| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Jul-31 10:44:46 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\AzraVeLucky\Desktop\Auth\Emu\x64\Release\Emu.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
| Suspicious | The PE contains functions most legitimate programs don't use. |
Possibly launches other programs:
|
| Malicious | VirusTotal score: 23/70 (Scanned on 2026-08-11 21:48:53) |
ALYac:
Trojan.GenericKD.81034828
Antiy-AVL: Trojan/Win32.Agent Arcabit: Trojan.Generic.D4D47E4C BitDefender: Trojan.GenericKD.81034828 CTX: exe.trojan.wacatac CrowdStrike: win/malicious_confidence_70% (W) DeepInstinct: MALICIOUS Elastic: malicious (high confidence) Emsisoft: Trojan.GenericKD.81034828 (B) GData: Trojan.GenericKD.81034828 Google: Detected Gridinsoft: Trojan.Win64.Wacatac.bot Lionic: Trojan.Win32.Generic.4!c Malwarebytes: Malware.AI.3936693593 MaxSecure: Trojan.Malware.300983.susgen MicroWorld-eScan: Trojan.GenericKD.81034828 Microsoft: Trojan:Win32/Wacatac.B!ml Symantec: ML.Attribute.HighConfidence TrellixENS: Artemis!D6B39483C34A TrendMicro-HouseCall: Trojan.Win64.Gen.TL0101H326ZC VIPRE: Trojan.GenericKD.81034828 Varist: W64/ABTrojan.HDFL-1436 alibabacloud: Trojan:Win/Wacatac.B9nj |
| MD5 | d6b39483c34a8894a8467b01a2997093 🔍 |
|---|---|
| SHA1 | 7c4492b1ae8baa9499acd692687dbd390d85e915 🔍 |
| SHA256 | a9a8135be03b1a4a1c42706e4e973c09ddfc157609ab4336367131fae9d1c937 🔍 |
| SHA3 | 085066180814dc4116985071fb34c5b42ef9936a09f743d866b4baee0da68f82 🔍 |
| SSDeep | 3072:rgFnhEeACHpm08WTU+4hCjET+Y90ffI12bLccqIFO+OGHgIOnmE+QR0nzJ80:rgFSeACHpm08WTUhhCQrD2Oh+QR0nzJ 🔍 |
| Imports Hash | 45a0d830845606b2483710edf1d60014 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Jul-31 10:44:46 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x17400 |
| SizeOfInitializedData | 0xfc00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000169F0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x2c000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | e220f96d2ba7e0ab46efb74512014ad9 🔍 |
|---|---|
| SHA1 | 35dc1e40d8e16b69ac7b4e299ee55baf5fbbe19b 🔍 |
| SHA256 | c11cbe3ae1bd4db1920c84c2f9d8d4160972689113757e951956ef8d864243d3 🔍 |
| SHA3 | a5d22cddc8fa2b1be0b04afb0ae12403689caea9ae08e04c64215238e7f93c3d 🔍 |
| VirtualSize | 0x17301 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x17400 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.32181 |
| MD5 | 1fa5ac422ac1a3fa8e05152ea41e3862 🔍 |
|---|---|
| SHA1 | 63f1d828ca8a3331955f64a3be7f2844fcba2cd8 🔍 |
| SHA256 | 6f08cca1a6dc296768800f59ddd678e83e682dae1dd23ccd15e15db80419772a 🔍 |
| SHA3 | 44dede4d4c01652588e272a307456289362448090ed36b16dd434c695761e254 🔍 |
| VirtualSize | 0xd836 |
| VirtualAddress | 0x19000 |
| SizeOfRawData | 0xda00 |
| PointerToRawData | 0x17800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.22876 |
| MD5 | 7c2e30d301c0f5039ac0480db8abf456 🔍 |
|---|---|
| SHA1 | 6bf6adfa86034b6ed85750a62b00501ab87ed5d5 🔍 |
| SHA256 | 0706290bf15edf747f191a53299064a43b62feae992f5398fb5281482eb58150 🔍 |
| SHA3 | 4fc293fa94eb7cf819f8dede4f1389369d392db2a2a24c70dd85e05609a765bb 🔍 |
| VirtualSize | 0x7d0 |
| VirtualAddress | 0x27000 |
