a792432cf2c59ef0dfcfccdb7b43e70133cb334c3eef7a63680e36fc48f3c7fd

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Jun-18 14:30:57
TLS Callbacks 3 callback(s) detected.

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Contains domain names:
  • .note.crashpad.info
  • RetroUSB.com
  • crashpad.info
  • devblogs.microsoft.com
  • https://devblogs.microsoft.com
  • https://devblogs.microsoft.com/pix/winpixeventruntime/
  • https://steamhistory.net
  • microsoft.com
  • note.crashpad.info
  • steamhistory.net
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • SwitchToThread
Code injection capabilities:
  • CreateRemoteThread
  • OpenProcess
  • VirtualAllocEx
  • WriteProcessMemory
Can access the registry:
  • RegCloseKey
  • RegOpenKeyExW
  • RegQueryValueExW
Possibly launches other programs:
  • CreateProcessA
  • CreateProcessW
  • ShellExecuteW
Uses functions commonly found in keyloggers:
  • AttachThreadInput
  • CallNextHookEx
  • GetAsyncKeyState
  • GetForegroundWindow
  • MapVirtualKeyW
Memory manipulation functions often used by packers:
  • VirtualAllocEx
  • VirtualProtect
  • VirtualProtectEx
Leverages the raw socket API to access the Internet:
  • inet_pton
Manipulates other processes:
  • OpenProcess
  • Process32First
  • Process32Next
  • ReadProcessMemory
  • WriteProcessMemory
Can take screenshots:
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 6/70 (Scanned on 2026-06-27 09:59:33) Antiy-AVL: RiskWare/Win64.Gamehack
ESET-NOD32: Win64/GameHack.XH potentially unsafe application
Microsoft: Trojan:Win32/Wacatac.B!ml
Sophos: Mal/Generic-S
Trapmine: malicious.high.ml.score
TrellixENS: Artemis!C31D2E7043ED

Hashes

MD5 c31d2e7043edf6328a6842de4c694214
SHA1 172813cf4c28e9b0bf98b42e78824e5b04fea271
SHA256 a792432cf2c59ef0dfcfccdb7b43e70133cb334c3eef7a63680e36fc48f3c7fd
SHA3 6a5d2672eec69925081ae8f53836c438b5b612c1712add3aa1c88ece791eedc4
SSDeep 98304:S14UeY75K910geuyubt1jsmUtws9lDi8iQm1AKR4BOjxyze5+Gw1ZH+4:SRFUP7jsNSJr+/L+
Imports Hash dfff736185d47402d01ca11d274fe975

DOS Header

e_magic MZ
e_cblp 0x78
e_cp 0x1
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x78

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jun-18 14:30:57
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x61b400
SizeOfInitializedData 0x3da600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000013D0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa0d000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 0841762b2f4fe0ad582566df6a44ae22
SHA1 b9e383dcd236ab0791517b7379b7875f362dbc80
SHA256 02812dc271a5b468d02eba36bc5846719e63ae73a248b323598ecd9d913b3264
SHA3 ca17bb239934f010c6d29e615538c6d00c95121f7ebb627badc4725907e0f6c8
VirtualSize 0x61b336
VirtualAddress 0x1000
SizeOfRawData 0x61b400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.49553

.rdata

MD5 c74e5125796aeb4958830a52ef0c7142
SHA1 9c02d345496f8633b08d22f1375e9c0383443e63
SHA256 a7321311eb3cdc546346094946ebd7c189e5f8145fd12c9d85f40a32803dca00
SHA3 4ac7ec301e3b46d0cb2f0aeda437e2f930edddf7056679855e277c2a57a690f9
VirtualSize 0x39c4b8
VirtualAddress 0x61d000
SizeOfRawData 0x39c600
PointerToRawData 0x61b800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.64155

.data

MD5 ccc28cf5c3e2b8a0376612b07eadea41
SHA1 ca409d8e2ca0e5900480a67a2babc4396e8622eb
SHA256 faed5ee8aa115384eb0db6a9f2f60866ceea49ad69779addc073cb64c3ee4b18
SHA3 7676123e232b3081c1817ef00755fca5d71fdfb72100a211b2ab91c5303568cf
VirtualSize 0x1d770
VirtualAddress 0x9ba000
SizeOfRawData 0xa600
PointerToRawData 0x9b7e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.41354

.pdata

MD5 8a1b49c27364811ce448607641a89b3f
SHA1 2934a51f4726eb04d5eef40e955a0ee0280572db
SHA256 5ec1ea3b1bacdaee8f9da013fa8426d9fe17b834735684593bb75fb144b6eb81
SHA3 df8aa9d9a0e0d47938fab41fb674c4f600ece8092bc16ce3857be9380839b735
VirtualSize 0x28bd8
VirtualAddress 0x9d8000
SizeOfRawData 0x28c00
PointerToRawData 0x9c2400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.43479

