| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-May-19 04:56:59 |
| TLS Callbacks | 3 callback(s) detected. |
| Suspicious | PEiD Signature: | HQR data file |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to RC5 or RC6 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .xdata |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 9 |
| TimeDateStamp | 2026-May-19 04:56:59 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x396e00 |
| SizeOfInitializedData | 0x676200 |
| SizeOfUninitializedData | 0x400 |
| AddressOfEntryPoint | 0x0000000000001440 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xa12000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xa16ac8 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| advapi32.dll |
SystemFunction036
|
|---|---|
| bcrypt.dll |
BCryptGenRandom
|
| d3dcompiler_47.dll |
D3DCompile
|
| dwmapi.dll |
DwmEnableBlurBehindWindow
|
| gdi32.dll |
CreateRectRgn
DeleteObject GetDeviceCaps StretchDIBits |
| imm32.dll |
ImmAssociateContextEx
ImmGetCompositionStringW ImmGetContext ImmReleaseContext |
| kernel32.dll |
AddVectoredExceptionHandler
CancelIo CompareStringOrdinal CreateEventA CreateEventW CreateFileMappingW CreateFileW CreateProcessW CreateThread CreateWaitableTimerExW FormatMessageW FreeEnvironmentStringsW GetCurrentDirectoryW GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetModuleHandleW GetOverlappedResult GetProcessHeap GetProcessId GetUserPreferredUILanguages GlobalAlloc GlobalLock GlobalSize GlobalUnlock HeapAlloc HeapFree HeapReAlloc InitOnceBeginInitialize InitOnceComplete MultiByteToWideChar QueryPerformanceCounter QueryPerformanceFrequency ReadFile ReadFileEx RemoveVectoredExceptionHandler SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread TlsAlloc TlsFree TlsGetValue TlsSetValue VirtualProtect WaitForMultipleObjects WaitForSingleObject WriteFileEx |
| ntdll.dll |
NtOpenFile
NtReadFile NtWriteFile |
| ole32.dll |
CoCreateInstance
CoInitializeEx CoUninitialize OleInitialize RegisterDragDrop RevokeDragDrop |
| oleaut32.dll |
GetErrorInfo
|
| shell32.dll |
DragFinish
DragQueryFileW |
| user32.dll |
AdjustWindowRectEx
ChangeDisplaySettingsExW ClientToScreen ClipCursor CloseClipboard CloseTouchInputHandle CreateIcon CreateWindowExW DefWindowProcW DestroyIcon DestroyWindow DispatchMessageW EmptyClipboard EnableMenuItem FlashWindowEx GetActiveWindow GetClientRect GetClipCursor GetClipboardData GetCursorPos GetDC GetForegroundWindow GetKeyState GetKeyboardLayout GetKeyboardState GetMenu GetMessageW GetMonitorInfoW GetRawInputData GetSystemMenu GetSystemMetrics GetTouchInputInfo GetUpdateRect GetWindowLongPtrW GetWindowLongW GetWindowPlacement GetWindowRect InvalidateRgn IsIconic IsProcessDPIAware IsWindowVisible LoadCursorW MapVirtualKeyA MapVirtualKeyW MonitorFromPoint MonitorFromRect MonitorFromWindow MsgWaitForMultipleObjectsEx OpenClipboard PeekMessageW PostMessageW PostThreadMessageW RedrawWindow RegisterClassExW RegisterRawInputDevices RegisterTouchWindow RegisterWindowMessageA ReleaseCapture ScreenToClient SendInput SendMessageW SetCapture SetClipboardData SetCursor SetForegroundWindow SetWindowDisplayAffinity SetWindowLongPtrW SetWindowLongW SetWindowPlacement SetWindowPos SetWindowTextW ShowCursor ShowWindow SystemParametersInfoA ToUnicodeEx TrackMouseEvent TranslateMessage ValidateRect |
| uxtheme.dll |
SetWindowTheme
|
| winmm.dll |
timeBeginPeriod
timeEndPeriod timeGetDevCaps |
| kernel32.dll (#2) |
AddVectoredExceptionHandler
