a9a8135be03b1a4a1c42706e4e973c09ddfc157609ab4336367131fae9d1c937

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Jul-31 10:44:46
Detected languages English - United States
Debug artifacts C:\Users\AzraVeLucky\Desktop\Auth\Emu\x64\Release\Emu.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Interesting strings found in the binary: Contains domain names:
  • ac.pvp.net
  • ap.vg.ac.pvp.net
  • eu.vg.ac.pvp.net
  • kr.vg.ac.pvp.net
  • na.vg.ac.pvp.net
  • vg.ac.pvp.net
Info Libraries used to perform cryptographic operations: Microsoft's Cryptography API
Suspicious The PE contains functions most legitimate programs don't use. Possibly launches other programs:
  • system
Uses Microsoft's cryptographic API:
  • CryptBinaryToStringA
  • CryptDecodeObjectEx
  • CryptStringToBinaryA
  • CryptImportPublicKeyInfoEx2
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Malicious VirusTotal score: 23/70 (Scanned on 2026-08-11 21:48:53) ALYac: Trojan.GenericKD.81034828
Antiy-AVL: Trojan/Win32.Agent
Arcabit: Trojan.Generic.D4D47E4C
BitDefender: Trojan.GenericKD.81034828
CTX: exe.trojan.wacatac
CrowdStrike: win/malicious_confidence_70% (W)
DeepInstinct: MALICIOUS
Elastic: malicious (high confidence)
Emsisoft: Trojan.GenericKD.81034828 (B)
GData: Trojan.GenericKD.81034828
Google: Detected
Gridinsoft: Trojan.Win64.Wacatac.bot
Lionic: Trojan.Win32.Generic.4!c
Malwarebytes: Malware.AI.3936693593
MaxSecure: Trojan.Malware.300983.susgen
MicroWorld-eScan: Trojan.GenericKD.81034828
Microsoft: Trojan:Win32/Wacatac.B!ml
Symantec: ML.Attribute.HighConfidence
TrellixENS: Artemis!D6B39483C34A
TrendMicro-HouseCall: Trojan.Win64.Gen.TL0101H326ZC
VIPRE: Trojan.GenericKD.81034828
Varist: W64/ABTrojan.HDFL-1436
alibabacloud: Trojan:Win/Wacatac.B9nj

Hashes

MD5 d6b39483c34a8894a8467b01a2997093 🔍
SHA1 7c4492b1ae8baa9499acd692687dbd390d85e915 🔍
SHA256 a9a8135be03b1a4a1c42706e4e973c09ddfc157609ab4336367131fae9d1c937 🔍
SHA3 085066180814dc4116985071fb34c5b42ef9936a09f743d866b4baee0da68f82 🔍
SSDeep 3072:rgFnhEeACHpm08WTU+4hCjET+Y90ffI12bLccqIFO+OGHgIOnmE+QR0nzJ80:rgFSeACHpm08WTUhhCQrD2Oh+QR0nzJ 🔍
Imports Hash 45a0d830845606b2483710edf1d60014 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jul-31 10:44:46
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x17400
SizeOfInitializedData 0xfc00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000169F0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x2c000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e220f96d2ba7e0ab46efb74512014ad9 🔍
SHA1 35dc1e40d8e16b69ac7b4e299ee55baf5fbbe19b 🔍
SHA256 c11cbe3ae1bd4db1920c84c2f9d8d4160972689113757e951956ef8d864243d3 🔍
SHA3 a5d22cddc8fa2b1be0b04afb0ae12403689caea9ae08e04c64215238e7f93c3d 🔍
VirtualSize 0x17301
VirtualAddress 0x1000
SizeOfRawData 0x17400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.32181

.rdata

MD5 1fa5ac422ac1a3fa8e05152ea41e3862 🔍
SHA1 63f1d828ca8a3331955f64a3be7f2844fcba2cd8 🔍
SHA256 6f08cca1a6dc296768800f59ddd678e83e682dae1dd23ccd15e15db80419772a 🔍
SHA3 44dede4d4c01652588e272a307456289362448090ed36b16dd434c695761e254 🔍
VirtualSize 0xd836
VirtualAddress 0x19000
SizeOfRawData 0xda00
PointerToRawData 0x17800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.22876

