| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Sep-04 00:14:08 |
| Detected languages |
English - United States
|
| TLS Callbacks | 2 callback(s) detected. |
| Debug artifacts |
C:\Users\javiy\Downloads\1bpluu\bin\Debug\base-broll.pdb
|
| Info | Matching compiler(s): |
MASM/TASM - sig2(h)
MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses known Mersenne Twister constants |
| Suspicious | The PE is possibly packed. | Unusual section name found: .msvcjmc |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/71 (Scanned on 2026-09-04 00:14:41) |
Microsoft:
Trojan:Win32/Wacatac.B!ml
Symantec: ML.Attribute.HighConfidence |
| MD5 | a3887ea1a1e60c4dc9052d2ec3b19a92 🔍 |
|---|---|
| SHA1 | 4c46f96899f27de415899afe1fb45972e08c9f7f 🔍 |
| SHA256 | 8b3a660f070670acb05973e5b8be461f8bb6d8784f00ac89d40efcd074660d55 🔍 |
| SHA3 | f045023e407353dc0d6b77ec09aa8f1a793eed28e4ab373a8a1cd66d18eb4708 🔍 |
| SSDeep | 49152:rF0tCdm+uwi7mnY8350iKSFk6gn+C8bo/kOTdnW/:dianD50Wkzg 🔍 |
| Imports Hash | c62d45e75cb843abc1935fe39c7234d9 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 11 |
| TimeDateStamp | 2026-Sep-04 00:14:08 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x40ce00 |
| SizeOfInitializedData | 0x145200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000007C7F (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x558000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | e26761110f9ee777b54f1a9c9984c61c 🔍 |
|---|---|
| SHA1 | aa49d40f53cf55f1ed25a0ab2b64199b71be9371 🔍 |
| SHA256 | 2189c4598ba6493df05d74452a2bbe59d5366b6b56e154bb098bb04644f4fb0e 🔍 |
| SHA3 | 169f6fb6c58a2923831d286e9744181c47247484bd39dd819def73ff603e77e3 🔍 |
| VirtualSize | 0x40cc25 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x40ce00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.34884 |
| MD5 | 3a428025a271c21c5c6dd2b5d420542f 🔍 |
|---|---|
| SHA1 | e0befd5fbd6d93c3249159c3ed813c2bb5fda919 🔍 |
| SHA256 | a76a803026594fa8bebc76eb7cd9070f3a8961aad46971d143a8fdbfe4dd9665 🔍 |
| SHA3 | d6a9f7326730280f8eb02e362daf29d68c206fe588c3ffae587835ae082f3416 🔍 |
| VirtualSize | 0xffc5e |
| VirtualAddress | 0x40e000 |
| SizeOfRawData | 0xffe00 |
| PointerToRawData | 0x40d200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.21952 |
| MD5 | 1b8d570f14c7b6a24f66f55426c068c5 🔍 |
|---|---|
| SHA1 | cc852f777390bd37137708f69a21b38c84d214b3 🔍 |
| SHA256 | 1c3bd0c5561b51ded579594c789d2ff50353e650c223e961aaef826e95b5a057 🔍 |
| SHA3 | 6c731d0d0ae0831d47103a7e5ea8507616c7f7d606a2e748df9c2c4c3cd58a8b 🔍 |
| VirtualSize | 0xe2c9 |
| VirtualAddress | 0x50e000 |
| SizeOfRawData | 0x3800 |
| PointerToRawData | 0x50d000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 1.94603 |
| MD5 | f8fa3a4f199b3769db71f0d1e378fc52 🔍 |
|---|---|
| SHA1 | d860061766cdb77bb52fcae912ef0476893c0563 🔍 |
| SHA256 | 95c32b77abda954f616f5f1486b92a8eb4a202fb7bb34f6edc103270807a669f 🔍 |
| SHA3 | be0388fc3de66f8fd8030000732ddc103707f67f4ce3bc7fe42d93170dd1272a 🔍 |
| VirtualSize | 0x2b008 |
| VirtualAddress | 0x51d000 |
| SizeOfRawData | 0x2b200 |
| PointerToRawData | 0x510800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.91027 |
| MD5 | 584e76b7a3e75e41ea4f5150f1ca287c 🔍 |
|---|---|
| SHA1 | e5ca9beab8c60d33aa50c056ed12c97207fe40fd 🔍 |
| SHA256 | 45eed5ad44c59a3501098d7870e88875d4c44c8e29bb7e1ba9af62f80478902c 🔍 |
| SHA3 | f39e6e8e71f8c48469b245adbfff439a1a662c8f3ac5a9f78cd32f6f2dfbd5d5 🔍 |
| VirtualSize | 0x2e80 |
| VirtualAddress | 0x549000 |
| SizeOfRawData | 0x3000 |
| PointerToRawData | 0x53ba00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 3.76863 |
| MD5 | b2f15118221a000a4575a9069ae4f224 🔍 |
|---|---|
| SHA1 | 14f4240f723f0ec980532c0e571b36edf51944f5 🔍 |
| SHA256 | 7f6d49153f6bb0d823960d0fd1a4f8ff03a6dbf95a8e61ccf0778045a00046f0 🔍 |