CancelIo CompareStringOrdinal CreateEventA CreateEventW CreateFileMappingW CreateFileW CreateProcessW CreateThread CreateWaitableTimerExW FormatMessageW FreeEnvironmentStringsW GetCurrentDirectoryW GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetModuleHandleW GetOverlappedResult GetProcessHeap GetProcessId GetUserPreferredUILanguages GlobalAlloc GlobalLock GlobalSize GlobalUnlock HeapAlloc HeapFree HeapReAlloc InitOnceBeginInitialize InitOnceComplete MultiByteToWideChar QueryPerformanceCounter QueryPerformanceFrequency ReadFile ReadFileEx RemoveVectoredExceptionHandler SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread TlsAlloc TlsFree TlsGetValue TlsSetValue VirtualProtect WaitForMultipleObjects WaitForSingleObject WriteFileEx |
| kernel32.dll (#3) |
AddVectoredExceptionHandler
CancelIo CompareStringOrdinal CreateEventA CreateEventW CreateFileMappingW CreateFileW CreateProcessW CreateThread CreateWaitableTimerExW FormatMessageW FreeEnvironmentStringsW GetCurrentDirectoryW GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetModuleHandleW GetOverlappedResult GetProcessHeap GetProcessId GetUserPreferredUILanguages GlobalAlloc GlobalLock GlobalSize GlobalUnlock HeapAlloc HeapFree HeapReAlloc InitOnceBeginInitialize InitOnceComplete MultiByteToWideChar QueryPerformanceCounter QueryPerformanceFrequency ReadFile ReadFileEx RemoveVectoredExceptionHandler SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread TlsAlloc TlsFree TlsGetValue TlsSetValue VirtualProtect WaitForMultipleObjects WaitForSingleObject WriteFileEx |
| kernel32.dll (#4) |
AddVectoredExceptionHandler
CancelIo CompareStringOrdinal CreateEventA CreateEventW CreateFileMappingW CreateFileW CreateProcessW CreateThread CreateWaitableTimerExW FormatMessageW FreeEnvironmentStringsW GetCurrentDirectoryW GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetModuleHandleW GetOverlappedResult GetProcessHeap GetProcessId GetUserPreferredUILanguages GlobalAlloc GlobalLock GlobalSize GlobalUnlock HeapAlloc HeapFree HeapReAlloc InitOnceBeginInitialize InitOnceComplete MultiByteToWideChar QueryPerformanceCounter QueryPerformanceFrequency ReadFile ReadFileEx RemoveVectoredExceptionHandler SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread TlsAlloc TlsFree TlsGetValue TlsSetValue VirtualProtect WaitForMultipleObjects WaitForSingleObject WriteFileEx |
| api-ms-win-core-synch-l1-2-0.dll |
WaitOnAddress
WakeByAddressAll WakeByAddressSingle |
| bcryptprimitives.dll |
ProcessPrng
|
| kernel32.dll (#5) |
AddVectoredExceptionHandler
CancelIo CompareStringOrdinal CreateEventA CreateEventW CreateFileMappingW CreateFileW CreateProcessW CreateThread CreateWaitableTimerExW FormatMessageW FreeEnvironmentStringsW GetCurrentDirectoryW GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetModuleHandleW GetOverlappedResult GetProcessHeap GetProcessId GetUserPreferredUILanguages GlobalAlloc GlobalLock GlobalSize GlobalUnlock HeapAlloc HeapFree HeapReAlloc InitOnceBeginInitialize InitOnceComplete MultiByteToWideChar QueryPerformanceCounter QueryPerformanceFrequency ReadFile ReadFileEx RemoveVectoredExceptionHandler SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread TlsAlloc TlsFree TlsGetValue TlsSetValue VirtualProtect WaitForMultipleObjects WaitForSingleObject WriteFileEx |
| ntdll.dll (#2) |
NtOpenFile
NtReadFile NtWriteFile |
| oleaut32.dll (#2) |
GetErrorInfo
|
| KERNEL32.dll |
DeleteCriticalSection
EnterCriticalSection InitializeCriticalSection LeaveCriticalSection RaiseException RtlUnwindEx VirtualQuery __C_specific_handler |
| msvcrt.dll |
__getmainargs
__initenv __iob_func __set_app_type __setusermatherr _amsg_exit _cexit _commode _errno _fmode _fpreset _hypot _initterm abort acos atexit calloc exit fflush fprintf free ldexp malloc memcmp memcpy memmove memset setvbuf signal strerror strlen strncmp tan vfprintf |
| ntdll.dll (#3) |
NtOpenFile
NtReadFile NtWriteFile |
| StartAddressOfRawData | 0x140a0b000 |
|---|---|
| EndAddressOfRawData | 0x140a0b008 |
| AddressOfIndex | 0x140a0719c |
| AddressOfCallbacks | 0x1409b1af0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x000000014015DAE0
0x0000000140396BE0 0x0000000140396BC0 |
No comments yet.