| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Feb-12 16:27:03 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to internet browsers:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish Uses constants related to RC5 or RC6 Uses known Diffie-Helman primes Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .fptable
Unusual section name found: .odinti |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x78 |
| e_cp | 0x1 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0 |
| e_ss | 0 |
| e_sp | 0 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x78 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 9 |
| TimeDateStamp | 2026-Feb-12 16:27:03 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x3f8e00 |
| SizeOfInitializedData | 0x1d5800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000003C6A7C (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xbac000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| USER32.dll |
BeginPaint
CloseClipboard CreateWindowExA CreateWindowExW DefWindowProcA DefWindowProcW DestroyWindow DispatchMessageW DrawTextW EndPaint EnumChildWindows EnumWindows FillRect FindWindowExA GetAsyncKeyState GetClientRect GetClipboardData GetClipboardSequenceNumber GetCursorPos GetDesktopWindow GetMessageW GetProcessWindowStation GetRawInputData GetSystemMetrics GetUserObjectInformationW GetWindowLongA GetWindowLongPtrA GetWindowLongPtrW GetWindowLongW GetWindowPlacement GetWindowRect GetWindowTextW GetWindowThreadProcessId InvalidateRect LoadCursorA LoadIconA MessageBoxW OpenClipboard PeekMessageW PostMessageW PostQuitMessage RegisterClassA RegisterClassExW RegisterRawInputDevices SetActiveWindow SetFocus SetLayeredWindowAttributes SetParent SetWindowLongA SetWindowLongPtrA SetWindowLongPtrW SetWindowLongW SetWindowPos SetWindowTextW ShowWindow TranslateMessage UpdateWindow |
|---|---|
| WS2_32.dll |
WSACleanup
WSAGetLastError WSAIoctl WSASetLastError WSAStartup __WSAFDIsSet accept bind closesocket connect freeaddrinfo getaddrinfo gethostbyaddr gethostbyname gethostname getnameinfo getpeername getservbyname getservbyport getsockname getsockopt htonl htons inet_addr inet_ntoa inet_ntop ioctlsocket listen ntohl ntohs recv recvfrom select send sendto setsockopt shutdown socket |
| GDI32.dll |
CreateFontW
CreateSolidBrush DeleteObject SelectObject SetBkMode SetTextColor |
| ADVAPI32.dll |
CryptAcquireContextW
CryptGenRandom CryptReleaseContext DeregisterEventSource RegCloseKey RegEnumKeyW RegGetValueW RegOpenKeyExW RegQueryValueExW RegisterEventSourceW ReportEventW |
| SHELL32.dll |
CommandLineToArgvW
ShellExecuteA |
| KERNEL32.dll |
AcquireSRWLockExclusive
AcquireSRWLockShared CloseHandle CompareStringW ConvertFiberToThread ConvertThreadToFiberEx CopyFileW CreateDirectoryW CreateEventA CreateFiberEx CreateFileA CreateFileW CreatePipe CreateProcessA CreateProcessW CreateSemaphoreA CreateThread CreateToolhelp32Snapshot DeleteCriticalSection DeleteFiber DeleteFileW DuplicateHandle EncodePointer EnterCriticalSection ExitProcess ExitThread ExpandEnvironmentStringsA FileTimeToSystemTime FindClose FindFirstFileExW FindFirstFileW FindNextFileW FlsAlloc FlsFree FlsGetValue FlsSetValue FlushFileBuffers FormatMessageA FreeEnvironmentStringsW FreeLibrary FreeLibraryAndExitThread GetACP GetCPInfo GetCommandLineA GetCommandLineW GetConsoleMode GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetDateFormatW GetDriveTypeW GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetExitCodeThread GetFileAttributesA GetFileAttributesExW GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFileSizeEx GetFileType GetFinalPathNameByHandleW GetFullPathNameW GetLastError GetLogicalProcessorInformation GetLongPathNameW GetModuleFileNameW GetModuleHandleA GetModuleHandleExW GetModuleHandleW GetOEMCP GetProcAddress