| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jul-28 18:34:50 |
| Detected languages |
English - United States
|
| TLS Callbacks | 2 callback(s) detected. |
| Debug artifacts |
kiten_tensei.pdb
|
| CompanyName | scryde |
| FileDescription | Scryde |
| FileVersion | 0.4.62 |
| ProductName | Scryde |
| ProductVersion | 0.4.62 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to RC5 or RC6 Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: SCRYDE TECH DMCC
Issuer: GlobalSign GCC R45 CodeSigning CA 2020 |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Jul-28 18:34:50 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x693e00 |
| SizeOfInitializedData | 0x299e00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000665500 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x931000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x93a101 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
CreateProcessW
GetFileAttributesW GetTempPathW DeleteFileW GetFinalPathNameByHandleW MoveFileExW CreateWaitableTimerExW SetWaitableTimer GetFileInformationByHandleEx GetFileInformationByHandle SetFilePointerEx FindNextFileW CreateToolhelp32Snapshot Process32FirstW OpenProcess GetProcessTimes Process32NextW GetSystemTimes GetProcessIoCounters FindFirstFileExW SetFileTime CreateThread SetHandleInformation WriteFileEx SleepEx ReadFileEx ReadProcessMemory HeapAlloc VirtualQueryEx MultiByteToWideChar WideCharToMultiByte CreateMutexA WaitForSingleObjectEx RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext CreateFileW QueryPerformanceCounter SetLastError CancelIoEx WriteFile SetFileCompletionNotificationModes GetWindowsDirectoryW GetOverlappedResult ReadFile PostQueuedCompletionStatus GetQueuedCompletionStatusEx UnmapViewOfFile DuplicateHandle GetCurrentProcess MapViewOfFile GetCommandLineW FreeEnvironmentStringsW GetEnvironmentStringsW GetEnvironmentVariableW GetCurrentDirectoryW SetEnvironmentVariableW FlushViewOfFile VirtualProtect TlsSetValue TlsGetValue TlsAlloc InitOnceExecuteOnce AcquireSRWLockShared AcquireSRWLockExclusive ReleaseSRWLockShared ReleaseSRWLockExclusive CreateFileMappingW SetFileInformationByHandle InitializeSRWLock WriteConsoleW RemoveDirectoryW GetConsoleOutputCP GetConsoleMode GetStdHandle QueryPerformanceFrequency GetSystemDirectoryW CompareStringOrdinal ExitProcess FlushFileBuffers GetExitCodeProcess WaitForSingleObject GetCurrentThreadId GetCurrentProcessId GetDiskFreeSpaceW GetVolumePathNameW CreateIoCompletionPort SetNamedPipeHandleState LocalFree FindClose LCIDToLocaleName GetProcAddress LoadLibraryExA AddVectoredExceptionHandler GetUserDefaultUILanguage GetModuleHandleA WakeAllConditionVariable GetModuleHandleW DeviceIoControl SleepConditionVariableSRW GetSystemTimeAsFileTime GetFullPathNameW InitializeSListHead SetUnhandledExceptionFilter RtlUnwindEx CreateMutexW RtlPcToFileHeader ReleaseMutex RaiseException FlsAlloc FlsGetValue FlsSetValue FlsFree EncodePointer SwitchToThread CloseHandle lstrlenW InitializeCriticalSectionEx Sleep GetSystemInfo CreateDirectoryW GetLastError FreeLibrary GetSystemTimePreciseAsFileTime HeapReAlloc LoadLibraryExW OutputDebugStringW LoadLibraryA OutputDebugStringA HeapFree GetProcessHeap LoadLibraryW GetCurrentThread GetModuleFileNameW SetThreadStackGuarantee FormatMessageW DeleteCriticalSection |
|---|---|
| advapi32.dll |
EventUnregister
EventWriteTransfer EventSetInformation OpenProcessToken GetTokenInformation IsValidSid RegQueryValueExW RegSetValueExW RegOpenKeyExW EventRegister RegCloseKey CryptDestroyHash CryptReleaseContext GetLengthSid CopySid RegDeleteValueW CryptAcquireContextW RegGetValueW CryptCreateHash CryptHashData CryptGetHashParam SystemFunction036 |
| shell32.dll |
CommandLineToArgvW