| SHA3 | 0a14b46243ff68e1b53e1edaa02cb4dee5d4e4236a9b14c6a4d3dc80fd0686db 🔍 |
| VirtualSize | 0xf6a |
| VirtualAddress | 0x54c000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0x53ea00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0.810115 |
| MD5 | 9a4fcd7e1723720904051dac53bcc071 🔍 |
|---|---|
| SHA1 | afda83ae604b6da24c7ea088d50098e326954ae4 🔍 |
| SHA256 | 69e57a5d8fa2ca97d937d476a7427073ab5171f53bee9fa9127287189cc28db8 🔍 |
| SHA3 | e0461dee2b24789fbb557e4cb2edcf56951388970db55b482f2b995de774093a 🔍 |
| VirtualSize | 0x48b |
| VirtualAddress | 0x54d000 |
| SizeOfRawData | 0x600 |
| PointerToRawData | 0x53fa00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0.0078302 |
| MD5 | 13446f5a07f6cd3d3b19ac51e7ebc3b8 🔍 |
|---|---|
| SHA1 | 92f82bd1a46d6ae1ee09fa714909722cdd423b67 🔍 |
| SHA256 | 19ec3d432b05d347dad855162082869e68524e249d0e3afa48bbad2d95131655 🔍 |
| SHA3 | 3143dbe8df8a109d59adb789374e61a43f3be06fc092e18c5ac8088862f0a2b1 🔍 |
| VirtualSize | 0x175 |
| VirtualAddress | 0x54e000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x540000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 0.411681 |
| MD5 | 0f343b0931126a20f133d67c2b018a3b 🔍 |
|---|---|
| SHA1 | 60cacbf3d72e1e7834203da608037b1bf83b40e8 🔍 |
| SHA256 | 5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef 🔍 |
| SHA3 | 6841b2c10aa6e5f7a384143e4de58fbc9aa28a4b742e9ad4ed14ba148a723a43 🔍 |
| VirtualSize | 0x233 |
| VirtualAddress | 0x54f000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x540200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 75c8b00bf3713c4bb0f885c80ac27eee 🔍 |
|---|---|
| SHA1 | 5a4bac151d20b8ffcc079aa72198eef10a0ba67e 🔍 |
| SHA256 | 8d8b79fffddab8a9c5616b715af08d6238f33188b9a5f3c3a1e49de202b43ce1 🔍 |
| SHA3 | 9a2446267883849a8d0720462916f5a7577e6dabf119d96f5c6db018517fffc0 🔍 |
| VirtualSize | 0x43c |
| VirtualAddress | 0x550000 |
| SizeOfRawData | 0x600 |
| PointerToRawData | 0x540600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 2.13913 |
| MD5 | 15e62e78c0eb92757c7a9072dc7691f7 🔍 |
|---|---|
| SHA1 | 7900c4eb005f1951210ef9416ea5d911984a2324 🔍 |
| SHA256 | 398d652e4dbf8fdc125a1f6f95f55b8ab837ceb8205127297d4cb75ae13d8fc9 🔍 |
| SHA3 | 9eff930bb816d2bc0f76f73f393de5e4e2f9bd33142cd55b153216f391749689 🔍 |
| VirtualSize | 0x6b77 |
| VirtualAddress | 0x551000 |
| SizeOfRawData | 0x6c00 |
| PointerToRawData | 0x540c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 3.22803 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
DwmGetColorizationColor DwmIsCompositionEnabled DwmEnableBlurBehindWindow |
| KERNEL32.dll |
GetCurrentThread
GetCurrentThreadId SetThreadPriority GetTickCount64 GetModuleHandleA GetProcAddress AllocConsole OpenProcess ReadProcessMemory CreateToolhelp32Snapshot Process32NextW Module32FirstW GetModuleHandleW GlobalAlloc GlobalUnlock GlobalLock GlobalFree MultiByteToWideChar WideCharToMultiByte VerSetConditionMask FreeLibrary LoadLibraryA GetLocaleInfoA CreateFileA GetFileSizeEx ReadFile HeapAlloc HeapReAlloc HeapFree GetProcessHeap MapViewOfFile UnmapViewOfFile CreateFileMappingA GetCPInfo GetOEMCP GetACP IsValidCodePage FindNextFileW FindFirstFileExW FindClose HeapQueryInformation SetFilePointerEx ReadConsoleW GetConsoleMode GetConsoleOutputCP FlushFileBuffers EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW QueryPerformanceFrequency GetTimeFormatW GetDateFormatW VirtualProtect IsThreadAFiber FlsFree FlsSetValue FlsGetValue FlsAlloc SetConsoleCtrlHandler OutputDebugStringW GetCommandLineW GetCommandLineA ExitProcess WriteFile GetSystemInfo HeapValidate HeapSize WriteConsoleW GetFileType GetStdHandle FreeLibraryAndExitThread ResumeThread ExitThread CreateThread GetModuleHandleExW TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount RtlUnwind EncodePointer SetLastError QueryPerformanceCounter CloseHandle