| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Mar-20 08:11:30 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
app.pdb
|
| CompanyName | ReideN Development |
| FileDescription | ReideN |
| FileVersion | 3.2.0 |
| LegalCopyright | Copyright © 2026 ReideN Development |
| ProductName | ReideN |
| ProductVersion | 3.2.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for VMWare presence:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to RC5 or RC6 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: ReideN Development
Issuer: ReideN Development |
| Suspicious | VirusTotal score: 1/66 (Scanned on 2026-04-18 04:32:57) | Trapmine: suspicious.low.ml.score |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Mar-20 08:11:30 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xdb5a00 |
| SizeOfInitializedData | 0x746a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000D7F978 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x14ff000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x1502b9c |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
GetSystemTimePreciseAsFileTime
LoadLibraryExA CreateProcessW GetWindowsDirectoryW GetSystemDirectoryW CompareStringOrdinal FreeEnvironmentStringsW CreateThread SetWaitableTimer GetProcessId CreateWaitableTimerExW lstrlenW LoadLibraryA LoadLibraryW GetConsoleOutputCP GetStdHandle TerminateProcess WriteConsoleW RtlCaptureContext MultiByteToWideChar CancelIo QueryPerformanceFrequency SleepEx ReadFileEx RtlLookupFunctionEntry FindNextFileW SetHandleInformation FormatMessageW WaitForMultipleObjects ExitProcess GetTempPathW GetFullPathNameW SetEnvironmentVariableW FindClose FindFirstFileExW GetFinalPathNameByHandleW DeleteFileW CreateEventW SwitchToThread GetFileInformationByHandleEx CreateDirectoryW MoveFileExW CopyFileExW RemoveDirectoryW GetCommandLineW GetEnvironmentStringsW GetCurrentDirectoryW SetLastError GetCurrentThread SetThreadStackGuarantee AddVectoredExceptionHandler SetFileInformationByHandle LocalFree IsWow64Process SetFilePointerEx ReleaseMutex CreateMutexA WaitForSingleObjectEx WideCharToMultiByte HeapReAlloc CreatePipe WaitForSingleObject GetEnvironmentVariableW TlsFree UnhandledExceptionFilter GetLastError SetUnhandledExceptionFilter DuplicateHandle InitializeSListHead RtlUnwindEx CreateIoCompletionPort SetFileCompletionNotificationModes RtlPcToFileHeader RaiseException GetOverlappedResult PostQueuedCompletionStatus ReadFile WriteFile CancelIoEx SetNamedPipeHandleState GetQueuedCompletionStatusEx CreateFileW GetCurrentThreadId GetFileAttributesW GetModuleFileNameW LoadLibraryExW LCIDToLocaleName FreeLibrary GetFileInformationByHandle GetConsoleMode GetComputerNameExW QueryPerformanceCounter GetUserDefaultUILanguage IsProcessorFeaturePresent ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW GetModuleHandleW GetSystemTimeAsFileTime GetCurrentProcess DeviceIoControl IsDebuggerPresent CheckRemoteDebuggerPresent VirtualQueryEx InitializeCriticalSectionAndSpinCount ReadProcessMemory TlsAlloc RtlVirtualUnwind DeleteCriticalSection GetModuleHandleA HeapFree Sleep GetProcessIoCounters GetSystemTimes GetProcessTimes OpenProcess GetExitCodeProcess GetProcAddress TlsGetValue Process32NextW Process32FirstW CreateToolhelp32Snapshot EncodePointer HeapAlloc GetProcessHeap OutputDebugStringA OutputDebugStringW TlsSetValue WriteFileEx GetSystemInfo CloseHandle K32GetPerformanceInfo GlobalMemoryStatusEx GetCurrentProcessId |
