8b3a660f070670acb05973e5b8be461f8bb6d8784f00ac89d40efcd074660d55

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Sep-04 00:14:08
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.
Debug artifacts C:\Users\javiy\Downloads\1bpluu\bin\Debug\base-broll.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig2(h)
MASM/TASM - sig1(h)
Info Interesting strings found in the binary: Contains domain names:
  • github.com
  • https://github.com
  • roblox.com
  • thumbnails.roblox.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses known Mersenne Twister constants
Suspicious The PE is possibly packed. Unusual section name found: .msvcjmc
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • SwitchToThread
  • FindWindowW
Code injection capabilities (PowerLoader):
  • FindWindowW
  • GetWindowLongW
Possibly launches other programs:
  • ShellExecuteW
Can create temporary files:
  • CreateFileA
  • CreateFileW
  • GetTempPathW
Uses functions commonly found in keyloggers:
  • CallNextHookEx
  • GetAsyncKeyState
  • GetForegroundWindow
Has Internet access capabilities:
  • WinHttpOpen
  • WinHttpCloseHandle
  • WinHttpConnect
  • WinHttpReadData
  • WinHttpQueryDataAvailable
  • WinHttpOpenRequest
  • WinHttpSendRequest
  • WinHttpReceiveResponse
Manipulates other processes:
  • OpenProcess
  • ReadProcessMemory
  • Process32NextW
Can take screenshots:
  • FindWindowW
  • GetDC
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious VirusTotal score: 2/71 (Scanned on 2026-09-04 00:14:41) Microsoft: Trojan:Win32/Wacatac.B!ml
Symantec: ML.Attribute.HighConfidence

Hashes

MD5 a3887ea1a1e60c4dc9052d2ec3b19a92 🔍
SHA1 4c46f96899f27de415899afe1fb45972e08c9f7f 🔍
SHA256 8b3a660f070670acb05973e5b8be461f8bb6d8784f00ac89d40efcd074660d55 🔍
SHA3 f045023e407353dc0d6b77ec09aa8f1a793eed28e4ab373a8a1cd66d18eb4708 🔍
SSDeep 49152:rF0tCdm+uwi7mnY8350iKSFk6gn+C8bo/kOTdnW/:dianD50Wkzg 🔍
Imports Hash c62d45e75cb843abc1935fe39c7234d9 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 11
TimeDateStamp 2026-Sep-04 00:14:08
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x40ce00
SizeOfInitializedData 0x145200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000007C7F (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x558000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e26761110f9ee777b54f1a9c9984c61c 🔍
SHA1 aa49d40f53cf55f1ed25a0ab2b64199b71be9371 🔍
SHA256 2189c4598ba6493df05d74452a2bbe59d5366b6b56e154bb098bb04644f4fb0e 🔍
SHA3 169f6fb6c58a2923831d286e9744181c47247484bd39dd819def73ff603e77e3 🔍
VirtualSize 0x40cc25
VirtualAddress 0x1000
SizeOfRawData 0x40ce00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.34884

.rdata

MD5 3a428025a271c21c5c6dd2b5d420542f 🔍
SHA1 e0befd5fbd6d93c3249159c3ed813c2bb5fda919 🔍
SHA256 a76a803026594fa8bebc76eb7cd9070f3a8961aad46971d143a8fdbfe4dd9665 🔍
SHA3 d6a9f7326730280f8eb02e362daf29d68c206fe588c3ffae587835ae082f3416 🔍
VirtualSize 0xffc5e
VirtualAddress 0x40e000
SizeOfRawData 0xffe00
PointerToRawData 0x40d200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.21952

.data

MD5 1b8d570f14c7b6a24f66f55426c068c5 🔍
SHA1 cc852f777390bd37137708f69a21b38c84d214b3 🔍
SHA256 1c3bd0c5561b51ded579594c789d2ff50353e650c223e961aaef826e95b5a057 🔍
SHA3 6c731d0d0ae0831d47103a7e5ea8507616c7f7d606a2e748df9c2c4c3cd58a8b 🔍
VirtualSize 0xe2c9
VirtualAddress 0x50e000
SizeOfRawData 0x3800
PointerToRawData 0x50d000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.94603

.pdata

MD5 f8fa3a4f199b3769db71f0d1e378fc52 🔍
SHA1 d860061766cdb77bb52fcae912ef0476893c0563 🔍
SHA256 95c32b77abda954f616f5f1486b92a8eb4a202fb7bb34f6edc103270807a669f 🔍
SHA3 be0388fc3de66f8fd8030000732ddc103707f67f4ce3bc7fe42d93170dd1272a 🔍
VirtualSize 0x2b008
VirtualAddress 0x51d000
SizeOfRawData 0x2b200
PointerToRawData 0x510800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.91027

