7f62ddc035e0b408bbdf46920772feaaa06e65662b67b000da0875bba0949d84

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Apr-15 08:08:59
Detected languages English - United States
Debug artifacts E:\randomm\Noxybpp\NOXYBP\x64\Release\NOXPBPV2.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Interesting strings found in the binary: Contains domain names:
  • https://discord.gg
Suspicious The PE contains functions most legitimate programs don't use. Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Possibly launches other programs:
  • ShellExecuteA
  • system
Manipulates other processes:
  • Process32NextW
  • Process32FirstW
Malicious VirusTotal score: 40/70 (Scanned on 2026-09-20 14:51:20) ALYac: Gen:Variant.Tedy.943827
APEX: Malicious
AVG: Win64:MalwareX-gen [Misc]
AhnLab-V3: Trojan/Win.Generic.C5879138
Alibaba: Trojan:Win64/MalwareX.51583d4e
Antiy-AVL: Trojan/Win64.Agent
Arcabit: Trojan.Tedy.DE66D3
Avast: Win64:MalwareX-gen [Misc]
Avira: TR/W64.Agent
BitDefender: Gen:Variant.Tedy.943827
CTX: exe.trojan.agen
CrowdStrike: win/malicious_confidence_60% (D)
Cylance: Unsafe
DeepInstinct: MALICIOUS
DrWeb: Trojan.Siggen32.39675
ESET-NOD32: Win64/Agent_AGen.MOR trojan
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Tedy.943827 (B)
F-Secure: Trojan.TR/W64.Agent
Fortinet: W64/Agent_AGen.MOR!tr
GData: Gen:Variant.Tedy.943827
Google: Detected
Ikarus: Trojan.Win64.Agent
Lionic: Trojan.Win32.Generic.4!c
Malwarebytes: Generic.Malware/Suspicious
MaxSecure: Trojan.Malware.682895355.susgen
McAfeeD: ti!7F62DDC035E0
MicroWorld-eScan: Gen:Variant.Tedy.943827
Microsoft: Trojan:Win32/Kepavll!rfn
NANO-Antivirus: Trojan.Win64.AgentAGen.lhsxsg
Paloalto: generic.ml
Rising: Trojan.Agent!8.B1E (TFE:5:W7BT4OUj5nE)
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
Tencent: Malware.Win32.Gencirc.14add366
TrellixENS: Artemis!6DED3EF5FFF5
VBA32: Trojan.Win64.Agent
VIPRE: Gen:Variant.Tedy.943827
Varist: W64/ABTrojan.TSHJ-2877
alibabacloud: Trojan:Win/Agent_AGen.MPY

Hashes

MD5 6ded3ef5fff5c976eb6941c3a52fd49c 🔍
SHA1 51b8070fb9a026448cd8920c2f52a9d847b5c358 🔍
SHA256 7f62ddc035e0b408bbdf46920772feaaa06e65662b67b000da0875bba0949d84 🔍
SHA3 4e8e70773ab742caeaf0102ddf0fbd65fea078e9cd12df8131c9709533065fbb 🔍
SSDeep 3072:vZ2mAJocBGjHfsT2pl8qidSUfQkHuIxte:vZ2mAJpGjHEib8qi9fQkHuGte 🔍
Imports Hash f944ff4d04d0cd1acf6dfa781c1b0649 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Apr-15 08:08:59
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x10600
SizeOfInitializedData 0xa600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000010488 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1f000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 ff5c20c9f37631fff7d20657efad9782 🔍
SHA1 20f461131915ada981b6690eb44e82a1b6d9a7db 🔍
SHA256 7ebd3c4b286a61a0f2bbfe357eaa2cdba30ac778f8a09dd60ed4c1fb89d4d717 🔍
SHA3 6603995348b0f2d0b6dc97597f979323c7e7541ccc0ffad0c3766c2fde00ee34 🔍
VirtualSize 0x10463
VirtualAddress 0x1000
SizeOfRawData 0x10600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.32227

.rdata

MD5 e320f8f77c7aba6b53fb557df722ace7 🔍
SHA1 7c83bba5d295603fe68c528d771d04f4cccbc0cf 🔍
SHA256 59b18806a45d3579cbb6db6e6d2c6d7d9fe3fd7c1f7146263d6e8b27c3e73756 🔍
SHA3 5aa3e934675206629aa9fa898793d346edd23957fc84c9a0ac528825e3c10f53 🔍
VirtualSize 0x87c6
VirtualAddress 0x12000
SizeOfRawData 0x8800
PointerToRawData 0x10a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.32949

.data

MD5 27e9f4b47ee8b585f0876c38f9a404d5 🔍
SHA1 f539f0dbac4e3e45fdb597b0593790e060647089 🔍
SHA256 e2a59f0cea5de57774e5651b137c9b3a06b3f80b2f17d35b1ab4ebcfceea8654 🔍
SHA3 ebf1f3978dc5a73427af9a083632207531a634c2fd15c391cef304772b400812 🔍
VirtualSize 0x868
VirtualAddress 0x1b000
SizeOfRawData 0x800
PointerToRawData 0x19200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.70278

.pdata

MD5 0a147bc23c6c71da4672e2f4d8b0400a 🔍
SHA1 821aefcbba28e9f1f1fa9d31e5280e85f6d3c226 🔍
SHA256 985a964e1691e2e15e0da48c4cb8ad9b2839667d5ba6f4047361c117a30280ec 🔍
SHA3 250e4e0d864b3664b7a58895f7f4fbb5abf538fb223d22ecf76d3189e70b68f7 🔍
VirtualSize 0xe94
VirtualAddress 0x1c000
SizeOfRawData 0x1000
PointerToRawData 0x19a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.65161