|---|---|
| advapi32.dll |
RegOpenKeyExW
RegQueryValueExW IsValidSid RegOpenKeyTransactedW CopySid OpenProcessToken RegCloseKey GetTokenInformation RegGetValueW RegCreateKeyExW RegCreateKeyTransactedW GetLengthSid EventRegister EventSetInformation EventWriteTransfer EventUnregister SystemFunction036 |
| oleaut32.dll |
SysFreeString
SysStringLen GetErrorInfo SetErrorInfo |
| bcryptprimitives.dll |
ProcessPrng
|
| ntdll.dll |
NtCreateNamedPipeFile
NtReadFile NtOpenFile NtWriteFile NtCreateFile RtlNtStatusToDosError NtQueryInformationProcess NtDeviceIoControlFile NtCancelIoFileEx RtlGetVersion |
| user32.dll |
OffsetRect
GetMenuBarInfo DrawMenuBar SetMenu GetMenuItemInfoW SetCapture CreateIcon SetWindowLongW EnableMenuItem GetSystemMenu SystemParametersInfoA SetPropW GetMenu ShowCursor ReleaseCapture RegisterRawInputDevices SendInput GetRawInputData ClipCursor GetClipCursor IsWindowVisible GetWindowDC EnumDisplayMonitors MonitorFromPoint SetWindowTextW GetWindowTextW GetWindowTextLengthW SetWindowDisplayAffinity SetForegroundWindow CreateAcceleratorTableW SetFocus PostQuitMessage TrackPopupMenu RegisterWindowMessageA GetKeyState SetParent MapWindowPoints GetWindow ShowWindow ReleaseDC GetWindowRect SetWindowLongPtrW GetParent InsertMenuW GetWindowLongPtrW AppendMenuW SetMenuItemInfoW FindWindowExW SetWindowRgn CreateMenu IsProcessDPIAware GetDC CreatePopupMenu ToUnicodeEx DestroyWindow TranslateAcceleratorW GetKeyboardLayout RegisterClassExW CreateWindowExW SetWindowPos GetMessageA TranslateMessage DispatchMessageA EnumChildWindows MsgWaitForMultipleObjectsEx PostMessageW AdjustWindowRect RedrawWindow SendMessageW IsIconic GetMessageW MapVirtualKeyExW DispatchMessageW PeekMessageW PostThreadMessageW DefWindowProcW ScreenToClient GetWindowLongW RemoveMenu CheckMenuItem DrawIconEx DestroyMenu GetKeyboardState EnableWindow IsWindowEnabled GetActiveWindow MapVirtualKeyW CloseTouchInputHandle GetTouchInputInfo GetAsyncKeyState TrackMouseEvent GetClientRect DestroyAcceleratorTable DestroyIcon GetForegroundWindow IsWindow AdjustWindowRectEx FlashWindowEx UpdateWindow InvalidateRect SetCursorPos DrawTextW LoadCursorW InvalidateRgn GetWindowPlacement SetWindowPlacement ChangeDisplaySettingsExW GetUpdateRect ValidateRect GetMonitorInfoW MonitorFromWindow GetCursorPos SetCursor GetSystemMetrics SystemParametersInfoW FillRect MonitorFromRect ClientToScreen RegisterTouchWindow |
| api-ms-win-core-synch-l1-2-0.dll |
WakeByAddressAll
WakeByAddressSingle WaitOnAddress |
| ole32.dll |
CoCreateFreeThreadedMarshaler
CoInitializeEx CoInitialize RegisterDragDrop OleInitialize RevokeDragDrop CoUninitialize CoCreateInstance |
| comctl32.dll |
SetWindowSubclass
DefSubclassProc RemoveWindowSubclass TaskDialogIndirect |
| shlwapi.dll |
SHCreateMemStream
|
| gdi32.dll |
SetBkMode
CreateCompatibleDC GetDeviceCaps CreateDIBSection SelectObject DeleteObject CreateSolidBrush CreateRectRgn DeleteDC BitBlt CombineRgn SetTextColor |
| combase.dll |
CoTaskMemFree
CoTaskMemAlloc |
| shell32.dll |
ShellExecuteW
ShellExecuteExW SHCreateItemFromParsingName SHGetKnownFolderPath CommandLineToArgvW DragQueryFileW DragFinish SHAppBarMessage |
| ws2_32.dll |
getsockname
