| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jul-27 05:01:32 |
| Detected languages |
English - United States
|
| CompanyName | Microsoft Corporation |
| FileDescription | Windows Executable |
| FileVersion | 10.0.19041.1 |
| InternalName | WinExec |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | WinExec.exe |
| ProductName | Microsoft Windows Operating System |
| ProductVersion | 10.0.19041.1 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
| Malicious | The file headers were tampered with. |
Unusual section name found: 6MQQ4
Unusual section name found: To36E Unusual section name found: dTH2eW6 Unusual section name found: IjOWm Unusual section name found: l1GgZADk Unusual section name found: SrxW Unusual section name found: HqZWPd The RICH header checksum is invalid. |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 20/69 (Scanned on 2026-07-27 09:09:20) |
ALYac:
Gen:Variant.Yogi.25083
APEX: Malicious Arcabit: Trojan.Yogi.D61FB BitDefender: Gen:Variant.Yogi.25083 Bkav: W32.Malware.C861BE3C CTX: exe.unknown.yogi CrowdStrike: win/malicious_confidence_90% (D) Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Yogi.25083 (B) GData: Gen:Variant.Yogi.25083 Kaspersky: VHO:Trojan-PSW.Win32.Stealer.gen Malwarebytes: Malware.AI.4109038465 MicroWorld-eScan: Gen:Variant.Yogi.25083 Microsoft: Trojan:Win32/Wacatac.C!ml Sangfor: Virus.Win32.Save.a SentinelOne: Static AI - Suspicious PE Sophos: Generic ML PUA (PUA) Symantec: ML.Attribute.HighConfidence Trapmine: suspicious.low.ml.score VIPRE: Gen:Variant.Yogi.25083 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x72ee |
| e_minalloc | 0x5506 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Jul-27 05:01:32 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x13c600 |
| SizeOfInitializedData | 0x53a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000011C150 (Section: 6MQQ4) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x196000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| USER32.dll |
GetSystemMetrics
EnumDisplaySettingsA CloseClipboard OpenClipboard ShowWindow EnumDisplayDevicesA GetClipboardData |
|---|---|
| KERNEL32.dll |
SetEnvironmentVariableW
FreeEnvironmentStringsW ReadFile GetModuleFileNameA GetLogicalDrives GetFileSizeEx Process32First FindFirstFileA GetCurrentProcess WriteFile FindNextFileA ExpandEnvironmentStringsA lstrlenA GetEnvironmentVariableA FindClose GetVolumeInformationA GetFileAttributesW lstrcatA GetModuleHandleA GetLocaleInfoA CreateToolhelp32Snapshot MultiByteToWideChar Sleep GetTempPathA GetDiskFreeSpaceA CopyFileA GetLastError GetFileAttributesA CreateFileA LoadLibraryA DeleteFileA Process32Next lstrcpyA CloseHandle FreeConsole GetSystemInfo GetProcAddress GlobalLock LocalFree ExitProcess GlobalMemoryStatusEx FreeLibrary WideCharToMultiByte GetConsoleWindow GetEnvironmentStrings GetTempFileNameA GetTickCount GlobalUnlock FreeEnvironmentStringsA IsDebuggerPresent GetComputerNameA AreFileApisANSI TryEnterCriticalSection GetStringTypeW EnterCriticalSection GetFullPathNameW GetDiskFreeSpaceW OutputDebugStringA LockFile LeaveCriticalSection InitializeCriticalSection SetFilePointer GetFullPathNameA SetEndOfFile UnlockFileEx GetTempPathW CreateMutexW WaitForSingleObject CreateFileW GetCurrentThreadId UnmapViewOfFile HeapValidate HeapSize FormatMessageW GetFileAttributesExW OutputDebugStringW FlushViewOfFile WaitForSingleObjectEx DeleteFileW HeapReAlloc RaiseException LoadLibraryW HeapAlloc HeapCompact HeapDestroy UnlockFile GetFileSize DeleteCriticalSection GetCurrentProcessId GetProcessHeap SystemTimeToFileTime GetSystemTimeAsFileTime GetSystemTime FormatMessageA CreateFileMappingW MapViewOfFile QueryPerformanceCounter FlushFileBuffers GetEnvironmentStringsW GetConsoleOutputCP WriteConsoleW GetCommandLineW GetCommandLineA GetCPInfo GetOEMCP HeapCreate SetStdHandle GetACP IsValidCodePage FindNextFileW FindFirstFileExW HeapFree LockFileEx SetUnhandledExceptionFilter GetStartupInfoW GetModuleHandleW InitializeSListHead RtlUnwindEx RtlPcToFileHeader SetLastError FlsAlloc FlsGetValue FlsSetValue FlsFree InitializeCriticalSectionEx RtlLookupFunctionEntry EncodePointer DuplicateHandle CreateProcessW CreateThread ExitThread FreeLibraryAndExitThread GetModuleHandleExW TerminateProcess GetModuleFileNameW GetStdHandle IsProcessorFeaturePresent RtlCaptureContext RtlVirtualUnwind UnhandledExceptionFilter SetFilePointerEx GetConsoleMode ReadConsoleW GetFileType GetExitCodeProcess CreatePipe VirtualProtect LoadLibraryExW CompareStringW LCMapStringW GetTimeZoneInformation |
| ADVAPI32.dll |
GetUserNameA
|
| WS2_32.dll |
freeaddrinfo
inet_ntop getaddrinfo |
| IPHLPAPI.DLL |
GetAdaptersInfo
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 10.0.19041.1 |
| ProductVersion | 10.0.19041.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Windows Executable |
| FileVersion (#2) | 10.0.19041.1 |
| InternalName | WinExec |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | WinExec.exe |
| ProductName | Microsoft Windows Operating System |
| ProductVersion (#2) | 10.0.19041.1 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-27 05:01:32 |
| Version | 0.0 |
| SizeofData | 900 |
| AddressOfRawData | 0x15c060 |
| PointerToRawData | 0x15aa60 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14016d040 |
| XOR Key | 0x9eda397a |
|---|---|
| Unmarked objects | 0 |
| C++ objects (35222) | 179 |
| C objects (35222) | 14 |
| ASM objects (35222) | 10 |
| ASM objects (35721) | 10 |
| C objects (35721) | 17 |
| C++ objects (35721) | 44 |
| Imports (35222) | 17 |
| Total imports | 179 |
| C++ objects (LTCG) (36248) | 2 |
| Resource objects (36248) | 1 |
| Linker (36248) | 1 |
No comments yet.