.idata

MD5 584e76b7a3e75e41ea4f5150f1ca287c 🔍
SHA1 e5ca9beab8c60d33aa50c056ed12c97207fe40fd 🔍
SHA256 45eed5ad44c59a3501098d7870e88875d4c44c8e29bb7e1ba9af62f80478902c 🔍
SHA3 f39e6e8e71f8c48469b245adbfff439a1a662c8f3ac5a9f78cd32f6f2dfbd5d5 🔍
VirtualSize 0x2e80
VirtualAddress 0x549000
SizeOfRawData 0x3000
PointerToRawData 0x53ba00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.76863

.msvcjmc

MD5 b2f15118221a000a4575a9069ae4f224 🔍
SHA1 14f4240f723f0ec980532c0e571b36edf51944f5 🔍
SHA256 7f6d49153f6bb0d823960d0fd1a4f8ff03a6dbf95a8e61ccf0778045a00046f0 🔍
SHA3 0a14b46243ff68e1b53e1edaa02cb4dee5d4e4236a9b14c6a4d3dc80fd0686db 🔍
VirtualSize 0xf6a
VirtualAddress 0x54c000
SizeOfRawData 0x1000
PointerToRawData 0x53ea00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.810115

.tls

MD5 9a4fcd7e1723720904051dac53bcc071 🔍
SHA1 afda83ae604b6da24c7ea088d50098e326954ae4 🔍
SHA256 69e57a5d8fa2ca97d937d476a7427073ab5171f53bee9fa9127287189cc28db8 🔍
SHA3 e0461dee2b24789fbb557e4cb2edcf56951388970db55b482f2b995de774093a 🔍
VirtualSize 0x48b
VirtualAddress 0x54d000
SizeOfRawData 0x600
PointerToRawData 0x53fa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.0078302

.00cfg

MD5 13446f5a07f6cd3d3b19ac51e7ebc3b8 🔍
SHA1 92f82bd1a46d6ae1ee09fa714909722cdd423b67 🔍
SHA256 19ec3d432b05d347dad855162082869e68524e249d0e3afa48bbad2d95131655 🔍
SHA3 3143dbe8df8a109d59adb789374e61a43f3be06fc092e18c5ac8088862f0a2b1 🔍
VirtualSize 0x175
VirtualAddress 0x54e000
SizeOfRawData 0x200
PointerToRawData 0x540000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.411681

.fptable

MD5 0f343b0931126a20f133d67c2b018a3b 🔍
SHA1 60cacbf3d72e1e7834203da608037b1bf83b40e8 🔍
SHA256 5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef 🔍
SHA3 6841b2c10aa6e5f7a384143e4de58fbc9aa28a4b742e9ad4ed14ba148a723a43 🔍
VirtualSize 0x233
VirtualAddress 0x54f000
SizeOfRawData 0x400
PointerToRawData 0x540200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 75c8b00bf3713c4bb0f885c80ac27eee 🔍
SHA1 5a4bac151d20b8ffcc079aa72198eef10a0ba67e 🔍
SHA256 8d8b79fffddab8a9c5616b715af08d6238f33188b9a5f3c3a1e49de202b43ce1 🔍
SHA3 9a2446267883849a8d0720462916f5a7577e6dabf119d96f5c6db018517fffc0 🔍
VirtualSize 0x43c
VirtualAddress 0x550000
SizeOfRawData 0x600
PointerToRawData 0x540600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.13913

.reloc

MD5 15e62e78c0eb92757c7a9072dc7691f7 🔍
SHA1 7900c4eb005f1951210ef9416ea5d911984a2324 🔍
SHA256 398d652e4dbf8fdc125a1f6f95f55b8ab837ceb8205127297d4cb75ae13d8fc9 🔍
SHA3 9eff930bb816d2bc0f76f73f393de5e4e2f9bd33142cd55b153216f391749689 🔍
VirtualSize 0x6b77
VirtualAddress 0x551000
SizeOfRawData 0x6c00
PointerToRawData 0x540c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 3.22803

