Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2023-Mar-11 14:46:52 |
Detected languages |
English - United States
|
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 34/73 (Scanned on 2025-03-11 21:40:47) |
APEX:
Malicious
AVG: FileRepMalware [Misc] AhnLab-V3: Trojan/Win.Generic.C5604983 Avast: FileRepMalware [Misc] Bkav: W32.Common.02476C0A CAT-QuickHeal: Trojan.Ghanarava.1724305954ab60dc CTX: exe.trojan.generic CrowdStrike: win/malicious_confidence_70% (W) Cylance: Unsafe DeepInstinct: MALICIOUS ESET-NOD32: a variant of Win64/GameHack.IZ potentially unsafe Fortinet: Riskware/Application GData: Win64.Trojan.Agent.O8GAWC Google: Detected Gridinsoft: Trojan.Win64.Gen.sa Ikarus: Trojan.Win32.Generic K7AntiVirus: Unwanted-Program ( 005b0e871 ) K7GW: Unwanted-Program ( 005b0e871 ) Lionic: Trojan.Win32.GameHack.4!c Malwarebytes: Malware.AI.1492285693 MaxSecure: Trojan.Malware.259638731.susgen McAfee: Artemis!8B9237462421 McAfeeD: ti!021F53C23281 Paloalto: generic.ml Panda: Trj/Chgt.AD Rising: Trojan.Znyonm!8.18A3A (CLOUD) Skyhigh: BehavesLike.Win64.Injector.th Symantec: ML.Attribute.HighConfidence Varist: W64/ABRisk.SCDW-7205 ViRobot: Trojan.Win.Z.Agent.1425408.CD Webroot: W32.Trojan.GenKD Yandex: Riskware.Agent!M3o8/zPudoY Zillya: Trojan.GameHack.Win64.600 alibabacloud: Trojan:Win/GameHack.690d4d02 |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 2023-Mar-11 14:46:52 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xaf600 |
SizeOfInitializedData | 0xaee00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000007C194 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x164000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
---|---|
d3dx9_43.dll |
D3DXMatrixTranspose
|
dwmapi.dll |
DwmExtendFrameIntoClientArea
|
USER32.dll |
FindWindowA
GetKeyState ScreenToClient GetCapture ClientToScreen TrackMouseEvent SetCapture SetCursor GetClientRect ReleaseCapture SetCursorPos GetCursorPos OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData DispatchMessageA LoadCursorA SetWindowPos ShowWindow GetAsyncKeyState SetWindowLongA GetForegroundWindow MoveWindow DefWindowProcA CreateWindowExA SetLayeredWindowAttributes TranslateMessage LoadIconA PeekMessageA UnregisterClassA PostQuitMessage RegisterClassExA UpdateWindow GetWindowThreadProcessId GetWindowRect |
KERNEL32.dll |
HeapReAlloc
CreateProcessW GetExitCodeProcess WaitForSingleObject ReadConsoleW EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW HeapAlloc HeapFree GetConsoleMode GetConsoleOutputCP FlushFileBuffers GetFileType SetFilePointerEx GetFileSizeEx GetCommandLineW GetCommandLineA WriteFile GetStdHandle GetModuleFileNameW ExitProcess ReadFile GetModuleHandleExW FreeLibraryAndExitThread ExitThread CreateThread RtlUnwind LoadLibraryExW TlsFree TlsSetValue WriteProcessMemory ReadProcessMemory GetModuleFileNameA SetConsoleTitleA GetCurrentProcess GetTickCount64 K32GetModuleBaseNameA Process32First Module32Next Module32First OpenProcess CreateToolhelp32Snapshot Process32Next CloseHandle VirtualProtectEx GetModuleHandleA MultiByteToWideChar GlobalAlloc GlobalFree GlobalLock WideCharToMultiByte GlobalUnlock LoadLibraryA QueryPerformanceFrequency GetProcAddress FreeLibrary QueryPerformanceCounter GetCurrentDirectoryW CreateDirectoryW CreateFileW FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesExW IsValidCodePage AreFileApisANSI GetLastError GetModuleHandleW MoveFileExW GetFileInformationByHandleEx LocalFree FormatMessageA GetLocaleInfoEx WaitForSingleObjectEx Sleep GetCurrentThreadId FlsAlloc FlsGetValue FlsSetValue FlsFree SetEndOfFile InitializeCriticalSectionEx GetSystemTimeAsFileTime EnterCriticalSection LeaveCriticalSection DeleteCriticalSection EncodePointer DecodePointer LCMapStringEx GetStringTypeW GetCPInfo InitializeCriticalSectionAndSpinCount SetEvent ResetEvent CreateEventW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW GetCurrentProcessId InitializeSListHead TlsGetValue GetACP GetOEMCP GetEnvironmentStringsW FreeEnvironmentStringsW GetProcessHeap SetEnvironmentVariableW SetStdHandle HeapSize WriteConsoleW RtlUnwindEx RtlPcToFileHeader RaiseException SetLastError TlsAlloc |
IMM32.dll |
ImmReleaseContext
ImmSetCompositionWindow ImmSetCandidateWindow ImmAssociateContextEx ImmGetContext |
D3DCOMPILER_43.dll |
D3DCompile
|
Characteristics |
0
|
---|---|
TimeDateStamp | 2023-Mar-11 14:46:52 |
Version | 0.0 |
SizeofData | 1008 |
AddressOfRawData | 0x1463d4 |
PointerToRawData | 0x144dd4 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2023-Mar-11 14:46:52 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x1401467e8 |
---|---|
EndAddressOfRawData | 0x1401467f0 |
AddressOfIndex | 0x1401568e8 |
AddressOfCallbacks | 0x1400b1800 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x140 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140154060 |
XOR Key | 0xaebf3c76 |
---|---|
Unmarked objects | 0 |
ASM objects (29395) | 23 |
C++ objects (29395) | 190 |
C objects (29395) | 27 |
C objects (VS2022 Update 4 (17.4.2) compiler 31935) | 18 |
ASM objects (VS2022 Update 4 (17.4.2) compiler 31935) | 10 |
Imports (29395) | 10 |
Imports (21202) | 7 |
Total imports | 237 |
C++ objects (VS2022 Update 4 (17.4.2) compiler 31935) | 92 |
C++ objects (LTCG) (VS2022 Update 5 (17.5.0-2) compiler 32215) | 17 |
Resource objects (VS2022 Update 5 (17.5.0-2) compiler 32215) | 1 |
Linker (VS2022 Update 5 (17.5.0-2) compiler 32215) | 1 |