.rsrc

MD5 bd90dc8684f5b3e44d9b014e286e1319 🔍
SHA1 cd01dd94b9f7068f46d7f02ac41d6a1dca561c53 🔍
SHA256 a7fb26caac177bd9eb55390506591611fa57e6ac1d801ff6f847e38cf872c57d 🔍
SHA3 a7c042f0c2c98c9c5cf3433a661bd687a8db6926f619cd65b30d87001171415d 🔍
VirtualSize 0x1e0
VirtualAddress 0x1d000
SizeOfRawData 0x200
PointerToRawData 0x1aa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.71006

.reloc

MD5 7c9e848ac5f2a162a5db43802608a134 🔍
SHA1 fc612c14a37ea4f291bfda5ebcb12374a33b5669 🔍
SHA256 b1d1fc9c42141158bf0ec22802b29e4e628f62a647be541fdcffd78bfe555830 🔍
SHA3 21ed12271818c068416358d6047904dd0953e7dec70b77d13e7d12ba96bbeed8 🔍
VirtualSize 0x154
VirtualAddress 0x1e000
SizeOfRawData 0x200
PointerToRawData 0x1ac00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.06907

Imports

KERNEL32.dll ReadFile
SetConsoleCtrlHandler
SetConsoleTitleA
SetConsoleScreenBufferSize
GetStdHandle
WriteFile
SetConsoleMode
SetCurrentConsoleFontEx
CreateNamedPipeW
SetConsoleWindowInfo
CreateFileW
CreateToolhelp32Snapshot
Sleep
GetConsoleMode
GetLastError
Process32NextW
Process32FirstW
CloseHandle
Beep
SetConsoleOutputCP
ConnectNamedPipe
InitializeSListHead
GetSystemTimeAsFileTime
GetModuleHandleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
SetUnhandledExceptionFilter
SHELL32.dll ShellExecuteA
MSVCP140.dll ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A
?_Xbad_alloc@std@@YAXXZ
?_Id_cnt@id@locale@std@@0HA
?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z
?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z
?id@?$ctype@D@std@@2V0locale@2@A
?_Xlength_error@std@@YAXPEBD@Z
?id@?$collate@D@std@@2V0locale@2@A
_Mtx_lock
_Strcoll
_Cnd_do_broadcast_at_thread_exit
_Thrd_id
_Thrd_detach
_Xtime_get_ticks
_Thrd_join
_Mtx_unlock
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?_Getcat@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?id@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@2V0locale@2@A
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
?put@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@QEBA?AV?$ostreambuf_iterator@DU?$char_traits@D@std@@@2@V32@AEAVios_base@2@DPEBUtm@@PEBD3@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAH@Z
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_J@Z
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?getloc@ios_base@std@@QEBA?AVlocale@2@XZ
?good@ios_base@std@@QEBA_NXZ
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?tolower@?$ctype@D@std@@QEBADD@Z
??1facet@locale@std@@MEAA@XZ
??0facet@locale@std@@IEAA@_K@Z
?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
?_Incref@facet@locale@std@@UEAAXXZ
?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ
??1_Locinfo@std@@QEAA@XZ
??0_Locinfo@std@@QEAA@PEBD@Z
__crtLCMapStringA
?_Throw_Cpp_error@std@@YAXH@Z
??0_Lockit@std@@QEAA@H@Z
??1_Lockit@std@@QEAA@XZ
_Strxfrm
?uncaught_exceptions@std@@YAHXZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll memcmp
memmove
memset
__C_specific_handler
memcpy
__current_exception
__current_exception_context
__std_exception_destroy
__std_exception_copy
__std_type_info_compare
__RTtypeid
_CxxThrowException
__std_terminate
strchr
api-ms-win-crt-heap-l1-1-0.dll free
_set_new_mode
realloc
_callnewh
malloc
api-ms-win-crt-string-l1-1-0.dll strcpy_s
strlen
wcscpy_s
_wcsicmp
api-ms-win-crt-time-l1-1-0.dll _localtime64_s
api-ms-win-crt-runtime-l1-1-0.dll _crt_atexit
_register_onexit_function
_cexit
_seh_filter_exe
_set_app_type
_get_initial_narrow_environment
_initialize_narrow_environment
_initterm_e
exit
_exit
terminate
__p___argc
__p___argv
_c_exit
_register_thread_local_exe_atexit_callback
_configure_narrow_argv
system
_beginthreadex
_initialize_onexit_table
_initterm
api-ms-win-crt-stdio-l1-1-0.dll __stdio_common_vsprintf_s
__stdio_common_vsscanf
_set_fmode
__p__commode
api-ms-win-crt-locale-l1-1-0.dll ___lc_locale_name_func
_configthreadlocale
___lc_collate_cp_func
api-ms-win-crt-math-l1-1-0.dll __setusermatherr

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Apr-15 08:08:59
Version 0.0
SizeofData 75
AddressOfRawData 0x170f4
PointerToRawData 0x15af4
Referenced File E:\randomm\Noxybpp\NOXYBP\x64\Release\NOXPBPV2.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Apr-15 08:08:59
Version 0.0
SizeofData 20
AddressOfRawData 0x17140
PointerToRawData 0x15b40

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Apr-15 08:08:59
Version 0.0
SizeofData 800
AddressOfRawData 0x17154
PointerToRawData 0x15b54

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Apr-15 08:08:59
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14001b040

RICH Header

XOR Key 0x4761ab3a
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 14
ASM objects (35403) 3
C objects (35403) 10
C++ objects (35403) 29
Imports (35403) 6
Imports (33145) 5
Total imports 180
C++ objects (LTCG) (35728) 1
Resource objects (35728) 1
Linker (35728) 1

Errors

Leave a comment

No comments yet.