8a519121a263cb7838bb9a57684f4ff8b83d1faf07e0f8d1b9f568c652b59490

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Aug-11 23:45:02
Detected languages English - United States

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Malicious The PE contains functions mostly used by malware. Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • FindWindowA
  • FindWindowW
Possibly launches other programs:
  • system
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
Manipulates other processes:
  • Process32FirstW
  • ReadProcessMemory
  • OpenProcess
  • Process32NextW
  • WriteProcessMemory
Malicious VirusTotal score: 7/70 (Scanned on 2026-08-13 22:08:44) APEX: Malicious
CrowdStrike: win/malicious_confidence_60% (D)
DeepInstinct: MALICIOUS
Elastic: malicious (moderate confidence)
Microsoft: Trojan:Win32/Wacatac.B!ml
SentinelOne: Static AI - Suspicious PE
Symantec: ML.Attribute.HighConfidence

Hashes

MD5 6d5ffb99367a9de348aae976253b1dc3 🔍
SHA1 86f51f3194b106017c15f61a71d49578f48e872b 🔍
SHA256 8a519121a263cb7838bb9a57684f4ff8b83d1faf07e0f8d1b9f568c652b59490 🔍
SHA3 7a24da68cd9b005016d99f6e3f50c4d8009440ae6b3dd69a2641bb7f82ae603f 🔍
SSDeep 12288:8EisVz9gYkyCe+g99weocQOmSUY8EWfS+Iia33WynZJ:85sVz9Ys+g9ijcQBZYYIijyn 🔍
Imports Hash ad52e32d4cc827b89add78c68f452510 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-11 23:45:02
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x6e600
SizeOfInitializedData 0x1da00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000006DD08 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x91000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 c91469b8125b286dc3a6f84ab1977aee 🔍
SHA1 bb89e5c9069e1fa61000eca6f50c146a9663371f 🔍
SHA256 fb3e56976c90ec3d5a2132d9a325d34550a199fd28f3c897f6710c2762609c7d 🔍
SHA3 1ac777ee23e5713baeed90d8571b15f224ad43993bbbe3eb8c04d8c5564007b8 🔍
VirtualSize 0x6e5d5
VirtualAddress 0x1000
SizeOfRawData 0x6e600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.48853

.rdata

MD5 d1b1af3273522d9eb800434e2f96687a 🔍
SHA1 fae2c7a5b286def8a3cbea1dfd6311e093beb9d5 🔍
SHA256 e9b66b7bdc5a78727ffcc126258a1f923f32e768936573eb96a6046a4e8129e0 🔍
SHA3 d09ef200e1d454e24d2c217f828c2016d0ec55c027847984cd038f1c679ab545 🔍
VirtualSize 0x18442
VirtualAddress 0x70000
SizeOfRawData 0x18600
PointerToRawData 0x6ea00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.32559

.data

MD5 195e22c3c4d2b68de6c1d84ea44ad835 🔍
SHA1 31b554c9acbd592051e5cef3e7a62238d64ff113 🔍
SHA256 d075837a16e7c9709b59b168517975a8780973ae5369d4132883cd5f6e36e75b 🔍
SHA3 679a80cae49057d02b71f5fe0e8d370943fd5f15577703c8ae61212973a1a379 🔍
VirtualSize 0x440
VirtualAddress 0x89000
SizeOfRawData 0x200
PointerToRawData 0x87000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.95821

.pdata

MD5 5f242c7efc843d672cbf31c6f61f7856 🔍
SHA1 e7e7a72f4d623f845e2048463c58129c7a5004ac 🔍
SHA256 655bfdd8e559b7b6bddf04147c7842405d765f9f0641118476e5b68846e1661f 🔍
SHA3 bb880d377749d98d6facacdb5e959011bd0caef50f75029c45e139044044aba3 🔍
VirtualSize 0x46c8
VirtualAddress 0x8a000
SizeOfRawData 0x4800
PointerToRawData 0x87200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.87938

.rsrc

MD5 770dc0cfd5c43c4c579d5319651b6651 🔍
SHA1 2ecb03e67427a7f6e90b9843b64860693f5d7e5b 🔍
SHA256 192f759e575c9dbaa1fd770e514f87add6ab066e1c59be1008bf98cb244fe896 🔍
SHA3 261d614a5950c88ecf77f2317f42f018d0c7ce9313775ac8c192dc3450cca76f 🔍
VirtualSize 0x1e0
VirtualAddress 0x8f000
SizeOfRawData 0x200
PointerToRawData 0x8ba00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.71768