SHCreateItemFromParsingName ShellExecuteExW DragQueryFileW Shell_NotifyIconGetRect DragFinish ILFree SHOpenFolderAndSelectItems ShellExecuteW SHAppBarMessage ILCreateFromPathW SHGetKnownFolderPath Shell_NotifyIconW |
| combase.dll |
CoTaskMemFree
CoCreateFreeThreadedMarshaler CoTaskMemAlloc |
| api-ms-win-core-synch-l1-2-0.dll |
WakeByAddressAll
WakeByAddressSingle WaitOnAddress |
| ws2_32.dll |
sendto
recvfrom getsockopt listen WSAStartup connect getaddrinfo freeaddrinfo setsockopt shutdown recv send WSASend bind WSACleanup getsockname WSAGetLastError getpeername closesocket WSAIoctl ioctlsocket WSASocketW accept |
| ntdll.dll |
NtCreateFile
RtlGetVersion RtlNtStatusToDosError NtCancelIoFileEx NtWriteFile NtQueryInformationProcess NtCreateNamedPipeFile NtReadFile NtDeviceIoControlFile NtOpenFile |
| user32.dll |
SetCapture
GetTouchInputInfo CloseTouchInputHandle EnumDisplayMonitors MonitorFromPoint RegisterClassExW RedrawWindow GetRawInputData ScreenToClient GetKeyState DestroyWindow ValidateRect GetUpdateRect GetAsyncKeyState SetParent GetWindow UpdateWindow MapVirtualKeyW InvalidateRect ChangeDisplaySettingsExW GetMenuItemInfoW RegisterClassW SetMenuItemInfoW SetTimer KillTimer FindWindowW SendMessageW CreateWindowExW SetWindowLongPtrW GetParent RegisterTouchWindow SetCursorPos SetCursor VkKeyScanW GetWindowLongPtrW LoadCursorW GetForegroundWindow GetDC IsWindowEnabled IsWindow IsIconic SetPropW SystemParametersInfoW ReleaseDC ClipCursor GetSystemMetrics EnableWindow GetClipCursor ShowCursor SetWindowTextW SetWindowDisplayAffinity DrawIconEx GetActiveWindow GetWindowPlacement SetWindowPlacement AdjustWindowRectEx GetMenu GetWindowLongW SetWindowLongW GetSystemMenu RegisterWindowMessageA MapWindowPoints OffsetRect GetWindowDC FillRect DrawTextW MonitorFromRect SendInput DefWindowProcW RegisterRawInputDevices ClientToScreen AdjustWindowRect PostMessageW SetFocus ReleaseCapture ToUnicodeEx MonitorFromWindow SetWindowRgn IsProcessDPIAware TrackPopupMenu SetForegroundWindow GetCursorPos GetWindowRect GetClientRect GetMenuBarInfo ShowWindow PostQuitMessage SystemParametersInfoA SetMenu CreateIcon RemoveMenu CheckMenuItem EnableMenuItem DrawMenuBar CreatePopupMenu CreateMenu AppendMenuW InsertMenuW CreateAcceleratorTableW DestroyAcceleratorTable DestroyIcon DestroyMenu GetKeyboardLayout SetWindowPos GetMessageA MapVirtualKeyExW TranslateMessage DispatchMessageA EnumChildWindows GetKeyboardState TranslateAcceleratorW InvalidateRgn MessageBoxW GetWindowTextW GetWindowTextLengthW GetWindowThreadProcessId IsWindowVisible EnumWindows ChangeWindowMessageFilterEx FlashWindowEx MsgWaitForMultipleObjectsEx DispatchMessageW GetMessageW PeekMessageW PostThreadMessageW TrackMouseEvent FindWindowExW GetMonitorInfoW |
| ole32.dll |
CoCreateInstance
CoInitialize CoUninitialize CoInitializeEx RevokeDragDrop RegisterDragDrop OleInitialize |
| oleaut32.dll |
GetErrorInfo
SysStringLen SetErrorInfo SysFreeString |
| comctl32.dll |
DefSubclassProc
RemoveWindowSubclass SetWindowSubclass TaskDialogIndirect |
| shlwapi.dll |
SHCreateMemStream
|
| iphlpapi.dll |
ConvertInterfaceLuidToIndex
ConvertLengthToIpv4Mask GetAdaptersAddresses |
| secur32.dll |
AcceptSecurityContext
QueryContextAttributesW DeleteSecurityContext ApplyControlToken DecryptMessage FreeCredentialsHandle EncryptMessage FreeContextBuffer InitializeSecurityContextW AcquireCredentialsHandleA |
| psapi.dll |
GetProcessMemoryInfo
GetModuleFileNameExW |
| powrprof.dll |
CallNtPowerInformation
|
| pdh.dll |
PdhRemoveCounter
PdhCloseQuery |
| bcryptprimitives.dll |
ProcessPrng
|
| dwmapi.dll |
DwmSetWindowAttribute
DwmEnableBlurBehindWindow DwmGetWindowAttribute |
| gdi32.dll |
SelectObject
DeleteObject CreateRectRgn CreateSolidBrush DeleteDC SetBkMode SetTextColor CreateCompatibleDC GetDeviceCaps BitBlt CombineRgn CreateDIBSection |
