| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Mar-25 02:41:53 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 5/72 (Scanned on 2026-03-25 02:42:30) |
APEX:
Malicious
Bkav: W64.AIDetectMalware CrowdStrike: win/malicious_confidence_70% (D) Microsoft: Program:Win32/Wacapew.C!ml Symantec: ML.Attribute.HighConfidence |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Mar-25 02:41:53 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x60b000 |
| SizeOfInitializedData | 0x84600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000600F2C (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x693000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| VMM.dll |
VMMDLL_WinReg_QueryValueExU
VMMDLL_PdbSymbolAddress VMMDLL_PdbLoad VMMDLL_ProcessGetModuleBaseU VMMDLL_ProcessGetInformationAll VMMDLL_PidGetFromName VMMDLL_Map_GetPhysMem VMMDLL_Map_GetEATU VMMDLL_Map_GetModuleFromNameW VMMDLL_Scatter_CloseHandle VMMDLL_Initialize VMMDLL_Close VMMDLL_MemFree VMMDLL_MemReadEx VMMDLL_Scatter_Initialize |
| KERNEL32.dll |
GetLastError
AreFileApisANSI SetFileInformationByHandle GetFileAttributesExW FindNextFileW FindFirstFileExW FindFirstFileW FindClose ReleaseMutex WaitForSingleObject CreateMutexA Sleep CreateThread CreateFileA ReadFile CloseHandle GetTickCount64 WriteFile GetTickCount ClearCommError SetupComm GetCommState PurgeComm SetCommMask SetCommState SetCommTimeouts GlobalAlloc GlobalLock GlobalFree MultiByteToWideChar WideCharToMultiByte QueryPerformanceCounter QueryPerformanceFrequency FreeLibrary GetProcAddress LoadLibraryA GetLocaleInfoA CreateFileW CreateDirectoryW GetCurrentDirectoryW GetLocaleInfoEx FormatMessageA LocalFree GetCurrentThreadId SleepConditionVariableSRW AcquireSRWLockShared AcquireSRWLockExclusive ReleaseSRWLockShared ReleaseSRWLockExclusive RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess WakeAllConditionVariable RtlCaptureContext GetModuleHandleW TerminateProcess RtlLookupFunctionEntry IsProcessorFeaturePresent IsDebuggerPresent GetCurrentProcessId GetFileInformationByHandleEx GetSystemTimeAsFileTime GlobalUnlock InitializeSListHead |
| USER32.dll |
SetCursor
SetCursorPos TrackMouseEvent GetKeyboardLayout ClientToScreen ScreenToClient GetForegroundWindow IsWindowUnicode GetCursorPos GetClientRect GetAsyncKeyState GetMonitorInfoA EnumDisplayMonitors SendInput TranslateMessage DispatchMessageW PeekMessageW DefWindowProcW PostQuitMessage UnregisterClassW RegisterClassExW CreateWindowExW DestroyWindow ShowWindow SetWindowPos GetSystemMetrics ReleaseCapture SetCapture GetCapture GetKeyState GetMessageExtraInfo UpdateWindow LoadCursorA MonitorFromPoint GetMonitorInfoW OpenClipboard CloseClipboard SetClipboardData GetClipboardData EmptyClipboard |
| SHELL32.dll |
ShellExecuteW
|
| ole32.dll |
CoCreateInstance
CoInitializeEx CoUninitialize |
| MSVCP140.dll |
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
_Thrd_yield ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAADD@Z ?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A ?get@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAHXZ _Thrd_id _Thrd_join ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z ?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ _Cnd_do_broadcast_at_thread_exit ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ??0_Lockit@std@@QEAA@H@Z ??1_Lockit@std@@QEAA@XZ ?_Xbad_alloc@std@@YAXXZ ?_Xinvalid_argument@std@@YAXPEBD@Z ?_Xlength_error@std@@YAXPEBD@Z ?_Xout_of_range@std@@YAXPEBD@Z _Mtx_lock _Mtx_unlock ?_Throw_Cpp_error@std@@YAXH@Z ?_Syserror_map@std@@YAPEBDH@Z ?