe.trojan.wacatac DeepInstinct: MALICIOUS DrWeb: BackDoor.Siggen2.5978 ESET-NOD32: Win64/Agent.IQV trojan Emsisoft: Trojan.GenericKD.79762549 (B) F-Secure: Trojan.TR/W64.Agent Fortinet: W64/Agent.IQV!tr GData: Trojan.GenericKD.79762549 Google: Detected Ikarus: Trojan.Win64.Agent Kaspersky: HEUR:Backdoor.Win32.Generic Lionic: Trojan.Win32.Generic.m!c MaxSecure: Trojan.Malware.324995110.susgen McAfeeD: ti!5FC1251E474E MicroWorld-eScan: Trojan.GenericKD.79762549 Microsoft: Trojan:Win32/Wacatac.B!ml Paloalto: generic.ml Rising: Backdoor.Generic!8.CE (TFE:5:TV9vigrEb1O) Sophos: Mal/Generic-S Symantec: Trojan Horse Tencent: Malware.Win32.Gencirc.14ab3f23 TrellixENS: Artemis!439255736797 TrendMicro: Trojan.Win32.WACATAC.USBLHD26 TrendMicro-HouseCall: Trojan.Win32.WACATAC.USBLHD26 VIPRE: Trojan.GenericKD.79762549 Varist: W64/ABTrojan.PGCS-2812 ViRobot: Trojan.Win.Z.Agent.8958976 alibabacloud: Backdoor:Win/Wacatac.B9nj |
| MD5 | 439255736797bc88bd19f282449e0436 🔍 |
|---|---|
| SHA1 | 724f6ca2ea66dbf117c7eea42c99760716ec75b9 🔍 |
| SHA256 | 5fc1251e474eae9253362a08095e989edc2b63de21d76052a2c849efc6792c3f 🔍 |
| SHA3 | 4a6adf2dd57fe1c079d32b784566df90642e112d5e01723ceae70134eee98eb3 🔍 |
| SSDeep | 98304:mahKD7SG0SRxW7SBaHvxkVgy3ju5LPCV+TRXsZ6:mRgWpgyzu5L2sB 🔍 |
| Imports Hash | 067f5a6aac4512b4a1c18cf8b3e7e2d7 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Mar-11 02:57:57 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x4d4000 |
| SizeOfInitializedData | 0x3b8200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000004B227C (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x88f000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | d19c8a2ebb4d05a14fff055de33ed015 🔍 |
|---|---|
| SHA1 | 5fe1b12b7cff7b0a83f8345b3aedd3c6be7b948c 🔍 |
| SHA256 | 0e37817bd2de7c9a1369f1e467a45c1539e23f64188df891e884e5c5cc896c6b 🔍 |
| SHA3 | c9e86f966702fe4edeebdaecb4819efc42caf402b7a20916b2604ad7df40701b 🔍 |
| VirtualSize | 0x4d3e80 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x4d4000 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.28108 |
| MD5 | 9fd473d9b154df34485eada710f4100b 🔍 |
|---|---|
| SHA1 | 28570fd8ab8e80ecfa2d4e31817fb3f1a98d89ea 🔍 |
| SHA256 | 16358754cea664adec997b7f4dcc785e99af6602488ba3f998a0527c1dce3d05 🔍 |
| SHA3 | 9fb6c72c3f6b5254ecc4856d2fb073267ff3aa4fd64c39e2bd26b60b248a82e2 🔍 |
| VirtualSize | 0x36c846 |
| VirtualAddress | 0x4d5000 |
| SizeOfRawData | 0x36ca00 |
| PointerToRawData | 0x4d4400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.01693 |
| MD5 | ad4357f355a728bb67c482ca36e4f8cd 🔍 |
|---|---|
| SHA1 | 43606a7eb9b10484d4c1a31580bc232b1dc63fad 🔍 |
| SHA256 | 3c4a5dde358482824b78dfd3b125673d84a13cde32a5302f711e4dc75f426324 🔍 |
| SHA3 | 43f02a2ebd491295ceed7e45be8fa43de1178c13c17bc62bfd87141f50c9881b 🔍 |
| VirtualSize | 0x4788 |
| VirtualAddress | 0x842000 |
| SizeOfRawData | 0x3600 |
| PointerToRawData | 0x840e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 2.37964 |
| MD5 | e509247fed5ba2a1b9861b28837bf3d3 🔍 |
|---|---|
| SHA1 | 71874fd868ae8484333cf481f715fb91b84bb040 🔍 |