.tls

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x58
VirtualAddress 0xa01000
SizeOfRawData 0x200
PointerToRawData 0x9eb000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.reloc

MD5 b74bb56516bbd3d888959f9e3325b83c
SHA1 e9ee9ac8be1e16c1dc080ab376b4e07341ba1af4
SHA256 74515a8c90a42b7f4c09f46785c4aceafdc50d1045dcd32969d7c4e61da9d51b
SHA3 ee18a4cfb88da41a36e53eea05845eec9597c433265b24d69bd2ffe44449be09
VirtualSize 0xaa70
VirtualAddress 0xa02000
SizeOfRawData 0xac00
PointerToRawData 0x9eb200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.46055

Imports

KERNEL32.dll AcquireSRWLockExclusive
AddVectoredExceptionHandler
AttachConsole
CancelIo
CloseHandle
CompareStringA
CopyFileExW
CreateDirectoryW
CreateEventW
CreateFileA
CreateFileW
CreatePipe
CreateProcessA
CreateProcessW
CreateRemoteThread
CreateSemaphoreW
CreateThread
CreateToolhelp32Snapshot
DeleteCriticalSection
DeleteFileW
DeviceIoControl
DuplicateHandle
EnterCriticalSection
EnumResourceNamesW
ExitProcess
FileTimeToSystemTime
FindClose
FindFirstFileExW
FindFirstFileW
FindNextFileW
FlsAlloc
FlsGetValue
FlsSetValue
FlushFileBuffers
FormatMessageA
FormatMessageW
FreeEnvironmentStringsW
FreeLibrary
GenerateConsoleCtrlEvent
GetActiveProcessorCount
GetCommandLineW
GetConsoleMode
GetConsoleScreenBufferInfo
GetCurrentDirectoryW
GetCurrentProcess
GetCurrentProcessId
GetCurrentThread
GetCurrentThreadId
GetEnvironmentStringsW
GetEnvironmentVariableA
GetExitCodeProcess
GetFileAttributesA
GetFileAttributesExW
GetFileSizeEx
GetFileTime
GetFileType
GetLastError
GetLocaleInfoA
GetLocaleInfoW
GetLogicalDrives
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleExW
GetModuleHandleW
GetNumberOfConsoleInputEvents
GetOverlappedResult
GetProcAddress
GetProcessHeap
GetStdHandle
GetSystemInfo
GetSystemPowerStatus
GetSystemTimeAsFileTime
GetSystemTimePreciseAsFileTime
GetThreadId
GetTickCount
GlobalAlloc
GlobalFree
GlobalLock
GlobalMemoryStatusEx
GlobalSize
GlobalUnlock
HeapAlloc
HeapFree
InitOnceExecuteOnce
InitializeCriticalSection
InitializeCriticalSectionAndSpinCount
IsProcessorFeaturePresent
IsWow64Process
LeaveCriticalSection
LoadLibraryA
LoadLibraryExW
LoadLibraryW
LocalFree
Module32First
Module32Next
MoveFileExA
MoveFileExW
MulDiv
MultiByteToWideChar
OpenProcess
OpenThread
OutputDebugStringW
Process32First
Process32Next
QueryPerformanceCounter
QueryPerformanceFrequency
RaiseException
ReadConsoleInputW
ReadFile
ReadProcessMemory
ReleaseSRWLockExclusive
ReleaseSemaphore
RemoveDirectoryW
RemoveVectoredExceptionHandler
ResetEvent
ResumeThread
RtlCaptureContext
RtlLookupFunctionEntry
RtlRestoreContext
RtlUnwindEx
RtlVirtualUnwind
SetConsoleCP
SetConsoleMode
SetConsoleOutputCP
SetConsoleTextAttribute
SetConsoleTitleA
SetEnvironmentVariableA
SetErrorMode
SetEvent
SetFilePointer
SetFilePointerEx
SetHandleInformation
SetLastError
SetNamedPipeHandleState
SetThreadExecutionState
SetThreadPriority
SetUnhandledExceptionFilter
Sleep
SleepConditionVariableSRW
SuspendThread
SwitchToThread
SystemTimeToFileTime
SystemTimeToTzSpecificLocalTime
TerminateProcess
Thread32First
Thread32Next
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
TryAcquireSRWLockExclusive
TryEnterCriticalSection
VerSetConditionMask
VerifyVersionInfoW
VirtualAllocEx
VirtualFreeEx
VirtualProtect
VirtualProtectEx
VirtualQuery
WaitForMultipleObjects
