| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Apr-18 01:28:54 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\Admin\Downloads\ext-5m-main\ext-5m-main\x64\Release\cheat.pdb
|
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 19/72 (Scanned on 2026-04-06 15:12:40) |
APEX:
Malicious
CTX: exe.trojan.generic CrowdStrike: win/malicious_confidence_90% (W) Cylance: Unsafe DeepInstinct: MALICIOUS Elastic: malicious (high confidence) Fortinet: PossibleThreat.PALLAS.M Google: Detected Gridinsoft: Malware.Win64.Gen.cl Ikarus: Riskware.Win32.Hacktool Lionic: Trojan.Win32.Generic.4!c McAfeeD: ti!89F9B43EB038 Microsoft: Adware:Win32/Tnega Paloalto: generic.ml SentinelOne: Static AI - Suspicious PE Sophos: Generic Reputation PUA (PUA) Symantec: ML.Attribute.HighConfidence TrellixENS: Artemis!2D3D9A404716 Varist: W64/ABRisk.UTZM-0172 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2025-Apr-18 01:28:54 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x6f800 |
| SizeOfInitializedData | 0x71a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000004A970 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xe5000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
LoadLibraryA
QueryPerformanceFrequency GetProcAddress FreeLibrary QueryPerformanceCounter WriteProcessMemory OpenProcess CreateToolhelp32Snapshot Module32FirstW Module32NextW VirtualProtectEx VirtualQueryEx SetEndOfFile WriteConsoleW HeapReAlloc HeapSize CreateFileW GetStringTypeW SetStdHandle GetProcessHeap FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetCPInfo GetOEMCP GetLocaleInfoA IsValidCodePage FindNextFileW FindFirstFileExW FindClose GetFileSizeEx GetConsoleOutputCP FlushFileBuffers GetFileType ReadConsoleW GetConsoleMode SetFilePointerEx LCMapStringW FlsFree FlsSetValue FlsGetValue FlsAlloc HeapFree GetModuleHandleA GlobalUnlock WideCharToMultiByte GlobalLock HeapAlloc WriteFile GetStdHandle GetModuleFileNameW GlobalFree GlobalAlloc MultiByteToWideChar GetExitCodeProcess ReadProcessMemory GetACP CloseHandle ExitProcess ReadFile GetModuleHandleExW FreeLibraryAndExitThread ExitThread CreateThread LoadLibraryExW GetCurrentThreadId Sleep ReleaseSRWLockExclusive AcquireSRWLockExclusive TryAcquireSRWLockExclusive SleepConditionVariableSRW WakeAllConditionVariable GetSystemTimeAsFileTime GetModuleHandleW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW GetCurrentProcessId InitializeSListHead RtlUnwindEx RtlPcToFileHeader RaiseException GetLastError SetLastError EncodePointer EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree |
|---|---|
| USER32.dll |
GetAsyncKeyState
SetClipboardData GetClipboardData EmptyClipboard CloseClipboard OpenClipboard GetCursorPos SetCursorPos ReleaseCapture IsWindowUnicode DefWindowProcW GetWindowRect DestroyWindow CreateWindowExW UnregisterClassW RegisterClassExW ShowWindow DispatchMessageW PeekMessageW SetLayeredWindowAttributes TranslateMessage SetWindowLongW UpdateWindow GetWindowThreadProcessId FindWindowA GetKeyState GetMessageExtraInfo ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow LoadCursorW SetCapture SetCursor GetClientRect |
| d3dx9_43.dll |
D3DXMatrixTranspose
|
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
| IMM32.dll |
ImmSetCandidateWindow
ImmSetCompositionWindow ImmReleaseContext ImmGetContext |
| D3DCOMPILER_47.dll |
D3DCompile
|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| WINMM.dll |
timeEndPeriod
timeBeginPeriod |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Apr-18 01:28:54 |
| Version | 0.0 |
| SizeofData | 95 |
| AddressOfRawData | 0x864fc |
| PointerToRawData | 0x850fc |
| Referenced File | C:\Users\Admin\Downloads\ext-5m-main\ext-5m-main\x64\Release\cheat.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Apr-18 01:28:54 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x8655c |
| PointerToRawData | 0x8515c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Apr-18 01:28:54 |
| Version | 0.0 |
| SizeofData | 992 |
| AddressOfRawData | 0x86570 |
| PointerToRawData | 0x85170 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Apr-18 01:28:54 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x140086998 |
|---|---|
| EndAddressOfRawData | 0x1400869a0 |
| AddressOfIndex | 0x1400dc62c |
| AddressOfCallbacks | 0x1400715a0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14008f080 |
| XOR Key | 0xe3c5a6c4 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 23 |
| C++ objects (30795) | 162 |
| C objects (30795) | 17 |
| ASM objects (34321) | 10 |
| C objects (34321) | 17 |
| C++ objects (34321) | 60 |
| Imports (21202) | 2 |
| Imports (30795) | 17 |
| Total imports | 204 |
| C++ objects (LTCG) (34810) | 17 |
| Resource objects (34810) | 1 |
| Linker (34810) | 1 |
No comments yet.