| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Jun-07 00:26:12 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish Uses constants related to RC5 or RC6 Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x130 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Jun-07 00:26:12 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x44c400 |
| SizeOfInitializedData | 0x215800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000040C068 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x667000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3dx9_43.dll |
D3DXCreateTextureFromFileInMemoryEx
|
|---|---|
| WS2_32.dll |
WSACleanup
WSAStartup ntohs socket htons recv setsockopt WSASetLastError WSAGetLastError closesocket WSAWaitForMultipleEvents WSAResetEvent WSAEventSelect WSAEnumNetworkEvents WSACreateEvent WSACloseEvent send getsockopt accept WSAIoctl __WSAFDIsSet bind connect getpeername select shutdown getservbyname getservbyport gethostbyaddr inet_ntoa inet_addr gethostbyname gethostname ioctlsocket sendto recvfrom freeaddrinfo getaddrinfo listen htonl getsockname |
| CRYPT32.dll |
CertFreeCTLContext
CertFindExtension CertGetNameStringW CryptQueryObject CertGetCertificateContextProperty CertFreeCertificateChainEngine CertGetCertificateChain CertFreeCertificateChain CertDuplicateCertificateContext CertCreateCertificateChainEngine CertAddCertificateContextToStore CertOpenSystemStoreW CertOpenStore CertCloseStore CertEnumCertificatesInStore CertFindCertificateInStore CertFreeCertificateContext CryptStringToBinaryW PFXImportCertStore CryptDecodeObjectEx CertFreeCRLContext |
| Secur32.dll |
InitSecurityInterfaceW
|
| ADVAPI32.dll |
OpenSCManagerA
RegOpenKeyExW RegQueryValueExW OpenProcessToken GetTokenInformation GetUserNameA RegOpenKeyExA RegQueryValueExA CloseServiceHandle EnumServicesStatusA ConvertSidToStringSidA CryptEnumProvidersW CryptSignHashW CryptDecrypt CryptExportKey CryptGetUserKey CryptGetProvParam CryptSetHashParam CryptGenRandom ReportEventW RegisterEventSourceW DeregisterEventSource CryptEncrypt CryptImportKey CryptDestroyKey CryptDestroyHash CryptHashData CryptCreateHash CryptGetHashParam CryptReleaseContext CryptAcquireContextW RegCloseKey |
| IPHLPAPI.DLL |
GetAdaptersInfo
if_nametoindex |
| KERNEL32.dll |
ExitProcess
GetConsoleCP GetDriveTypeW SystemTimeToTzSpecificLocalTime FileTimeToSystemTime GetConsoleOutputCP SetFilePointerEx GetCommandLineA GetCommandLineW HeapFree HeapAlloc FlsAlloc FlsGetValue FlsSetValue FlsFree ExitThread GetTimeFormatW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW FlushFileBuffers GetExitCodeProcess CreateProcessW GetTimeZoneInformation ReadConsoleInputW HeapReAlloc SetStdHandle SetEndOfFile FreeLibraryAndExitThread GetDateFormatW CreateFileW CloseHandle DeviceIoControl CreateToolhelp32Snapshot Process32FirstW Process32NextW GlobalAlloc GlobalUnlock GlobalLock GlobalFree MultiByteToWideChar WideCharToMultiByte VerSetConditionMask QueryPerformanceCounter QueryPerformanceFrequency FreeLibrary GetModuleHandleA GetProcAddress LoadLibraryA IsDebuggerPresent GetCurrentProcessId GetCurrentThreadId VirtualAlloc VirtualFree SetUnhandledExceptionFilter GetLastError GetCurrentProcess GetSystemDirectoryW VirtualQuery CreateFileMappingW MapViewOfFile UnmapViewOfFile K32GetModuleInformation GetModuleFileNameW GetStdHandle GetEnvironmentVariableA CreateDirectoryA DeleteFileA GetFileAttributesA SetFileAttributesA GetVolumeInformationA CreateMutexA Sleep IsValidCodePage CreateThread GetCurrentThread SetThreadPriority SetPriorityClass OpenProcess GlobalMemoryStatusEx GetSystemInfo GetSystemTime GetLocalTime GetTickCount GetTickCount64 GetWindowsDirectoryA GetNativeSystemInfo VirtualProtect GetModuleFileNameA GetModuleHandleW GlobalSize LocalAlloc LocalFree QueryFullProcessImageNameA GetComputerNameA FreeConsole GetConsoleMode