.reloc

MD5 17f701fd2ab5d5610226672fb4f168cb 🔍
SHA1 2a2cf706c5e9ad8a53228877e4a18c7579cd11d2 🔍
SHA256 7a4274c48cccc811969b2792b843c3c1ab1e7c0df411203094943c24a4a1ef56 🔍
SHA3 f7b488937e41638db318d7f34a53d6fb761600d11b2a402969706cecc0f0977a 🔍
VirtualSize 0x254
VirtualAddress 0x90000
SizeOfRawData 0x400
PointerToRawData 0x8bc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 3.67988

Imports

KERNEL32.dll Process32FirstW
CloseHandle
Module32FirstW
ReadProcessMemory
GetModuleHandleW
Module32NextW
MultiByteToWideChar
GetLocaleInfoA
QueryPerformanceFrequency
IsDBCSLeadByte
QueryPerformanceCounter
CreateToolhelp32Snapshot
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
SleepConditionVariableSRW
Sleep
GetCurrentThreadId
WakeAllConditionVariable
SetUnhandledExceptionFilter
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeSListHead
OpenProcess
K32GetModuleFileNameExW
GetProcessId
Process32NextW
WriteProcessMemory
USER32.dll GetKeyState
GetMessageExtraInfo
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
LoadCursorW
SetCapture
SetCursor
GetClientRect
IsWindowUnicode
ReleaseCapture
SetCursorPos
DefWindowProcW
DestroyWindow
PostMessageA
PostQuitMessage
SendInput
GetCursorPos
UpdateWindow
FindWindowA
RegisterClassExW
SetWindowLongW
FindWindowW
CreateWindowExW
ScreenToClient
TranslateMessage
UnregisterClassW
GetSystemMetrics
ShowWindow
GetAsyncKeyState
DispatchMessageW
PeekMessageW
SetLayeredWindowAttributes
MSVCP140.dll ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@M@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
?good@ios_base@std@@QEBA_NXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
_Query_perf_frequency
?_Throw_Cpp_error@std@@YAXH@Z
?uncaught_exceptions@std@@YAHXZ
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?_Xout_of_range@std@@YAXPEBD@Z
?_Xlength_error@std@@YAXPEBD@Z
_Cnd_do_broadcast_at_thread_exit
_Thrd_id
_Query_perf_counter
_Thrd_join
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
d3d11.dll D3D11CreateDeviceAndSwapChain
dwmapi.dll DwmExtendFrameIntoClientArea
D3DCOMPILER_47.dll D3DCompile
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll memset
__C_specific_handler
_CxxThrowException
__current_exception
__current_exception_context
memcpy
memcmp
memchr
strchr
__std_terminate
__std_exception_copy
__std_exception_destroy
memmove
api-ms-win-crt-runtime-l1-1-0.dll _get_initial_narrow_environment
_initterm
_initterm_e
_exit
exit
__p___argc
__p___argv
_c_exit
_register_thread_local_exe_atexit_callback
_seh_filter_exe
_cexit
_beginthreadex
system
_crt_atexit
terminate
_register_onexit_function
_set_app_type
_initialize_onexit_table
_initialize_narrow_environment
_configure_narrow_argv
api-ms-win-crt-heap-l1-1-0.dll malloc
_set_new_mode
_callnewh
free
api-ms-win-crt-string-l1-1-0.dll wcslen
strcmp
strlen
strncmp
strncpy
_wcsicmp
api-ms-win-crt-stdio-l1-1-0.dll fread
__stdio_common_vsprintf
_wfopen
fwrite
fseek
fclose
fflush
__acrt_iob_func
ftell
__p__commode
__stdio_common_vsscanf
_set_fmode
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-convert-l1-1-0.dll atof
api-ms-win-crt-math-l1-1-0.dll sqrtf
atan2f
cosf
fmodf
log
ceilf
sinf
logf
pow
powf
acosf
_fdclass
__setusermatherr
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-11 23:45:02
Version 0.0
SizeofData 892
AddressOfRawData 0x7f0f4
PointerToRawData 0x7daf4

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-11 23:45:02
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x14007f490
EndAddressOfRawData 0x14007f498
AddressOfIndex 0x140089250
AddressOfCallbacks 0x140070618
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140089040

RICH Header

XOR Key 0xdc770f0a
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 16
ASM objects (35403) 4
C objects (35403) 10
C++ objects (35403) 30
Imports (35403) 6
Imports (33145) 13
Total imports 197
C++ objects (LTCG) (35724) 7
Resource objects (35724) 1
Linker (35724) 1

Errors

Leave a comment

No comments yet.