| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2023-Jul-31 12:08:33 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| FileVersion | 0.1.0 |
| FileDescription | badapple |
| CompanyName | https://github.com/mon |
| ProductVersion | 0.1.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 10/72 (Scanned on 2026-02-14 23:26:36) |
APEX:
Malicious
AhnLab-V3: Trojan/Win.Joke.C5600458 Alibaba: RiskWare:Win64/BadJoke.a0014e4d Kaspersky: Hoax.Win64.BadJoke.aj MaxSecure: Trojan.Malware.232980218.susgen McAfeeD: ti!6927CB724565 Paloalto: generic.ml Rising: Trojan.Generic!8.C3 (KTSE) TrellixENS: Artemis!6A022E937A77 huorong: Joke/CrazyScreen.af |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2023-Jul-31 12:08:33 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x70c00 |
| SizeOfInitializedData | 0x4e3200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000006E080 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x557000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
ReleaseSRWLockShared
RtlCaptureContext ReleaseMutex FreeLibrary GetCurrentProcess CreateMutexA LoadLibraryA CreateThread AcquireSRWLockShared IsProcessorFeaturePresent WaitForSingleObjectEx SetLastError GetCurrentDirectoryW WriteConsoleW MultiByteToWideChar GetConsoleMode QueryPerformanceFrequency TryAcquireSRWLockExclusive GetCurrentThread GetProcAddress FormatMessageW WaitForMultipleObjectsEx WaitForSingleObject SetEvent CreateEventA ReleaseSRWLockExclusive SwitchToThread AcquireSRWLockExclusive GetModuleHandleW HeapReAlloc HeapFree GetProcessHeap HeapAlloc SetThreadStackGuarantee AddVectoredExceptionHandler GetLastError GetStdHandle GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead RtlVirtualUnwind CloseHandle QueryPerformanceCounter IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetEnvironmentVariableW GetModuleHandleA AttachConsole RtlLookupFunctionEntry Sleep |
|---|---|
| user32.dll |
EndDeferWindowPos
DeferWindowPos BeginDeferWindowPos DispatchMessageA DefWindowProcA PeekMessageA SetTimer SystemParametersInfoA CreateWindowExA RegisterClassA LoadIconW TranslateMessage |
| gdi32.dll |
CreateSolidBrush
|
| ole32.dll |
CoCreateInstance
CoTaskMemFree PropVariantClear CoUninitialize CoInitializeEx |
| ntdll.dll |
NtWriteFile
RtlNtStatusToDosError |
| advapi32.dll |
SystemFunction036
|
| bcrypt.dll |
BCryptGenRandom
|
| oleaut32.dll |
GetErrorInfo
SysFreeString SysStringLen |
| VCRUNTIME140.dll |
memcmp
__current_exception_context memcpy memset memmove __CxxFrameHandler3 __C_specific_handler __current_exception |
| api-ms-win-crt-math-l1-1-0.dll |
powf
expf floorf sin floor atan cos log2 cosf log10 pow round __setusermatherr exp2 |
| api-ms-win-crt-runtime-l1-1-0.dll |
_set_app_type
_seh_filter_exe _configure_narrow_argv _initialize_narrow_environment _get_initial_narrow_environment _initterm _initterm_e exit _exit __p___argc _crt_atexit _register_thread_local_exe_atexit_callback __p___argv terminate _initialize_onexit_table _register_onexit_function _c_exit _cexit |
| api-ms-win-crt-stdio-l1-1-0.dll |
_set_fmode
__p__commode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-heap-l1-1-0.dll |
free
_set_new_mode |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.1.0.0 |
| ProductVersion | 0.1.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| FileVersion (#2) | 0.1.0 |
| FileDescription | badapple |
| CompanyName | https://github.com/mon |
| ProductVersion (#2) | 0.1.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Jul-31 12:08:33 |
| Version | 0.0 |
| SizeofData | 876 |
| AddressOfRawData | 0x4b6734 |
| PointerToRawData | 0x4b5734 |
| StartAddressOfRawData | 0x1404b6ac0 |
|---|---|
| EndAddressOfRawData | 0x1404b6b78 |
| AddressOfIndex | 0x14053b314 |
| AddressOfCallbacks | 0x1400724b0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x0000000140038930
|
| Size | 0x138 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1404bb0b0 |
| XOR Key | 0x2f481678 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 10 |
| Imports (30034) | 2 |
| C++ objects (30034) | 22 |
| C objects (30034) | 9 |
| ASM objects (30034) | 3 |
| Total imports | 127 |
| Imports (30148) | 17 |
| Unmarked objects (#2) | 6 |
| Resource objects (30151) | 1 |
| Linker (30151) | 1 |