| SizeOfRawData | 0x800 |
| PointerToRawData | 0x25200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.36582 |
| MD5 | 5d2922b3b9e0087760f9e8066dca1f14 🔍 |
|---|---|
| SHA1 | 7006e550803ed6668e0635d0f3ef0c29b348380e 🔍 |
| SHA256 | a102c2d49f34ffe442d2503bcd79582fbc96305cf4786652b318194ad463de0e 🔍 |
| SHA3 | 48190a7424647d1d0057343ec3ec214f5b18e76c29c4e2350752d1629f64bd37 🔍 |
| VirtualSize | 0x123c |
| VirtualAddress | 0x28000 |
| SizeOfRawData | 0x1400 |
| PointerToRawData | 0x25a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.95812 |
| MD5 | 61142c17ca8835763a5e7aa96625d412 🔍 |
|---|---|
| SHA1 | 14923acdd22853dbb6c9abbb2f8639bd913728c1 🔍 |
| SHA256 | f726d9bcadc31651ebcac999e2085ac8884ac85131c07af7405cd1bd407fab99 🔍 |
| SHA3 | 6d777fac8372eafff3079d1454d50231ef5f9a3366836a6f554d7a598e84d787 🔍 |
| VirtualSize | 0x2b0 |
| VirtualAddress | 0x2a000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x26e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.0228 |
| MD5 | 24c4970ac86242d5c881626ed2af2a4a 🔍 |
|---|---|
| SHA1 | 08285ecb3e0a9978e14e644d93621f6dd9689f80 🔍 |
| SHA256 | 48ae0617ce1a19cfde87ef841c52c7713589bc731d7d23e828139663f30ef81e 🔍 |
| SHA3 | 92c413f54415feb37a5bd126618901f45b7b59bbd0944a269bc4fb848ce46418 🔍 |
| VirtualSize | 0x1a0 |
| VirtualAddress | 0x2b000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x27200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 4.6396 |
| KERNEL32.dll |
Sleep
GetLastError CloseHandle LocalFree ConnectNamedPipe CreateFileW PeekNamedPipe CreateNamedPipeW WriteFile AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW SetUnhandledExceptionFilter GetModuleHandleW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead ReleaseSRWLockExclusive ReadFile |
|---|---|
| MSVCP140.dll |
_Xtime_get_ticks
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z _Strcoll ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z ?good@ios_base@std@@QEBA_NXZ ?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?tolower@?$ctype@D@std@@QEBADD@Z ??1facet@locale@std@@MEAA@XZ ??0facet@locale@std@@IEAA@_K@Z ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ ?_Incref@facet@locale@std@@UEAAXXZ ?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ ??1_Locinfo@std@@QEAA@XZ ??0_Locinfo@std@@QEAA@PEBD@Z __crtLCMapStringA ?id@?$collate@D@std@@2V0locale@2@A ?_Xlength_error@std@@YAXPEBD@Z ?id@?$ctype@D@std@@2V0locale@2@A ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z ?_Xout_of_range@std@@YAXPEBD@Z ?_Id_cnt@id@locale@std@@0HA ?_Xinvalid_argument@std@@YAXPEBD@Z ?_Xbad_alloc@std@@YAXXZ ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?uncaught_exceptions@std@@YAHXZ ??0_Lockit@std@@QEAA@H@Z ??1_Lockit@std@@QEAA@XZ _Query_perf_frequency _Strxfrm _Query_perf_counter ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z |
| bcrypt.dll |
BCryptGenerateSymmetricKey
BCryptEncrypt BCryptCloseAlgorithmProvider BCryptExportKey BCryptGenRandom BCryptOpenAlgorithmProvider BCryptGenerateKeyPair BCryptFinalizeKeyPair BCryptGetProperty BCryptDestroyKey BCryptSetProperty |
| CRYPT32.dll |
CryptBinaryToStringA
CryptDecodeObjectEx CryptStringToBinaryA CryptImportPublicKeyInfoEx2 |