getpeername send WSASend getsockopt setsockopt ioctlsocket connect WSAIoctl WSASocketW bind shutdown WSACleanup WSAStartup freeaddrinfo getaddrinfo recv WSAGetLastError closesocket |
| secur32.dll |
DecryptMessage
EncryptMessage AcquireCredentialsHandleA ApplyControlToken AcceptSecurityContext FreeContextBuffer InitializeSecurityContextW DeleteSecurityContext QueryContextAttributesW FreeCredentialsHandle |
| crypt32.dll |
CertGetCertificateChain
CertVerifyCertificateChainPolicy CertDuplicateCertificateChain CertFreeCertificateChain CertDuplicateCertificateContext CertCloseStore CertFreeCertificateContext CertDuplicateStore CertAddCertificateContextToStore CertEnumCertificatesInStore CertOpenStore |
| dwmapi.dll |
DwmSetWindowAttribute
DwmGetWindowAttribute DwmEnableBlurBehindWindow |
| pdh.dll |
PdhGetFormattedCounterValue
PdhOpenQueryA PdhAddEnglishCounterW PdhRemoveCounter PdhCloseQuery PdhEnumObjectsA PdhCollectQueryData |
| powrprof.dll |
CallNtPowerInformation
|
| psapi.dll |
GetProcessMemoryInfo
GetModuleFileNameExW |
| SHELL32.dll |
SHOpenFolderAndSelectItems
#190 #155 |
| bcrypt.dll |
BCryptGenRandom
|
| api-ms-win-crt-math-l1-1-0.dll |
roundf
trunc round pow floor __setusermatherr |
| api-ms-win-crt-string-l1-1-0.dll |
strcmp
wcsncmp wcslen wcscmp strlen strcpy_s _wcsicmp |
| api-ms-win-crt-runtime-l1-1-0.dll |
_set_app_type
_configure_narrow_argv _initialize_narrow_environment _get_initial_narrow_environment _initterm abort _initterm_e terminate exit _wassert _crt_atexit _register_onexit_function _initialize_onexit_table _exit _seh_filter_exe __p___argc _register_thread_local_exe_atexit_callback _c_exit _cexit __p___argv |
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
_callnewh _set_new_mode free calloc |
| api-ms-win-crt-convert-l1-1-0.dll |
_wtoi
wcstol _ultow_s |
| api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
_set_fmode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 3.2.0.0 |
| ProductVersion | 3.2.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | ReideN Development |
| FileDescription | ReideN |
| FileVersion (#2) | 3.2.0 |
| LegalCopyright | Copyright © 2026 ReideN Development |
| ProductName | ReideN |
| ProductVersion (#2) | 3.2.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-20 08:11:30 |
| Version | 0.0 |
| SizeofData | 32 |
| AddressOfRawData | 0x1133374 |
| PointerToRawData | 0x1132174 |
| Referenced File | app.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-20 08:11:30 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x1133394 |
| PointerToRawData | 0x1132194 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-20 08:11:30 |
| Version | 0.0 |
| SizeofData | 1048 |
| AddressOfRawData | 0x11333a8 |
| PointerToRawData | 0x11321a8 |
| StartAddressOfRawData | 0x141133808 |
|---|---|
| EndAddressOfRawData | 0x141133a1c |
| AddressOfIndex | 0x141415c38 |
| AddressOfCallbacks | 0x140db7eb8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x0000000140CD7720
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1414136c0 |
| XOR Key | 0xe088faf6 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 14 |
| ASM objects (35207) | 9 |
| C objects (35207) | 13 |
| C++ objects (35207) | 47 |
| Imports (30151) | 4 |
| Imports (33145) | 3 |
| C objects (35217) | 96 |
| Total imports | 578 |
| Unmarked objects (#2) | 963 |
| Resource objects (35217) | 1 |
| Linker (35217) | 1 |
No comments yet.