_Winerror_map@std@@YAHH@Z ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?always_noconv@codecvt_base@std@@QEBA_NXZ ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Gnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ ?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Pnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?_Id_cnt@id@locale@std@@0HA ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?uncaught_exceptions@std@@YAHXZ _Xtime_get_ticks _Query_perf_counter _Query_perf_frequency ??Bios_base@std@@QEBA_NXZ ?good@ios_base@std@@QEBA_NXZ ?flags@ios_base@std@@QEBAHXZ ?setf@ios_base@std@@QEAAHHH@Z ?width@ios_base@std@@QEBA_JXZ ?width@ios_base@std@@QEAA_J_J@Z ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD0@Z ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_J@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@M@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z |
| WS2_32.dll |
WSAStartup
closesocket WSACleanup WSAGetLastError bind htons inet_addr socket recvfrom sendto setsockopt |
| IMM32.dll |
ImmReleaseContext
ImmSetCompositionWindow ImmSetCandidateWindow ImmGetContext |
| VCRUNTIME140.dll |
__C_specific_handler
__current_exception_context __current_exception __std_exception_copy __std_exception_destroy _CxxThrowException strchr memchr memcmp memcpy memmove memset __std_terminate strstr |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| api-ms-win-crt-runtime-l1-1-0.dll |
_initialize_narrow_environment
_initialize_onexit_table _register_onexit_function _crt_atexit _cexit _seh_filter_exe _set_app_type _get_initial_narrow_environment _initterm _initterm_e exit _exit _beginthreadex __p___argc __p___argv _c_exit _register_thread_local_exe_atexit_callback abort _invoke_watson system _configure_narrow_argv _errno terminate |
| api-ms-win-crt-string-l1-1-0.dll |
strncpy_s
strncpy wcslen strlen tolower toupper isxdigit strncmp strcmp |
| api-ms-win-crt-math-l1-1-0.dll |
roundf
powf sqrtf acosf ceilf cosf sinf fmodf __setusermatherr |
| api-ms-win-crt-heap-l1-1-0.dll |
free
malloc _callnewh _set_new_mode |
| api-ms-win-crt-convert-l1-1-0.dll |
strtoul
strtof strtol atof atoi |
| api-ms-win-crt-stdio-l1-1-0.dll |
ftell
fclose fseek fflush fgetc _wfopen fgetpos fputc fread fsetpos _get_stream_buffer_pointers __p__commode __stdio_common_vfprintf __acrt_iob_func fwrite setvbuf ungetc __stdio_common_vsprintf __stdio_common_vsprintf_s __stdio_common_vsscanf _set_fmode _fseeki64 |
| api-ms-win-crt-filesystem-l1-1-0.dll |
remove
_lock_file _unlock_file |
| api-ms-win-crt-time-l1-1-0.dll |
_localtime64_s
strftime _time64 |
| api-ms-win-crt-utility-l1-1-0.dll |
srand
qsort rand |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
___lc_codepage_func |
| D3DCOMPILER_47.dll |
D3DCompile
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-25 02:41:53 |
| Version | 0.0 |
| SizeofData | 912 |
| AddressOfRawData | 0x622a20 |
| PointerToRawData | 0x621e20 |
| StartAddressOfRawData | 0x140622dd0 |
|---|---|
| EndAddressOfRawData | 0x140622dd8 |
| AddressOfIndex | 0x140688b70 |
| AddressOfCallbacks | 0x14060cd48 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140687040 |
| XOR Key | 0x9ff23205 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 20 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 34 |
| Imports (35207) | 6 |
| C objects (33145) | 2 |
| Imports (35217) | 2 |
| Imports (2207) | 2 |
| Imports (33145) | 29 |
| Total imports | 419 |
| C++ objects (35223) | 33 |
| Resource objects (35223) | 1 |
| Linker (35223) | 1 |
No comments yet.