.data

MD5 7c2e30d301c0f5039ac0480db8abf456 🔍
SHA1 6bf6adfa86034b6ed85750a62b00501ab87ed5d5 🔍
SHA256 0706290bf15edf747f191a53299064a43b62feae992f5398fb5281482eb58150 🔍
SHA3 4fc293fa94eb7cf819f8dede4f1389369d392db2a2a24c70dd85e05609a765bb 🔍
VirtualSize 0x7d0
VirtualAddress 0x27000
SizeOfRawData 0x800
PointerToRawData 0x25200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.36582

.pdata

MD5 5d2922b3b9e0087760f9e8066dca1f14 🔍
SHA1 7006e550803ed6668e0635d0f3ef0c29b348380e 🔍
SHA256 a102c2d49f34ffe442d2503bcd79582fbc96305cf4786652b318194ad463de0e 🔍
SHA3 48190a7424647d1d0057343ec3ec214f5b18e76c29c4e2350752d1629f64bd37 🔍
VirtualSize 0x123c
VirtualAddress 0x28000
SizeOfRawData 0x1400
PointerToRawData 0x25a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.95812

.rsrc

MD5 61142c17ca8835763a5e7aa96625d412 🔍
SHA1 14923acdd22853dbb6c9abbb2f8639bd913728c1 🔍
SHA256 f726d9bcadc31651ebcac999e2085ac8884ac85131c07af7405cd1bd407fab99 🔍
SHA3 6d777fac8372eafff3079d1454d50231ef5f9a3366836a6f554d7a598e84d787 🔍
VirtualSize 0x2b0
VirtualAddress 0x2a000
SizeOfRawData 0x400
PointerToRawData 0x26e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.0228

.reloc

MD5 24c4970ac86242d5c881626ed2af2a4a 🔍
SHA1 08285ecb3e0a9978e14e644d93621f6dd9689f80 🔍
SHA256 48ae0617ce1a19cfde87ef841c52c7713589bc731d7d23e828139663f30ef81e 🔍
SHA3 92c413f54415feb37a5bd126618901f45b7b59bbd0944a269bc4fb848ce46418 🔍
VirtualSize 0x1a0
VirtualAddress 0x2b000
SizeOfRawData 0x200
PointerToRawData 0x27200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.6396