| SHA256 | 764285af64e29fb773d4d6990fa34d8452d4cc3ddce2f7e51bbdc9575bbcc1c3 🔍 |
| SHA3 | ac980254b0dfd225dc0aab5b106e8103d16abfd5532bb439524abd7f7efec01e 🔍 |
| VirtualSize | 0x39fc0 |
| VirtualAddress | 0x847000 |
| SizeOfRawData | 0x3a000 |
| PointerToRawData | 0x844400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.50715 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x100 |
| VirtualAddress | 0x881000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x87e400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 28a13be1a7fa676eb9a6f1443b371532 🔍 |
|---|---|
| SHA1 | 4003a2427f09126cac2ea73e9ccb17534375bf51 🔍 |
| SHA256 | ed4255a6813336d4735e736f32dff8a5710f645dae46e234bd44bb254045979a 🔍 |
| SHA3 | f63ea21ef70a0638c4383676fdcd3cc6b743f910a449e8b66f397cddf28be045 🔍 |
| VirtualSize | 0xccb4 |
| VirtualAddress | 0x882000 |
| SizeOfRawData | 0xce00 |
| PointerToRawData | 0x87e600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.4673 |
| bcryptprimitives.dll |
ProcessPrng
|
|---|---|
| kernel32.dll |
TlsSetValue
TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount DeleteCriticalSection LeaveCriticalSection EnterCriticalSection EncodePointer RaiseException RtlPcToFileHeader RtlUnwindEx IsProcessorFeaturePresent GetStartupInfoW SetUnhandledExceptionFilter UnhandledExceptionFilter IsDebuggerPresent InitializeSListHead GetSystemTimeAsFileTime HeapFree FindNextFileW RtlLookupFunctionEntry RtlCaptureContext GetProcAddress TerminateProcess LoadLibraryExA FreeLibrary GetProcessHeap IsValidCodePage GetOEMCP QueryPerformanceCounter GetSystemTimePreciseAsFileTime GetCPInfo WriteFileEx CreateProcessW GetWindowsDirectoryW GetLastError GetSystemDirectoryW CompareStringOrdinal FormatMessageW GetStringTypeW FreeEnvironmentStringsW CreateThread Sleep SetWaitableTimer TlsFree GetExitCodeProcess CreateFileW GetCommandLineA HeapAlloc SetStdHandle CreateWaitableTimerExW GetACP GetModuleHandleExW LoadLibraryExW FlsAlloc FlsGetValue FlsSetValue FlsFree GetConsoleOutputCP InitializeCriticalSectionEx VirtualProtect GetModuleHandleW GetStdHandle WriteConsoleW HeapSize GetSystemInfo MultiByteToWideChar GetConsoleMode SetConsoleMode CancelIo QueryPerformanceFrequency SleepEx ReadFileEx WaitForMultipleObjects SetHandleInformation ExitProcess GetModuleFileNameW GetModuleHandleA GetFullPathNameW SetEnvironmentVariableW GetFileType FindClose FindFirstFileExW GetFinalPathNameByHandleW DeleteFileW GetFileInformationByHandle SwitchToThread GetFileInformationByHandleEx SetConsoleCtrlHandler PostQueuedCompletionStatus CreateIoCompletionPort GetQueuedCompletionStatusEx GetOverlappedResult ReadFile WriteFile CreateDirectoryW MoveFileExW SetFileCompletionNotificationModes GetTimeZoneInformationForYear GetCurrentProcessId CreateEventA SetEvent CompareStringW CloseHandle LCMapStringW GetComputerNameExW VirtualQuery RtlVirtualUnwind GetCurrentThreadId SetThreadPriority WaitForMultipleObjectsEx GetCommandLineW GetEnvironmentVariableW GetEnvironmentStringsW CreateEventW WaitForSingleObject GetCurrentDirectoryW SetLastError GetCurrentThread SetThreadStackGuarantee AddVectoredExceptionHandler DuplicateHandle FlushFileBuffers GetFileAttributesW SetFileInformationByHandle HeapReAlloc lstrlenW GetCurrentProcess WideCharToMultiByte WaitForSingleObjectEx LoadLibraryA CreateMutexA ReleaseMutex SetFilePointerEx |