SetConsoleMode SetConsoleCtrlHandler SetConsoleCP SetConsoleOutputCP GetConsoleCursorInfo SetConsoleCursorInfo GetConsoleScreenBufferInfo SetConsoleTextAttribute SetConsoleTitleA SetCurrentConsoleFontEx GetConsoleWindow ReleaseSRWLockExclusive AcquireSRWLockExclusive SetLastError EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection FormatMessageW SleepEx GetFullPathNameW MoveFileExW WaitForSingleObjectEx GetFileType ReadFile PeekNamedPipe WaitForMultipleObjects VerifyVersionInfoW GetFileSizeEx WriteFile RtlVirtualUnwind InitializeSRWLock ReleaseSRWLockShared AcquireSRWLockShared TlsAlloc TlsGetValue TlsSetValue TlsFree GetModuleHandleExW GetSystemTimeAsFileTime GetEnvironmentVariableW GetACP RtlUnwind ReleaseSemaphore WaitForSingleObject GetExitCodeThread CreateSemaphoreA GetSystemDirectoryA FormatMessageA LoadLibraryW SystemTimeToFileTime FindClose FindFirstFileW FindNextFileW ReadConsoleA ReadConsoleW DeleteFileW LoadLibraryExW InitializeCriticalSectionAndSpinCount RtlUnwindEx RaiseException RtlPcToFileHeader InitializeSListHead GetStartupInfoW IsProcessorFeaturePresent UnhandledExceptionFilter GetCPInfo GetStringTypeW WakeAllConditionVariable LCMapStringEx DecodePointer EncodePointer GetFileInformationByHandleEx AreFileApisANSI SetFileInformationByHandle GetFileInformationByHandle GetFileAttributesExW GetOEMCP GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW FindFirstFileExW CreateDirectoryW GetCurrentDirectoryW GetProcessHeap WriteConsoleW HeapSize TerminateProcess InitializeCriticalSection InitOnceComplete InitOnceBeginInitialize GetLocaleInfoEx SleepConditionVariableSRW TryAcquireSRWLockExclusive |
| USER32.dll |
OpenClipboard
CloseClipboard SetClipboardData GetClipboardData EmptyClipboard GetSystemMetrics GetKeyState GetForegroundWindow SetCursorPos SetCursor GetCursorPos ClientToScreen ScreenToClient LoadCursorW SendMessageW IsWindow DestroyWindow ShowWindow SetWindowPos GetClientRect IsWindowVisible MessageBoxW GetUserObjectInformationW GetProcessWindowStation EnumDisplayMonitors GetMonitorInfoA LoadIconW GetWindow GetWindowThreadProcessId EnumWindows GetDesktopWindow SetWindowLongPtrW GetWindowLongPtrW MessageBoxA GetWindowRect GetLastInputInfo |
| SHELL32.dll |
ShellExecuteA
|
| ole32.dll |
GetHGlobalFromStream
CreateStreamOnHGlobal |
| d3d9.dll |
Direct3DCreate9Ex
|
| IMM32.dll |
ImmGetContext
ImmReleaseContext ImmAssociateContextEx ImmSetCompositionWindow ImmSetCandidateWindow |
| ntdll.dll |
RtlCaptureContext
RtlLookupFunctionEntry |
| WININET.dll |
InternetOpenA
InternetCloseHandle InternetOpenUrlA InternetReadFile HttpQueryInfoA |
| gdiplus.dll |
GdipAlloc
GdipGetImageEncodersSize GdiplusStartup GdiplusShutdown GdipFree GdipGetImageEncoders GdipCloneImage GdipCreateBitmapFromHBITMAP GdipSaveImageToStream GdipDisposeImage |
| bcrypt.dll |
BCryptGenRandom
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-07 00:26:12 |
| Version | 0.0 |
| SizeofData | 1068 |
| AddressOfRawData | 0x58f598 |
| PointerToRawData | 0x58dd98 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-07 00:26:12 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x14058fa10 |
|---|---|
| EndAddressOfRawData | 0x140593074 |
| AddressOfIndex | 0x140620330 |
| AddressOfCallbacks | 0x14044eea0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14060f780 |
| XOR Key | 0xf7b78766 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 211 |
| C objects (33145) | 45 |
| ASM objects (33145) | 25 |
| 253 (35207) | 3 |
| C objects (35207) | 19 |
| ASM objects (35207) | 12 |
| C++ objects (35207) | 100 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 2 |
| Imports (33145) | 32 |
| Unmarked objects (#2) | 42 |
| C objects (35223) | 970 |
| Imports (21202) | 3 |
| Total imports | 412 |
| C++ objects (35223) | 18 |
| Resource objects (35223) | 1 |
| Linker (35223) | 1 |
No comments yet.