| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Mar-13 11:01:32 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\Admin\Downloads\yuki-external\yuki-external\x64\Release\owo.pdb
|
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 18/70 (Scanned on 2026-03-13 11:15:02) |
ALYac:
Gen:Variant.Application.Tedy.17879
APEX: Malicious Arcabit: Trojan.Application.Tedy.D45D7 BitDefender: Gen:Variant.Application.Tedy.17879 Bkav: W64.AIDetectMalware CTX: exe.unknown.tedy CrowdStrike: win/malicious_confidence_90% (D) ESET-NOD32: Win64/GameHack_AGen.ALH potentially unsafe application Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Application.Tedy.17879 (B) GData: Gen:Variant.Application.Tedy.17879 Google: Detected Ikarus: Trojan.Win64.Krypt McAfeeD: ti!A069957A4546 MicroWorld-eScan: Gen:Variant.Application.Tedy.17879 Microsoft: Trojan:Win32/Wacatac.B!ml Rising: Trojan.Kryptik@AI.98 (RDML:5fiArCep/YFf8+zaDkN7yw) VIPRE: Gen:Variant.Application.Tedy.17879 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Mar-13 11:01:32 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x72800 |
| SizeOfInitializedData | 0x1d400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000071898 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x94000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
Module32First
OpenProcess CreateToolhelp32Snapshot Process32Next CloseHandle MultiByteToWideChar GlobalAlloc GlobalFree GlobalLock WideCharToMultiByte GlobalUnlock GetLocaleInfoA LoadLibraryA QueryPerformanceFrequency GetProcAddress VerSetConditionMask FreeLibrary QueryPerformanceCounter InitializeSListHead GetSystemTimeAsFileTime GetCurrentProcessId IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess GetCurrentProcess SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext WakeAllConditionVariable GetCurrentThreadId SleepConditionVariableSRW Module32Next AcquireSRWLockExclusive ReleaseSRWLockExclusive GetFileInformationByHandleEx GetModuleHandleW GetLastError AreFileApisANSI GetFileAttributesExW FindNextFileW FindFirstFileExW FindFirstFileW FindClose CreateFileW CreateDirectoryW Process32First GetPrivateProfileStringA GetPrivateProfileIntA GetConsoleWindow GetLocaleInfoEx FormatMessageA LocalFree WritePrivateProfileStringA GetCurrentThread GetProcessId Sleep GetModuleHandleA SetThreadPriority |
|---|---|
| USER32.dll |
ScreenToClient
GetMessageExtraInfo GetSystemMetrics UnregisterClassW RegisterClassExW LoadCursorA GetDC GetCapture ShowWindow ClientToScreen TrackMouseEvent GetKeyboardLayout SetCapture SetCursor GetClientRect SetProcessDPIAware IsWindowUnicode ReleaseCapture CreateWindowExW ReleaseDC OpenClipboard DestroyWindow CloseClipboard DispatchMessageA SendInput EmptyClipboard GetCursorPos MonitorFromPoint SetCursorPos DefWindowProcW UpdateWindow GetClipboardData SetClipboardData FindWindowA GetKeyNameTextA PostQuitMessage PeekMessageA TranslateMessage SetLayeredWindowAttributes GetAsyncKeyState GetForegroundWindow MapVirtualKeyA GetWindowLongA GetWindowTextA SetWindowLongA GetKeyState |
| GDI32.dll |
GetDeviceCaps
|
| SHELL32.dll |
ShellExecuteW
|
| MSVCP140.dll |
?_Xinvalid_argument@std@@YAXPEBD@Z
?_Id_cnt@id@locale@std@@0HA ?_Xout_of_range@std@@YAXPEBD@Z ?_Winerror_map@std@@YAHH@Z ?_Xlength_error@std@@YAXPEBD@Z ?_Syserror_map@std@@YAPEBDH@Z _Cnd_do_broadcast_at_thread_exit _Query_perf_counter _Thrd_detach _Xtime_get_ticks ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?_Getcat@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ?put@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@QEBA?AV?$ostreambuf_iterator@DU?$char_traits@D@std@@@2@V32@AEAVios_base@2@DPEBUtm@@PEBD3@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ?get@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAHXZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ ?good@ios_base@std@@QEBA_NXZ _Query_perf_frequency ??1_Lockit@std@@QEAA@XZ ?_Xbad_alloc@std@@YAXXZ ??0_Lockit@std@@QEAA@H@Z ?_Throw_Cpp_error@std@@YAXH@Z ?id@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@2V0locale@2@A ?uncaught_exceptions@std@@YAHXZ ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| IMM32.dll |
ImmReleaseContext
ImmSetCandidateWindow ImmGetContext ImmSetCompositionWindow |
| D3DCOMPILER_47.dll |
D3DCompile
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
memmove
__std_exception_destroy __std_exception_copy __std_terminate strstr strchr memcmp memchr memcpy memset __C_specific_handler __current_exception __current_exception_context _CxxThrowException |
| api-ms-win-crt-runtime-l1-1-0.dll |
_register_thread_local_exe_atexit_callback
_c_exit __p___argv __p___argc _exit _initterm_e _initterm _get_initial_narrow_environment _set_app_type _seh_filter_exe _cexit _crt_atexit _initialize_onexit_table _initialize_narrow_environment _configure_narrow_argv abort _errno terminate _beginthreadex _invoke_watson exit _register_onexit_function |
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
free malloc _set_new_mode |
| api-ms-win-crt-convert-l1-1-0.dll |
strtof
atof |
| api-ms-win-crt-time-l1-1-0.dll |
_localtime64_s
|
| api-ms-win-crt-string-l1-1-0.dll |
strcpy_s
strncmp tolower _stricmp strncpy strcmp |
| api-ms-win-crt-utility-l1-1-0.dll |
rand
qsort |
| api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vfprintf
__p__commode _set_fmode __stdio_common_vsprintf_s __stdio_common_vsprintf __stdio_common_vsscanf fread _wfopen fwrite __acrt_iob_func ftell fseek fclose fflush |
| api-ms-win-crt-environment-l1-1-0.dll |
_dupenv_s
|
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
___lc_codepage_func |
| api-ms-win-crt-math-l1-1-0.dll |
acosf
sinf fmodf cosf atan2f floorf powf sqrtf logf ceilf __setusermatherr |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-13 11:01:32 |
| Version | 0.0 |
| SizeofData | 97 |
| AddressOfRawData | 0x7fdc8 |
| PointerToRawData | 0x7e9c8 |
| Referenced File | C:\Users\Admin\Downloads\yuki-external\yuki-external\x64\Release\owo.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-13 11:01:32 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x7fe2c |
| PointerToRawData | 0x7ea2c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-13 11:01:32 |
| Version | 0.0 |
| SizeofData | 912 |
| AddressOfRawData | 0x7fe40 |
| PointerToRawData | 0x7ea40 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-13 11:01:32 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1400801f0 |
|---|---|
| EndAddressOfRawData | 0x1400801f8 |
| AddressOfIndex | 0x14008bcc8 |
| AddressOfCallbacks | 0x1400748f0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14008b040 |
| XOR Key | 0xafdd0b59 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 20 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 35 |
| Imports (35207) | 6 |
| Imports (33145) | 17 |
| Total imports | 301 |
| C++ objects (LTCG) (35224) | 9 |
| ASM objects (35224) | 1 |
| Resource objects (35224) | 1 |
| Linker (35224) | 1 |
No comments yet.