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
dwmapi.dll DwmExtendFrameIntoClientArea
DwmGetColorizationColor
DwmIsCompositionEnabled
DwmEnableBlurBehindWindow
KERNEL32.dll GetCurrentThread
GetCurrentThreadId
SetThreadPriority
GetTickCount64
GetModuleHandleA
GetProcAddress
AllocConsole
OpenProcess
ReadProcessMemory
CreateToolhelp32Snapshot
Process32NextW
Module32FirstW
GetModuleHandleW
GlobalAlloc
GlobalUnlock
GlobalLock
GlobalFree
MultiByteToWideChar
WideCharToMultiByte
VerSetConditionMask
FreeLibrary
LoadLibraryA
GetLocaleInfoA
CreateFileA
GetFileSizeEx
ReadFile
HeapAlloc
HeapReAlloc
HeapFree
GetProcessHeap
MapViewOfFile
UnmapViewOfFile
CreateFileMappingA
GetCPInfo
GetOEMCP
GetACP
IsValidCodePage
FindNextFileW
FindFirstFileExW
FindClose
HeapQueryInformation
SetFilePointerEx
ReadConsoleW
GetConsoleMode
GetConsoleOutputCP
FlushFileBuffers
EnumSystemLocalesW
GetUserDefaultLCID
IsValidLocale
GetLocaleInfoW
LCMapStringW
QueryPerformanceFrequency
GetTimeFormatW
GetDateFormatW
VirtualProtect
IsThreadAFiber
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
SetConsoleCtrlHandler
OutputDebugStringW
GetCommandLineW
GetCommandLineA
ExitProcess
WriteFile
GetSystemInfo
HeapValidate
HeapSize
WriteConsoleW
GetFileType
GetStdHandle
FreeLibraryAndExitThread
ResumeThread
ExitThread
CreateThread
GetModuleHandleExW
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
RtlUnwind
EncodePointer
SetLastError
QueryPerformanceCounter
CloseHandle
GetEnvironmentStringsW
FreeEnvironmentStringsW
LoadLibraryExW
GetModuleFileNameW
InterlockedFlushSList
InterlockedPushEntrySList
RtlUnwindEx
RtlPcToFileHeader
VirtualQuery
GetLastError
RaiseException
GetStartupInfoW
IsDebuggerPresent
InitializeSListHead
GetCurrentProcessId
IsProcessorFeaturePresent
TerminateProcess
GetCurrentProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
SetEnvironmentVariableW
SetStdHandle
GetStringTypeW
SetEndOfFile
Sleep
CreateFileW
CompareStringW
WaitForSingleObjectEx
SwitchToThread
GetExitCodeThread
GetNativeSystemInfo
ReleaseSRWLockExclusive
ReleaseSRWLockShared
AcquireSRWLockExclusive
AcquireSRWLockShared
TryAcquireSRWLockExclusive
TryAcquireSRWLockShared
SleepConditionVariableSRW
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
SetFileInformationByHandle
GetTempPathW
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreExW
FlushProcessWriteBuffers
GetCurrentProcessorNumber
GetSystemTimeAsFileTime
FreeLibraryWhenCallbackReturns
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
GetFileInformationByHandleEx
CreateSymbolicLinkW
WakeConditionVariable
WakeAllConditionVariable
FormatMessageA
LocalFree
GetLocaleInfoEx
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
USER32.dll SetWindowsHookExW
UnhookWindowsHookEx
CallNextHookEx
DefWindowProcW
PostQuitMessage
UnregisterClassW
GetCursorPos
TranslateMessage
DispatchMessageW
PeekMessageW
PostMessageW
GetAsyncKeyState
SendInput
FindWindowW
GetClipboardData
RegisterClassExW
SetProcessDPIAware
MonitorFromWindow
LoadCursorW
ScreenToClient
ClientToScreen
SetCursor
SetCursorPos
GetClientRect
ReleaseDC
GetDC
IsWindowUnicode
ReleaseCapture
SetCapture
GetCapture
GetKeyState
GetMessageExtraInfo
TrackMouseEvent
GetKeyboardLayout
EmptyClipboard
CreateWindowExW
SetClipboardData
CloseClipboard
OpenClipboard
SetWindowLongW
GetWindowLongW
GetWindowRect
GetForegroundWindow
UpdateWindow
SetWindowPos
SetLayeredWindowAttributes
ShowWindow
DestroyWindow
IsWindow
MsgWaitForMultipleObjects
GDI32.dll DeleteObject
GetDeviceCaps
CreateRectRgn
SHELL32.dll ShellExecuteW
ole32.dll CoCreateInstance
CoInitializeEx
CoUninitialize
WINMM.dll timeBeginPeriod
timeEndPeriod
WINHTTP.dll WinHttpOpen
WinHttpCloseHandle
WinHttpConnect
WinHttpReadData
WinHttpQueryDataAvailable
WinHttpOpenRequest
WinHttpSendRequest
WinHttpReceiveResponse
IMM32.dll ImmSetCompositionWindow
ImmGetContext
ImmReleaseContext
ImmSetCandidateWindow
D3DCOMPILER_47.dll D3DCompile

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Sep-04 00:14:08
Version 0.0
SizeofData 81
AddressOfRawData 0x4dece4
PointerToRawData 0x4ddee4
Referenced File C:\Users\javiy\Downloads\1bpluu\bin\Debug\base-broll.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Sep-04 00:14:08
Version 0.0
SizeofData 20
AddressOfRawData 0x4ded38
PointerToRawData 0x4ddf38

TLS Callbacks

StartAddressOfRawData 0x14054d000
EndAddressOfRawData 0x14054d38a
AddressOfIndex 0x14051a3ac
AddressOfCallbacks 0x14040ee30
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks 0x00000001400040D9
0x000000014000BC3A

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140510100

RICH Header

XOR Key 0x557705ee
Unmarked objects 0
C++ objects (33145) 178
ASM objects (33145) 28
253 (35207) 1
ASM objects (35207) 12
C objects (35207) 19
C++ objects (35207) 73
C objects (33145) 37
C objects (VS2022 Update 7 (17.7.0-3) compiler 32822) 27
Imports (33145) 23
Total imports 232
C++ objects (35228) 17
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.