| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jun-01 00:59:32 |
| Detected languages |
English - United States
|
| TLS Callbacks | 2 callback(s) detected. |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 5/71 (Scanned on 2026-06-01 12:17:13) |
Cylance:
Unsafe
Cynet: Malicious (score: 100) Elastic: malicious (moderate confidence) Microsoft: Program:Win32/Wacapew.C!ml VBA32: suspected of Trojan.Downloader.gen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Jun-01 00:59:32 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x79200 |
| SizeOfInitializedData | 0x23e00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00055FE0 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x7b000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xa2000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d9.dll |
Direct3DCreate9
|
|---|---|
| USER32.dll |
wsprintfA
MessageBoxA CallWindowProcA PostMessageA MapVirtualKeyA GetAsyncKeyState OpenClipboard CloseClipboard SetClipboardData GetClipboardData EmptyClipboard GetKeyboardLayout TrackMouseEvent GetMessageExtraInfo GetKeyState GetForegroundWindow SetWindowLongA GetCapture SetCapture SetCursor ReleaseCapture LoadCursorA ScreenToClient ClientToScreen GetCursorPos IsWindowUnicode SetCursorPos GetClientRect GetDesktopWindow |
| KERNEL32.dll |
GetACP
IsValidCodePage FindNextFileW FindFirstFileExW FindClose GetFileSizeEx SetFilePointerEx ReadConsoleW LCMapStringW LoadLibraryExW GetConsoleMode GetConsoleOutputCP GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW GetEnvironmentVariableA DeleteFileA CloseHandle Sleep CreateThread DisableThreadLibraryCalls GetModuleHandleA GetTickCount64 CreateFileA ReadFile WaitForSingleObject GetTickCount GetCurrentProcess GetCurrentThreadId K32GetModuleInformation VirtualQuery VirtualQueryEx FlushFileBuffers WriteFile AddVectoredExceptionHandler VirtualProtect CreateDirectoryA OutputDebugStringA SetUnhandledExceptionFilter GetLastError GetEnvironmentStringsW ExitProcess TerminateProcess GetLocalTime GetModuleFileNameA GetModuleHandleExA GetProcAddress QueryFullProcessImageNameA MapViewOfFile UnmapViewOfFile CreateFileMappingA GetVolumeInformationA GlobalAlloc GlobalUnlock GlobalLock GlobalFree MultiByteToWideChar WideCharToMultiByte QueryPerformanceCounter QueryPerformanceFrequency FreeLibrary LoadLibraryA GetLocaleInfoA VirtualAlloc VirtualFree HeapCreate HeapDestroy HeapAlloc HeapReAlloc HeapFree OpenThread SuspendThread ResumeThread GetThreadContext SetThreadContext FlushInstructionCache GetModuleHandleW CreateToolhelp32Snapshot WriteConsoleW Thread32Next DecodePointer FreeEnvironmentStringsW GetProcessHeap CreateFileW GetStringTypeW GetStdHandle UnhandledExceptionFilter IsDebuggerPresent GetModuleFileNameW GetModuleHandleExW GetFileType SetStdHandle DeleteCriticalSection InitializeCriticalSectionEx LeaveCriticalSection EnterCriticalSection EncodePointer FlsFree FlsSetValue FlsGetValue HeapSize SetEndOfFile GetCurrentProcessId Thread32First FlsAlloc SetLastError InterlockedFlushSList IsProcessorFeaturePresent ReleaseSRWLockExclusive AcquireSRWLockExclusive GetStartupInfoW GetSystemTimeAsFileTime InitializeSListHead TryAcquireSRWLockExclusive GetSystemTimePreciseAsFileTime RaiseException RtlUnwind |
| ADVAPI32.dll |
RegOpenKeyExA
RegQueryValueExA RegSetValueExA RegCloseKey RegCreateKeyExA |
| WINMM.dll |
timeBeginPeriod
|
| dbghelp.dll |
MiniDumpWriteDump
|
| WINHTTP.dll |
WinHttpReceiveResponse
WinHttpSendRequest WinHttpCrackUrl WinHttpOpen WinHttpCloseHandle WinHttpConnect WinHttpReadData WinHttpQueryDataAvailable WinHttpSetOption WinHttpSetTimeouts WinHttpOpenRequest |
| IMM32.dll |
ImmSetCandidateWindow
ImmReleaseContext ImmSetCompositionWindow ImmGetContext |
| Ordinal | 1 |
|---|---|
| Address | 0x1f00 |
| Ordinal | 2 |
|---|---|
| Address | 0x1f00 |
| Ordinal | 3 |
|---|---|
| Address | 0x1f00 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-01 00:59:32 |
| Version | 0.0 |
| SizeofData | 980 |
| AddressOfRawData | 0x9404c |
| PointerToRawData | 0x9264c |
| StartAddressOfRawData | 0x10094430 |
|---|---|
| EndAddressOfRawData | 0x10094568 |
| AddressOfIndex | 0x1009a01c |
| AddressOfCallbacks | 0x1007b344 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x100557C0
0x100556D0 |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x10098c40 |
| SEHandlerTable | 0x10093e2c |
| SEHandlerCount | 88 |
| XOR Key | 0xb46e65f2 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (33145) | 35 |
| C++ objects (33145) | 164 |
| C objects (33145) | 25 |
| ASM objects (35721) | 24 |
| C objects (35721) | 15 |
| C++ objects (35721) | 45 |
| Imports (33145) | 21 |
| Total imports | 202 |
| C++ objects (36246) | 26 |
| C objects (36246) | 4 |
| Exports (36246) | 1 |
| Resource objects (36246) | 1 |
| Linker (36246) | 1 |
No comments yet.