WaitForSingleObject
WaitForSingleObjectEx
WakeAllConditionVariable
WakeConditionVariable
WideCharToMultiByte
WriteConsoleA
WriteConsoleW
WriteFile
WriteProcessMemory
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
__p__commode
__p__fmode
__stdio_common_vfprintf
__stdio_common_vfwprintf
__stdio_common_vsnprintf_s
__stdio_common_vsprintf
_close
_filelengthi64
_fileno
_fseeki64
_fsopen
_ftelli64
_fwrite_nolock
_get_osfhandle
_isatty
_open_osfhandle
_setmode
_sopen
_wfopen
_write
fclose
feof
ferror
fflush
fgetc
fgets
fgetwc
fopen
fputc
fputwc
fread
fseek
ftell
fwrite
getc
putchar
puts
setbuf
setvbuf
ungetc
ungetwc
api-ms-win-crt-runtime-l1-1-0.dll _assert
__p___argc
__p___argv
__sys_nerr
_beginthreadex
_cexit
_configure_narrow_argv
_crt_atexit
_endthreadex
_errno
_exit
_initialize_narrow_environment
_initterm
_initterm_e
_register_thread_local_exe_atexit_callback
_seh_filter_exe
_set_app_type
_set_invalid_parameter_handler
abort
exit
signal
strerror
strerror_s
api-ms-win-crt-locale-l1-1-0.dll ___lc_codepage_func
___mb_cur_max_func
__pctype_func
_configthreadlocale
_create_locale
_free_locale
localeconv
setlocale
api-ms-win-crt-heap-l1-1-0.dll _aligned_free
_aligned_malloc
_set_new_mode
calloc
free
malloc
realloc
api-ms-win-crt-private-l1-1-0.dll __intrinsic_setjmp
longjmp
memchr
memcmp
memcpy
memmove
strchr
strrchr
strstr
wcsstr
api-ms-win-crt-string-l1-1-0.dll _iswalpha_l
_iswcntrl_l
_iswdigit_l
_iswlower_l
_iswprint_l
_iswpunct_l
_iswspace_l
_iswupper_l
_iswxdigit_l
_strcoll_l
_strdup
_strrev
_strxfrm_l
_tolower_l
_toupper_l
_towlower_l
_towupper_l
_wcscoll_l
_wcsxfrm_l
isalnum
isalpha
isdigit
islower
isprint
isspace
isxdigit
mbrlen
memset
strcmp
strcpy
strlen
strncmp
strncpy
strnlen
strpbrk
tolower
toupper
wcscmp
wcslen
wcsncmp
wcsnlen
USER32.dll AdjustWindowRectEx
AttachThreadInput
BeginPaint
CallNextHookEx
CallWindowProcW
ChangeDisplaySettingsExW
CheckMenuItem
ClientToScreen
ClipCursor
CloseClipboard
CreateIconFromResource
CreateIconFromResourceEx
CreateIconIndirect
CreatePopupMenu
CreateWindowExA
CreateWindowExW
DefWindowProcW
DeleteMenu
DestroyCursor
DestroyIcon
DestroyMenu
DestroyWindow
DialogBoxIndirectParamW
DispatchMessageW
DrawTextW
EmptyClipboard
EnableMenuItem
EnableWindow
EndDialog
EndPaint
EnumClipboardFormats
EnumDisplayDevicesW
EnumDisplayMonitors
EnumDisplaySettingsW
EnumWindows
FillRect
FlashWindowEx
GetAsyncKeyState
GetClassInfoExW
GetClientRect
GetClipCursor
GetClipboardData
GetClipboardFormatNameA
GetClipboardSequenceNumber
GetCursorPos
GetDC
GetDesktopWindow
GetDlgItem
GetDoubleClickTime
GetFocus
GetForegroundWindow
GetKeyState
GetKeyboardLayout
GetKeyboardState
GetMenu
GetMenuItemInfoW
GetMessageA
GetMessageExtraInfo
GetMessagePos
GetMessageTime
GetMessageW
GetMonitorInfoW
GetPropW
GetQueueStatus
GetRawInputBuffer
GetRawInputData
GetRawInputDeviceInfoA
GetRawInputDeviceList
GetSystemMetrics
GetUpdateRect
GetWindowLongPtrW
GetWindowLongW
GetWindowPlacement
GetWindowRect
GetWindowTextLengthW
GetWindowTextW
GetWindowThreadProcessId
InsertMenuW
IntersectRect
IsClipboardFormatAvailable
IsIconic
IsWindow
IsZoomed
KillTimer
LoadCursorW
LoadIconW
MapVirtualKeyW
MessageBoxA
MonitorFromPoint
MonitorFromWindow
MsgWaitForMultipleObjects
OpenClipboard
PeekMessageW
PostMessageW
PostThreadMessageW
PtInRect
RegisterClassExA
RegisterClassExW
RegisterClassW
