| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Jun-09 19:21:16 |
| Detected languages |
English - Canada
English - United Kingdom English - United States |
| CompanyName | 1nonlywrld |
| FileDescription | Exitlag Loader |
| FileVersion | 1.0.0.1 |
| InternalName | loader.exe |
| LegalCopyright | Copyright (C) 2026 |
| OriginalFilename | loader.exe |
| ProductName | ExitlagLoader |
| ProductVersion | 1.0.0.1 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
Code injection capabilities:
|
| Suspicious | The PE is possibly a dropper. | Resources amount for 85.0583% of the executable. |
| Malicious | VirusTotal score: 8/69 (Scanned on 2026-07-19 03:58:47) |
APEX:
Malicious
Bkav: W32.Malware.1F915A63 CrowdStrike: win/malicious_confidence_60% (D) Elastic: malicious (high confidence) MaxSecure: Trojan.Malware.8328611.susgen Symantec: ML.Attribute.HighConfidence Trapmine: suspicious.low.ml.score TrendMicro-HouseCall: Trojan.Win64.Gen.TL0101FS26YX |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Jun-09 19:21:16 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xb600 |
| SizeOfInitializedData | 0x71200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000000B3D0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x80000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
GetTokenInformation
CryptReleaseContext CheckTokenMembership FreeSid OpenProcessToken AllocateAndInitializeSid CryptGenRandom CryptAcquireContextW |
|---|---|
| KERNEL32.dll |
FillConsoleOutputCharacterA
FindFirstFileW WriteProcessMemory GetConsoleScreenBufferInfo SetConsoleTextAttribute EnterCriticalSection FindNextFileW GetCurrentProcess SetConsoleScreenBufferSize GetStdHandle WriteConsoleA WriteFile RemoveDirectoryW GetModuleFileNameW SetConsoleWindowInfo GetProcessId LeaveCriticalSection InitializeCriticalSection GetEnvironmentVariableW FindClose WaitForSingleObject CreateFileW GetFileAttributesW ReadFile GetModuleHandleA OpenProcess MultiByteToWideChar Sleep GlobalAlloc DeleteFileW CloseHandle CreateThread K32EnumProcesses FillConsoleOutputAttribute GetProcAddress GlobalLock VirtualAllocEx GetFileSize DeleteCriticalSection WideCharToMultiByte GetConsoleWindow CreateRemoteThread QueryFullProcessImageNameW VirtualFreeEx SetConsoleCursorPosition GlobalUnlock RtlLookupFunctionEntry GetModuleHandleW IsDebuggerPresent InitializeSListHead GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter CreateDirectoryW ReadConsoleA IsProcessorFeaturePresent TerminateProcess RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter RtlCaptureContext |
| USER32.dll |
CloseClipboard
EmptyClipboard OpenClipboard ShowWindow SetClipboardData SetForegroundWindow BringWindowToTop |
| COMDLG32.dll |
GetOpenFileNameW
|
| SHELL32.dll |
ShellExecuteExW
|
| MSVCP140.dll |
?_Xlength_error@std@@YAXPEBD@Z
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__std_exception_copy
__current_exception_context __current_exception __std_exception_destroy _CxxThrowException __C_specific_handler memset memcpy memcmp memmove wcsrchr |
| api-ms-win-crt-runtime-l1-1-0.dll |
_cexit
_initialize_onexit_table _register_onexit_function _c_exit terminate _wsystem system __p___argv _invoke_watson _seh_filter_exe _crt_atexit __p___argc _set_app_type _exit exit _initterm_e _initterm _get_initial_narrow_environment _initialize_narrow_environment _configure_narrow_argv _register_thread_local_exe_atexit_callback |
| api-ms-win-crt-string-l1-1-0.dll |
_wcsicmp
strcmp |
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
malloc free _set_new_mode |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
| api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
_set_fmode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.1 |
| ProductVersion | 1.0.0.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - Canada |
| CompanyName | 1nonlywrld |
| FileDescription | Exitlag Loader |
| FileVersion (#2) | 1.0.0.1 |
| InternalName | loader.exe |
| LegalCopyright | Copyright (C) 2026 |
| OriginalFilename | loader.exe |
| ProductName | ExitlagLoader |
| ProductVersion (#2) | 1.0.0.1 |
| Resource LangID | English - United Kingdom |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-09 19:21:16 |
| Version | 0.0 |
| SizeofData | 720 |
| AddressOfRawData | 0x10ce4 |
| PointerToRawData | 0xf6e4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-09 19:21:16 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140013040 |
| XOR Key | 0x65d5bc0a |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 12 |
| ASM objects (35207) | 3 |
| C objects (35207) | 10 |
| C++ objects (35207) | 27 |
| Imports (35207) | 6 |
| Imports (33145) | 11 |
| Total imports | 131 |
| C++ objects (LTCG) (35224) | 1 |
| Resource objects (35224) | 1 |
| 151 | 1 |
| Linker (35224) | 1 |
No comments yet.