GetEnvironmentStringsW FreeEnvironmentStringsW LoadLibraryExW GetModuleFileNameW InterlockedFlushSList InterlockedPushEntrySList RtlUnwindEx RtlPcToFileHeader VirtualQuery GetLastError RaiseException GetStartupInfoW IsDebuggerPresent InitializeSListHead GetCurrentProcessId IsProcessorFeaturePresent TerminateProcess GetCurrentProcess SetUnhandledExceptionFilter UnhandledExceptionFilter SetEnvironmentVariableW SetStdHandle GetStringTypeW SetEndOfFile Sleep CreateFileW CompareStringW WaitForSingleObjectEx SwitchToThread GetExitCodeThread GetNativeSystemInfo ReleaseSRWLockExclusive ReleaseSRWLockShared AcquireSRWLockExclusive AcquireSRWLockShared TryAcquireSRWLockExclusive TryAcquireSRWLockShared SleepConditionVariableSRW EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection SetFileInformationByHandle GetTempPathW InitOnceExecuteOnce CreateEventExW CreateSemaphoreExW FlushProcessWriteBuffers GetCurrentProcessorNumber GetSystemTimeAsFileTime FreeLibraryWhenCallbackReturns CreateThreadpoolTimer SetThreadpoolTimer WaitForThreadpoolTimerCallbacks CloseThreadpoolTimer CreateThreadpoolWait SetThreadpoolWait CloseThreadpoolWait GetFileInformationByHandleEx CreateSymbolicLinkW WakeConditionVariable WakeAllConditionVariable FormatMessageA LocalFree GetLocaleInfoEx RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind |
| USER32.dll |
SetWindowsHookExW
UnhookWindowsHookEx CallNextHookEx DefWindowProcW PostQuitMessage UnregisterClassW GetCursorPos TranslateMessage DispatchMessageW PeekMessageW PostMessageW GetAsyncKeyState SendInput FindWindowW GetClipboardData RegisterClassExW SetProcessDPIAware MonitorFromWindow LoadCursorW ScreenToClient ClientToScreen SetCursor SetCursorPos GetClientRect ReleaseDC GetDC IsWindowUnicode ReleaseCapture SetCapture GetCapture GetKeyState GetMessageExtraInfo TrackMouseEvent GetKeyboardLayout EmptyClipboard CreateWindowExW SetClipboardData CloseClipboard OpenClipboard SetWindowLongW GetWindowLongW GetWindowRect GetForegroundWindow UpdateWindow SetWindowPos SetLayeredWindowAttributes ShowWindow DestroyWindow IsWindow MsgWaitForMultipleObjects |
| GDI32.dll |
DeleteObject
GetDeviceCaps CreateRectRgn |
| SHELL32.dll |
ShellExecuteW
|
| ole32.dll |
CoCreateInstance
CoInitializeEx CoUninitialize |
| WINMM.dll |
timeBeginPeriod
timeEndPeriod |
| WINHTTP.dll |
WinHttpOpen
WinHttpCloseHandle WinHttpConnect WinHttpReadData WinHttpQueryDataAvailable WinHttpOpenRequest WinHttpSendRequest WinHttpReceiveResponse |
| IMM32.dll |
ImmSetCompositionWindow
ImmGetContext ImmReleaseContext ImmSetCandidateWindow |
| D3DCOMPILER_47.dll |
D3DCompile
|
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Sep-04 00:14:08 |
| Version | 0.0 |
| SizeofData | 81 |
| AddressOfRawData | 0x4dece4 |
| PointerToRawData | 0x4ddee4 |
| Referenced File | C:\Users\javiy\Downloads\1bpluu\bin\Debug\base-broll.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Sep-04 00:14:08 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x4ded38 |
| PointerToRawData | 0x4ddf38 |
| StartAddressOfRawData | 0x14054d000 |
|---|---|
| EndAddressOfRawData | 0x14054d38a |
| AddressOfIndex | 0x14051a3ac |
| AddressOfCallbacks | 0x14040ee30 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks |
0x00000001400040D9
0x000000014000BC3A |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140510100 |
| XOR Key | 0x557705ee |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 178 |
| ASM objects (33145) | 28 |
| 253 (35207) | 1 |
| ASM objects (35207) | 12 |
| C objects (35207) | 19 |
| C++ objects (35207) | 73 |
| C objects (33145) | 37 |
| C objects (VS2022 Update 7 (17.7.0-3) compiler 32822) | 27 |
| Imports (33145) | 23 |
| Total imports | 232 |
| C++ objects (35228) | 17 |
| Resource objects (35228) | 1 |
| Linker (35228) | 1 |
No comments yet.