| api-ms-win-core-synch-l1-2-0.dll |
WakeByAddressSingle
WaitOnAddress WakeByAddressAll |
| ws2_32.dll |
getaddrinfo
freeaddrinfo shutdown bind WSASocketW WSAIoctl WSAStartup WSACleanup recv connect WSASend send getsockname getpeername getsockopt setsockopt WSAGetLastError closesocket ioctlsocket |
| secur32.dll |
EncryptMessage
ApplyControlToken DecryptMessage FreeContextBuffer InitializeSecurityContextW FreeCredentialsHandle AcquireCredentialsHandleA DeleteSecurityContext QueryContextAttributesW AcceptSecurityContext |
| advapi32.dll |
SetServiceStatus
RegisterServiceCtrlHandlerExW StartServiceCtrlDispatcherW SystemFunction036 RegCloseKey RegOpenKeyExW RegQueryValueExW RegOpenKeyTransactedW RegCreateKeyExW RegCreateKeyTransactedW |
| ntdll.dll |
NtReadFile
NtOpenFile NtCreateNamedPipeFile NtDeviceIoControlFile RtlNtStatusToDosError NtCancelIoFileEx NtCreateFile NtWriteFile |
| ole32.dll |
CoCreateInstance
CoTaskMemFree PropVariantClear CoUninitialize CoInitializeEx |
| oleaut32.dll |
SysStringLen
GetErrorInfo SysFreeString |
| crypt32.dll |
CertAddCertificateContextToStore
CertOpenStore CertEnumCertificatesInStore CertFreeCertificateChain CertDuplicateCertificateChain CertCloseStore CertDuplicateStore CertFreeCertificateContext CertDuplicateCertificateContext CertVerifyCertificateChainPolicy CertGetCertificateChain |
| bcrypt.dll |
BCryptGenRandom
|
| libmp3lame.DLL (delay-loaded) |
#139
#22 #6 #41 #4 #1 #148 #164 |
| Attributes | 0x1 |
|---|---|
| Name | libmp3lame.DLL |
| ModuleHandle | 0x846740 |
| DelayImportAddressTable | 0x8454e0 |
| DelayImportNameTable | 0x83fcf0 |
| BoundDelayImportTable | 0x83fd38 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-11 02:57:57 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0x77a444 |
| PointerToRawData | 0x779844 |
| Referenced File | voice_2.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-11 02:57:57 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x77a468 |
| PointerToRawData | 0x779868 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-11 02:57:57 |
| Version | 0.0 |
| SizeofData | 1072 |
| AddressOfRawData | 0x77a47c |
| PointerToRawData | 0x77987c |
| StartAddressOfRawData | 0x14077a8f8 |
|---|---|
| EndAddressOfRawData | 0x14077aac0 |
| AddressOfIndex | 0x1408456a8 |
| AddressOfCallbacks | 0x1404d5758 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x000000014046E5C0
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140844a40 |
| XOR Key | 0x9906a2de |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 142 |
| C objects (33145) | 18 |
| ASM objects (33145) | 11 |
| ASM objects (35207) | 9 |
| C objects (35207) | 16 |
| C objects (35222) | 12 |
| C++ objects (35207) | 45 |
| Total imports | 393 |
| Unmarked objects (#2) | 632 |
| Linker (35222) | 1 |
No comments yet.