Imports

KERNEL32.dll Sleep
GetLastError
CloseHandle
LocalFree
ConnectNamedPipe
CreateFileW
PeekNamedPipe
CreateNamedPipeW
WriteFile
AcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
SetUnhandledExceptionFilter
GetModuleHandleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
ReleaseSRWLockExclusive
ReadFile
MSVCP140.dll _Xtime_get_ticks
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
_Strcoll
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z
?good@ios_base@std@@QEBA_NXZ
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?tolower@?$ctype@D@std@@QEBADD@Z
??1facet@locale@std@@MEAA@XZ
??0facet@locale@std@@IEAA@_K@Z
?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
?_Incref@facet@locale@std@@UEAAXXZ
?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ
??1_Locinfo@std@@QEAA@XZ
??0_Locinfo@std@@QEAA@PEBD@Z
__crtLCMapStringA
?id@?$collate@D@std@@2V0locale@2@A
?_Xlength_error@std@@YAXPEBD@Z
?id@?$ctype@D@std@@2V0locale@2@A
?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z
?_Xout_of_range@std@@YAXPEBD@Z
?_Id_cnt@id@locale@std@@0HA
?_Xinvalid_argument@std@@YAXPEBD@Z
?_Xbad_alloc@std@@YAXXZ
?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?uncaught_exceptions@std@@YAHXZ
??0_Lockit@std@@QEAA@H@Z
??1_Lockit@std@@QEAA@XZ
_Query_perf_frequency
_Strxfrm
_Query_perf_counter
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
bcrypt.dll BCryptGenerateSymmetricKey
BCryptEncrypt
BCryptCloseAlgorithmProvider
BCryptExportKey
BCryptGenRandom
BCryptOpenAlgorithmProvider
BCryptGenerateKeyPair
BCryptFinalizeKeyPair
BCryptGetProperty
BCryptDestroyKey
BCryptSetProperty
CRYPT32.dll CryptBinaryToStringA
CryptDecodeObjectEx
CryptStringToBinaryA
CryptImportPublicKeyInfoEx2
WS2_32.dll setsockopt
ioctlsocket
freeaddrinfo
recv
connect
socket
send
WSAStartup
closesocket
select
getaddrinfo
Secur32.dll InitializeSecurityContextW
DecryptMessage
FreeCredentialsHandle
AcquireCredentialsHandleW
QueryContextAttributesW
DeleteSecurityContext
EncryptMessage
FreeContextBuffer
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll _CxxThrowException
__std_terminate
__current_exception_context
__current_exception
memset
memmove
memcmp
memcpy
__RTtypeid
__std_exception_destroy
__std_type_info_compare
__C_specific_handler
__std_exception_copy
strchr
api-ms-win-crt-heap-l1-1-0.dll realloc
_callnewh
_set_new_mode
free
malloc
api-ms-win-crt-utility-l1-1-0.dll srand
rand
api-ms-win-crt-stdio-l1-1-0.dll __stdio_common_vsnprintf_s
__stdio_common_vfprintf
__stdio_common_vsprintf_s
__acrt_iob_func
_set_fmode
__p__commode
api-ms-win-crt-time-l1-1-0.dll _localtime64_s
_time64
api-ms-win-crt-string-l1-1-0.dll strlen
tolower
api-ms-win-crt-convert-l1-1-0.dll atoi
strtol
strtoul
api-ms-win-crt-runtime-l1-1-0.dll system
_register_thread_local_exe_atexit_callback
_c_exit
_errno
terminate
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_cexit
_seh_filter_exe
_set_app_type
__p___argv
_get_initial_narrow_environment
_initterm
_initterm_e
exit
_exit
__p___argc
api-ms-win-crt-locale-l1-1-0.dll ___lc_locale_name_func
_configthreadlocale
___lc_collate_cp_func
api-ms-win-crt-math-l1-1-0.dll __setusermatherr

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x249
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.06044
MD5 f7e7c81035fc42015d50fadd75b9300f 🔍
SHA1 df759518191bad6608c336186b31c120b3dadb34 🔍
SHA256 72ae19a66b5d012088d762d3e2de6498a9b3b8fc153352ca6c76cf045d1fe96e 🔍
SHA3 1038ef4fa889f000231ecd6b7f2eb0759548ed2a8e5da6ca3e19b38062e60dbd 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jul-31 10:44:46
Version 0.0
SizeofData 82
AddressOfRawData 0x229d8
PointerToRawData 0x211d8
Referenced File C:\Users\AzraVeLucky\Desktop\Auth\Emu\x64\Release\Emu.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jul-31 10:44:46
Version 0.0
SizeofData 20
AddressOfRawData 0x22a2c
PointerToRawData 0x2122c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-31 10:44:46
Version 0.0
SizeofData 912
AddressOfRawData 0x22a40
PointerToRawData 0x21240

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jul-31 10:44:46
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x140022df0
EndAddressOfRawData 0x140022df8
AddressOfIndex 0x140027700
AddressOfCallbacks 0x140019638
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140027040

RICH Header

XOR Key 0xde699a7b
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 18
ASM objects (35721) 4
C objects (35721) 10
C++ objects (35721) 32
Imports (35721) 6
Imports (33145) 11
Total imports 194
C++ objects (LTCG) (36252) 1
Resource objects (36252) 1
Linker (36252) 1

Errors

Leave a comment

No comments yet.