| crypt32.dll |
CertFreeCertificateChainEngine
CertAddEncodedCertificateToStore CertGetCertificateChain CertDuplicateCertificateContext CertDuplicateStore CertCreateCertificateChainEngine CertSetCertificateContextProperty CryptUnprotectData CertFreeCertificateContext CertCloseStore CryptMsgClose CertGetCertificateContextProperty CertDuplicateCertificateChain CertFindCertificateInStore CertAddCertificateContextToStore CertOpenStore CryptProtectData CryptMsgGetParam CryptQueryObject CertEnumCertificatesInStore CertFreeCertificateChain CertVerifyCertificateChainPolicy |
| rstrtmgr.dll |
RmGetList
RmStartSession RmRegisterResources RmEndSession |
| wintrust.dll |
WinVerifyTrust
|
| bcrypt.dll |
BCryptGenRandom
|
| api-ms-win-crt-string-l1-1-0.dll |
wcslen
wcscmp _wcsicmp strlen strcmp strcpy_s |
| api-ms-win-crt-math-l1-1-0.dll |
pow
roundf round floor trunc __setusermatherr |
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
calloc _callnewh _set_new_mode realloc free |
| api-ms-win-crt-utility-l1-1-0.dll |
_rotl64
bsearch |
| api-ms-win-crt-convert-l1-1-0.dll |
_wtoi
strtol wcstol _ultow_s |
| api-ms-win-crt-runtime-l1-1-0.dll |
__p___argv
_c_exit _initterm __p___argc abort _seh_filter_exe _set_app_type _initterm_e _configure_narrow_argv _register_thread_local_exe_atexit_callback _initialize_narrow_environment _errno terminate _crt_atexit _get_initial_narrow_environment exit _register_onexit_function _initialize_onexit_table _exit _wassert _cexit |
| api-ms-win-crt-environment-l1-1-0.dll |
getenv
|
| api-ms-win-crt-stdio-l1-1-0.dll |
_setmode
fwrite ftell fseek fflush _fileno __p__commode fopen fgets __stdio_common_vsprintf ferror feof _set_fmode fclose __stdio_common_vfprintf __stdio_common_vsscanf __acrt_iob_func fread |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Ordinal | 1 |
|---|---|
| Address | 0x659a30 |
| Ordinal | 2 |
|---|---|
| Address | 0x659ab0 |
| Ordinal | 3 |
|---|---|
| Address | 0x659b30 |
| Ordinal | 4 |
|---|---|
| Address | 0x659b70 |
| Ordinal | 5 |
|---|---|
| Address | 0x659c00 |
| Ordinal | 6 |
|---|---|
| Address | 0x659570 |
| Ordinal | 7 |
|---|---|
| Address | 0x659720 |
| Ordinal | 8 |
|---|---|
| Address | 0x659bd0 |
| Ordinal | 9 |
|---|---|
| Address | 0x659bf0 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.4.62.0 |
| ProductVersion | 0.4.62.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | scryde |
| FileDescription | Scryde |
| FileVersion (#2) | 0.4.62 |
| ProductName | Scryde |
| ProductVersion (#2) | 0.4.62 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-28 18:34:50 |
| Version | 0.0 |
| SizeofData | 41 |
| AddressOfRawData | 0x8d56cc |
| PointerToRawData | 0x8d48cc |
| Referenced File | kiten_tensei.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-28 18:34:50 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x8d56f8 |
| PointerToRawData | 0x8d48f8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-28 18:34:50 |
| Version | 0.0 |
| SizeofData | 1084 |
| AddressOfRawData | 0x8d570c |
| PointerToRawData | 0x8d490c |
| StartAddressOfRawData | 0x1408d5b90 |
|---|---|
| EndAddressOfRawData | 0x1408d5d74 |
| AddressOfIndex | 0x1408effbc |
| AddressOfCallbacks | 0x1406960b8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x000000014050DEE0
0x00000001406541B0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1408ea940 |
| XOR Key | 0x6fbefda |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 19 |
| ASM objects (35721) | 10 |
| C objects (35721) | 14 |
| C++ objects (35721) | 46 |
| Total imports | 504 |
| C objects (36248) | 75 |
| Unmarked objects (#2) | 104 |
| Exports (36248) | 1 |
| Resource objects (36248) | 1 |
| Linker (36248) | 1 |
No comments yet.