| WS2_32.dll |
setsockopt
ioctlsocket freeaddrinfo recv connect socket send WSAStartup closesocket select getaddrinfo |
| Secur32.dll |
InitializeSecurityContextW
DecryptMessage FreeCredentialsHandle AcquireCredentialsHandleW QueryContextAttributesW DeleteSecurityContext EncryptMessage FreeContextBuffer |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
_CxxThrowException
__std_terminate __current_exception_context __current_exception memset memmove memcmp memcpy __RTtypeid __std_exception_destroy __std_type_info_compare __C_specific_handler __std_exception_copy strchr |
| api-ms-win-crt-heap-l1-1-0.dll |
realloc
_callnewh _set_new_mode free malloc |
| api-ms-win-crt-utility-l1-1-0.dll |
srand
rand |
| api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vsnprintf_s
__stdio_common_vfprintf __stdio_common_vsprintf_s __acrt_iob_func _set_fmode __p__commode |
| api-ms-win-crt-time-l1-1-0.dll |
_localtime64_s
_time64 |
| api-ms-win-crt-string-l1-1-0.dll |
strlen
tolower |
| api-ms-win-crt-convert-l1-1-0.dll |
atoi
strtol strtoul |
| api-ms-win-crt-runtime-l1-1-0.dll |
system
_register_thread_local_exe_atexit_callback _c_exit _errno terminate _configure_narrow_argv _initialize_narrow_environment _initialize_onexit_table _register_onexit_function _crt_atexit _cexit _seh_filter_exe _set_app_type __p___argv _get_initial_narrow_environment _initterm _initterm_e exit _exit __p___argc |
| api-ms-win-crt-locale-l1-1-0.dll |
___lc_locale_name_func
_configthreadlocale ___lc_collate_cp_func |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x249 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.06044 |
| MD5 | f7e7c81035fc42015d50fadd75b9300f 🔍 |
| SHA1 | df759518191bad6608c336186b31c120b3dadb34 🔍 |
| SHA256 | 72ae19a66b5d012088d762d3e2de6498a9b3b8fc153352ca6c76cf045d1fe96e 🔍 |
| SHA3 | 1038ef4fa889f000231ecd6b7f2eb0759548ed2a8e5da6ca3e19b38062e60dbd 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-31 10:44:46 |
| Version | 0.0 |
| SizeofData | 82 |
| AddressOfRawData | 0x229d8 |
| PointerToRawData | 0x211d8 |
| Referenced File | C:\Users\AzraVeLucky\Desktop\Auth\Emu\x64\Release\Emu.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-31 10:44:46 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x22a2c |
| PointerToRawData | 0x2122c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-31 10:44:46 |
| Version | 0.0 |
| SizeofData | 912 |
| AddressOfRawData | 0x22a40 |
| PointerToRawData | 0x21240 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-31 10:44:46 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x140022df0 |
|---|---|
| EndAddressOfRawData | 0x140022df8 |
| AddressOfIndex | 0x140027700 |
| AddressOfCallbacks | 0x140019638 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140027040 |
| XOR Key | 0xde699a7b |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 18 |
| ASM objects (35721) | 4 |
| C objects (35721) | 10 |
| C++ objects (35721) | 32 |
| Imports (35721) | 6 |
| Imports (33145) | 11 |
| Total imports | 194 |
| C++ objects (LTCG) (36252) | 1 |
| Resource objects (36252) | 1 |
| Linker (36252) | 1 |
No comments yet.