RegisterClipboardFormatW
RegisterDeviceNotificationW
RegisterRawInputDevices
RegisterWindowMessageA
RegisterWindowMessageW
ReleaseCapture
ReleaseDC
RemovePropW
ScreenToClient
SendMessageW
SetActiveWindow
SetCapture
SetClipboardData
SetCursor
SetCursorPos
SetFocus
SetForegroundWindow
SetLayeredWindowAttributes
SetMenuItemInfoW
SetParent
SetPropW
SetRectEmpty
SetTimer
SetWindowLongPtrW
SetWindowLongW
SetWindowPos
SetWindowRgn
SetWindowTextW
SetWindowsHookExW
ShowWindow
SystemParametersInfoA
SystemParametersInfoW
ToUnicode
TrackMouseEvent
TrackPopupMenu
TranslateMessage
UnhookWindowsHookEx
UnregisterClassA
UnregisterClassW
UnregisterDeviceNotification
ValidateRect
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
_fdopen
acos
acosf
asin
asinf
atan
atan2
atan2f
atanf
ceil
ceilf
cos
cosf
exp
exp2
exp2f
expf
floor
floorf
fmod
fmodf
log
log10
log10f
logf
lround
lroundf
modf
modff
pow
powf
round
roundf
sin
sinf
sqrt
sqrtf
tan
tanf
trunc
truncf
api-ms-win-crt-convert-l1-1-0.dll _i64toa
_itoa
_ltoa
_strtod_l
_ui64toa
_ultoa
atof
atoi
mbrtowc
mbsrtowcs
strtof
strtol
strtoll
strtoul
strtoull
wcrtomb
wcrtomb_s
wcstod
wcstol
wcstoll
wcstoul
wcstoull
api-ms-win-crt-time-l1-1-0.dll _ctime64
_gmtime64_s
_localtime64_s
_mkgmtime64
_mktime64
_strftime_l
_time32
_time64
strftime
api-ms-win-crt-multibyte-l1-1-0.dll _mbtowc_l
api-ms-win-crt-environment-l1-1-0.dll __p__environ
getenv
WINMM.dll timeBeginPeriod
timeEndPeriod
ADVAPI32.dll RegCloseKey
RegOpenKeyExW
RegQueryValueExW
ole32.dll CLSIDFromString
CoCreateInstance
CoInitializeEx
CoTaskMemFree
CoUninitialize
OleInitialize
OleUninitialize
PropVariantClear
RegisterDragDrop
ReleaseStgMedium
RevokeDragDrop
SETUPAPI.dll CM_Get_Device_IDA
CM_Get_Parent
CM_Locate_DevNodeA
SetupDiDestroyDeviceInfoList
SetupDiEnumDeviceInfo
SetupDiGetClassDevsA
SetupDiGetDeviceInstanceIdA
SetupDiGetDeviceRegistryPropertyW
SHELL32.dll CommandLineToArgvW
DragAcceptFiles
DragFinish
DragQueryFileW
SHBrowseForFolderW
SHGetFolderPathW
SHGetPathFromIDListW
ShellExecuteW
Shell_NotifyIconW
GDI32.dll BitBlt
ChoosePixelFormat
CombineRgn
CreateBitmap
CreateCompatibleBitmap
CreateCompatibleDC
CreateDCW
CreateDIBSection
CreateFontIndirectW
CreateRectRgn
CreateSolidBrush
DeleteDC
DeleteObject
DescribePixelFormat
GetDIBits
GetDeviceCaps
GetICMProfileW
GetPixelFormat
GetTextExtentPoint32A
GetTextMetricsW
SelectObject
SetPixel
SetPixelFormat
SwapBuffers
api-ms-win-crt-filesystem-l1-1-0.dll _lock_file
_mkdir
_stat64i32
_umask
_unlink
_unlock_file
remove
rename
api-ms-win-crt-utility-l1-1-0.dll qsort
rand
rand_s
OLEAUT32.dll SysFreeString
IMM32.dll ImmAssociateContext
ImmGetCandidateListW
ImmGetCompositionFontW
ImmGetCompositionStringW
ImmGetContext
ImmGetIMEFileNameA
ImmNotifyIME
ImmReleaseContext
ImmSetCandidateWindow
ImmSetCompositionStringW
ImmSetCompositionWindow
VERSION.dll GetFileVersionInfoA
GetFileVersionInfoSizeA
VerQueryValueA
WS2_32.dll inet_pton
bcrypt.dll BCryptGenRandom

Delayed Imports

Version Info

TLS Callbacks

StartAddressOfRawData 0x140a01000
EndAddressOfRawData 0x140a01050
AddressOfIndex 0x1409c6c20
AddressOfCallbacks 0x140937450
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x00000001404543E0
0x00000001400FA2C0
0x00000001400FA340

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0

RICH Header

Errors

Leave a comment

No comments yet.