GetProcessHeap GetProcessTimes GetProductInfo GetStartupInfoW GetStdHandle GetStringTypeW GetSystemDirectoryA GetSystemInfo GetSystemTime GetSystemTimeAsFileTime GetSystemTimePreciseAsFileTime GetThreadTimes GetTimeFormatW GetTimeZoneInformation GetVersion GlobalLock GlobalMemoryStatusEx GlobalUnlock HeapAlloc HeapFree HeapReAlloc HeapSize InitializeConditionVariable InitializeCriticalSection InitializeCriticalSectionEx InitializeSListHead InitializeSRWLock IsDebuggerPresent IsProcessorFeaturePresent IsValidCodePage IsWow64Process LCMapStringW LeaveCriticalSection LoadLibraryA LoadLibraryExW LoadLibraryW LockFileEx MoveFileExW MultiByteToWideChar OpenProcess OutputDebugStringW PeekNamedPipe Process32First Process32Next QueryPerformanceCounter QueryPerformanceFrequency RaiseException ReadConsoleA ReadConsoleW ReadDirectoryChangesW ReadFile ReleaseSRWLockExclusive ReleaseSRWLockShared ReleaseSemaphore RemoveDirectoryW ResumeThread RtlCaptureContext RtlLookupFunctionEntry RtlPcToFileHeader RtlUnwind RtlUnwindEx RtlVirtualUnwind SetConsoleCtrlHandler SetConsoleMode SetEndOfFile SetEnvironmentVariableA SetEnvironmentVariableW SetEvent SetFileAttributesW SetFilePointer SetFilePointerEx SetHandleInformation SetLastError SetStdHandle SetThreadPriority SetUnhandledExceptionFilter Sleep SleepConditionVariableCS SwitchToFiber SystemTimeToFileTime SystemTimeToTzSpecificLocalTime TerminateProcess TerminateThread TlsAlloc TlsFree TlsGetValue TlsSetValue UnhandledExceptionFilter VirtualFree VirtualProtect WaitForSingleObject WakeConditionVariable WideCharToMultiByte WriteConsoleW WriteFile |
| bcrypt.dll |
BCryptGenRandom
|
| ntdll.dll |
RtlGetVersion
RtlNtStatusToDosError RtlWaitOnAddress |
| DNSAPI.dll |
DnsQuery_UTF8
DnsRecordListFree |
| ole32.dll |
CoInitializeEx
CoTaskMemFree CoUninitialize |
| CRYPT32.dll |
CertCloseStore
CertFindCertificateInStore CertFreeCertificateContext CertOpenSystemStoreW |
| Ordinal | 1 |
|---|---|
| Address | 0x173520 |
| Ordinal | 2 |
|---|---|
| Address | 0x173f00 |
| Ordinal | 3 |
|---|---|
| Address | 0x176060 |
| Ordinal | 4 |
|---|---|
| Address | 0x173fb0 |
| Ordinal | 5 |
|---|---|
| Address | 0x174190 |
| Ordinal | 6 |
|---|---|
| Address | 0x174e20 |
| Ordinal | 7 |
|---|---|
| Address | 0x176080 |
| Ordinal | 8 |
|---|---|
| Address | 0x1760e0 |
| Ordinal | 9 |
|---|---|
| Address | 0x174240 |
| Ordinal | 10 |
|---|---|
| Address | 0x174d70 |
| Ordinal | 11 |
|---|---|
| Address | 0x174500 |
| Ordinal | 12 |
|---|---|
| Address | 0x174ed0 |
| Ordinal | 13 |
|---|---|
| Address | 0x173800 |
| Ordinal | 14 |
|---|---|
| Address | 0x177140 |
| Ordinal | 15 |
|---|---|
| Address | 0x1770b0 |
| Ordinal | 16 |
|---|---|
| Address | 0x1761f0 |
| Ordinal | 17 |
|---|---|
| Address | 0x173760 |
| Ordinal | 18 |
|---|---|
| Address | 0x176dd0 |
| Ordinal | 19 |
|---|---|
| Address | 0x176f80 |
| Ordinal | 20 |
|---|---|
| Address | 0x176f00 |
| Ordinal | 21 |
|---|---|
| Address | 0x176480 |
| Ordinal | 22 |
|---|---|
| Address | 0x176380 |
| Ordinal | 23 |
|---|---|
| Address | 0x176ee0 |
| Ordinal | 24 |
|---|---|
| Address | 0x176e60 |
| Ordinal | 25 |
|---|---|
| Address | 0x1776f0 |
| Ordinal | 26 |
|---|---|
| Address | 0x1776e0 |
| Ordinal | 27 |
|---|---|
| Address | 0x176740 |
| Ordinal | 28 |
|---|---|
| Address | 0x173460 |
| Ordinal | 29 |
|---|---|
| Address | 0x176190 |
| Ordinal | 30 |
|---|---|
| Address | 0x1763a0 |
| Ordinal | 31 |
|---|---|
| Address | 0x177210 |
| Ordinal | 32 |
|---|---|
| Address | 0x177160 |
| Ordinal | 33 |
|---|---|
| Address | 0x177090 |
| Ordinal | 34 |
|---|---|
| Address | 0x176fa0 |
| Ordinal | 35 |
|---|---|
| Address | 0x175cb0 |
| Ordinal | 36 |
|---|---|
| Address | 0x177700 |
| Ordinal | 37 |
|---|---|
| Address | 0x177d50 |
| Ordinal | 38 |
|---|---|
| Address | 0x177b60 |
| Ordinal | 39 |
|---|---|
| Address | 0x177ad0 |
| Ordinal | 40 |
|---|---|
| Address | 0x177a40 |
| Ordinal | 41 |
|---|---|
| Address | 0x177bf0 |
| Ordinal | 42 |
|---|---|
| Address | 0x1779b0 |
| Ordinal | 43 |
|---|---|
| Address | 0x177950 |
| Ordinal | 44 |
|---|---|
| Address | 0x1778f0 |
| Ordinal | 45 |
|---|---|
| Address | 0x177ef0 |
| Ordinal | 46 |
|---|---|
| Address | 0x177fb0 |
| Ordinal | 47 |
|---|---|
| Address | 0x178070 |
| Ordinal | 48 |
|---|---|
| Address | 0x177e10 |
| Ordinal | 49 |
|---|---|
| Address | 0x1777d0 |
| Ordinal | 50 |
|---|---|
| Address | 0x174ae0 |
| Ordinal | 51 |
|---|---|
| Address | 0x177c80 |
| Ordinal | 52 |
|---|---|
| Address | 0x173e20 |
| Ordinal | 53 |
|---|---|
| Address | 0x174b90 |
| Ordinal | 54 |
|---|---|
| Address | 0x174f10 |
| Ordinal | 55 |
|---|---|
| Address | 0x174110 |
| Ordinal | 56 |
|---|---|
| Address | 0x174f50 |
| Ordinal | 57 |
|---|---|
| Address | 0x174090 |
| Ordinal | 58 |
|---|---|
| Address | 0x175e80 |
| Ordinal | 59 |
|---|---|
| Address | 0x175f90 |
| Ordinal | 60 |
|---|---|
| Address | 0x173260 |
| Ordinal | 61 |
|---|---|
| Address | 0x173280 |
| Ordinal | 62 |
|---|---|
| Address | 0x175de0 |
| Ordinal | 63 |
|---|---|
| Address | 0x1775b0 |
| Ordinal | 64 |
|---|---|
| Address | 0x177350 |
| Ordinal | 65 |
|---|---|
| Address | 0x177230 |
| Ordinal | 66 |
|---|---|
| Address | 0x177470 |
| Ordinal | 67 |
|---|---|
| Address | 0x1767c0 |
| Ordinal | 68 |
|---|---|
| Address | 0x176870 |
| Ordinal | 69 |
|---|---|
| Address | 0x176940 |
| Ordinal | 70 |
|---|---|
| Address | 0x176a70 |
| Ordinal | 71 |
|---|---|
| Address | 0x174fa0 |
| Ordinal | 72 |
|---|---|
| Address | 0x175190 |
| Ordinal | 73 |
|---|---|
| Address | 0x1747e0 |
| Ordinal | 74 |
|---|---|
| Address | 0x1758f0 |
| Ordinal | 75 |
|---|---|
| Address | 0x174950 |
| Ordinal | 76 |
|---|---|
| Address | 0x1764d0 |
| Ordinal | 77 |
|---|---|
| Address | 0x1736d0 |
| Ordinal | 78 |
|---|---|
| Address | 0x173c60 |
| Ordinal | 79 |
|---|---|
| Address | 0x174840 |
| Ordinal | 80 |
|---|---|
| Address | 0x1765f0 |
| Ordinal | 81 |
|---|---|
| Address | 0x1749c0 |
| Ordinal | 82 |
|---|---|
| Address | 0x174a50 |
| Ordinal | 83 |
|---|---|
| Address | 0x176660 |
| Ordinal | 84 |
|---|---|
| Address | 0x1753b0 |
| Ordinal | 85 |
|---|---|
| Address | 0x173d30 |
| Ordinal | 86 |
|---|---|
| Address | 0x174c40 |
| Ordinal | 87 |
|---|---|
| Address | 0x173bf0 |
| Ordinal | 88 |
|---|---|
| Address | 0x1764a0 |
| Ordinal | 89 |
|---|---|
| Address | 0x175620 |
| Ordinal | 90 |
|---|---|
| Address | 0x176400 |
| Ordinal | 91 |
|---|---|
| Address | 0x1756e0 |
| Ordinal | 92 |
|---|---|
| Address | 0x175a60 |
| Ordinal | 93 |
|---|---|
| Address | 0x175ba0 |
| Ordinal | 94 |
|---|---|
| Address | 0x175e10 |
| Ordinal | 95 |
|---|---|
| Address | 0x173db0 |
| Ordinal | 96 |
|---|---|
| Address | 0x1746a0 |
| Ordinal | 97 |
|---|---|
| Address | 0x176d30 |
| Ordinal | 98 |
|---|---|
| Address | 0x175420 |
| Ordinal | 99 |
|---|---|
| Address | 0x174bf0 |
| Ordinal | 100 |
|---|---|
| Address | 0x176770 |
| Ordinal | 101 |
|---|---|
| Address | 0x1766d0 |
| Ordinal | 102 |
|---|---|
| Address | 0x173860 |
| Ordinal | 103 |
|---|---|
| Address | 0x173990 |
| Ordinal | 104 |
|---|---|
| Address | 0x1738f0 |
| Ordinal | 105 |
|---|---|
| Address | 0x173b60 |
| Ordinal | 106 |
|---|---|
| Address | 0x173a90 |
| Ordinal | 107 |
|---|---|
| Address | 0x173f20 |
| Ordinal | 108 |
|---|---|
| Address | 0x173f60 |
| Ordinal | 109 |
|---|---|
| Address | 0x176250 |
| StartAddressOfRawData | 0x140b9a000 |
|---|---|
| EndAddressOfRawData | 0x140b9a628 |
| AddressOfIndex | 0x140b4e2f8 |
| AddressOfCallbacks | 0x14053cbd8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140571bc0 |