| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2024-May-28 09:26:28 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\Lenovo\Desktop\Developer\valorant-example-external-main\x64\Release\ValorantExternalFree.pdb
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 Uses known Mersenne Twister constants |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 55/72 (Scanned on 2026-02-09 16:00:59) |
ALYac:
Application.GenericFCA.31
APEX: Malicious AVG: Win64:MalwareX-gen [Trj] AhnLab-V3: Trojan/Win.Generic.R657512 Alibaba: HackTool:Win32/GameHack_AGen.5bf6c23e Antiy-AVL: HackTool/Win64.Gamehack Arcabit: Application.GenericFCA.31 Avast: Win64:MalwareX-gen [Trj] Avira: HEUR/AGEN.1371957 BitDefender: Application.GenericFCA.31 Bkav: W64.AIDetectMalware CTX: exe.hacktool.agen CrowdStrike: win/malicious_confidence_100% (W) Cylance: Unsafe Cynet: Malicious (score: 99) DeepInstinct: MALICIOUS DrWeb: Tool.VulnDriver.22 ESET-NOD32: Win64/HackTool.GameHack_AGen.O trojan Elastic: malicious (high confidence) Emsisoft: Application.GenericFCA.31 (B) F-Secure: Heuristic.HEUR/AGEN.1371957 Fortinet: W64/GameHack_AGen.O!tr GData: Application.GenericFCA.31 Google: Detected Ikarus: Trojan-Downloader.Win64.Agent Jiangmin: HackTool.Gamehack.ajsa K7AntiVirus: Hacktool ( 005cdf0d1 ) K7GW: Hacktool ( 005cdf0d1 ) Kaspersky: HackTool.Win32.Gamehack.dfgb Kingsoft: Win32.HackTool.GameHack.a Lionic: Hacktool.Win32.GameHack.3!c Malwarebytes: Malware.AI.1817745936 MaxSecure: Trojan.Malware.273257511.susgen McAfeeD: Trojan:Win/Vulndriver.EAG MicroWorld-eScan: Application.GenericFCA.31 Microsoft: Trojan:Win32/Casdet!rfn NANO-Antivirus: Trojan.Win64.Gamehack.kvqgjt Paloalto: generic.ml Panda: Trj/GdSda.A Rising: HackTool.GameHack!8.59E (TFE:5:oxM8JQn3x8U) Sangfor: Virus.Win32.Save.a SentinelOne: Static AI - Malicious PE Skyhigh: BehavesLike.Win64.Injector.ch Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence TACHYON: Trojan/W64.Agent.827904 Tencent: Malware.Win32.Gencirc.1414e364 TrellixENS: Artemis!4AC882EBDBC1 VIPRE: Application.GenericFCA.31 Varist: W64/Gamehack.U VirIT: Trojan.Win64.Agent.GZJ Xcitium: Malware@#w1w17bkpu3tv Yandex: Riskware.HackTool!0r/EMyZdn/k Zillya: Tool.GameHackAGen.Win64.412 huorong: HackTool/DriverLoader.a |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2024-May-28 09:26:28 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xaa800 |
| SizeOfInitializedData | 0x21200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000A996C (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xd0000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
InitializeCriticalSectionEx
CreateFileW GetCurrentThreadId GetLastError CloseHandle DeleteCriticalSection GetCurrentProcessId GetTempPathW Process32First SetLastError SetConsoleTitleA CreateToolhelp32Snapshot Sleep Process32Next CreateThread DeviceIoControl OutputDebugStringW InitializeSListHead GetSystemTimeAsFileTime GetModuleHandleW IsDebuggerPresent SleepConditionVariableSRW WakeAllConditionVariable AcquireSRWLockExclusive ReleaseSRWLockExclusive IsProcessorFeaturePresent TerminateProcess GetCurrentProcess SetUnhandledExceptionFilter UnhandledExceptionFilter VirtualAlloc VirtualFree QueryPerformanceCounter LoadLibraryA GetModuleHandleA GlobalUnlock WideCharToMultiByte GlobalLock GlobalFree GlobalAlloc FreeLibrary GetProcAddress QueryPerformanceFrequency MultiByteToWideChar |
|---|---|
| USER32.dll |
SetCapture
SetCursor GetClientRect IsWindowUnicode GetWindowThreadProcessId DispatchMessageA GetWindowRect DestroyWindow SetWindowPos GetSystemMetrics ShowWindow GetAsyncKeyState SetWindowLongA GetWindowLongA EnumWindows DefWindowProcA CreateWindowExA TranslateMessage PeekMessageA PostQuitMessage GetDesktopWindow FindWindowA RegisterClassExA UpdateWindow SetForegroundWindow UnregisterClassA GetKeyState OpenClipboard LoadCursorA ScreenToClient GetCapture ClientToScreen TrackMouseEvent ReleaseCapture GetForegroundWindow SetCursorPos GetCursorPos CloseClipboard EmptyClipboard GetClipboardData SetClipboardData |
| ADVAPI32.dll |
RegOpenKeyW
RegCreateKeyW RegDeleteKeyW RegCloseKey RegSetKeyValueW |
| IMM32.dll |
ImmSetCompositionWindow
ImmReleaseContext ImmGetContext ImmSetCandidateWindow |
| D3DCOMPILER_47.dll |
D3DCompile
|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| MSVCP140.dll |
_Query_perf_frequency
?good@ios_base@std@@QEBA_NXZ _Query_perf_counter ?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A ?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?_Random_device@std@@YAIXZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ??1_Lockit@std@@QEAA@XZ ??0_Lockit@std@@QEAA@H@Z ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z ?_Xlength_error@std@@YAXPEBD@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z ??7ios_base@std@@QEBA_NXZ ?always_noconv@codecvt_base@std@@QEBA_NXZ ??Bid@locale@std@@QEAA_KXZ ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?uncaught_exception@std@@YA_NXZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z |
| ntdll.dll |
RtlInitUnicodeString
RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind NtQuerySystemInformation |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
memmove
memset _CxxThrowException __std_terminate strstr memcpy memcmp memchr __current_exception_context __current_exception __C_specific_handler __std_exception_copy __std_exception_destroy |
| api-ms-win-crt-stdio-l1-1-0.dll |
__acrt_iob_func
__p__commode _set_fmode __stdio_common_vsnprintf_s fflush ftell __stdio_common_vsprintf __stdio_common_vsprintf_s _get_stream_buffer_pointers _fseeki64 fsetpos ungetc fclose fseek setvbuf fgetpos fgetc __stdio_common_vfprintf fwrite fputc _wfopen __stdio_common_vsscanf fread |
| api-ms-win-crt-utility-l1-1-0.dll |
srand
rand qsort |
| api-ms-win-crt-string-l1-1-0.dll |
strcpy_s
strncmp _stricmp strncpy strcmp |
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
free _set_new_mode _callnewh |
| api-ms-win-crt-convert-l1-1-0.dll |
atof
|
| api-ms-win-crt-filesystem-l1-1-0.dll |
_unlock_file
_lock_file _wremove |
| api-ms-win-crt-time-l1-1-0.dll |
_time64
|
| api-ms-win-crt-runtime-l1-1-0.dll |
_initialize_narrow_environment
_initialize_onexit_table _register_onexit_function _crt_atexit _cexit _seh_filter_exe _set_app_type terminate _get_initial_narrow_environment _initterm _initterm_e _exit system __p___argc __p___argv _c_exit _register_thread_local_exe_atexit_callback _configure_narrow_argv exit _invalid_parameter_noinfo_noreturn |
| api-ms-win-crt-math-l1-1-0.dll |
ceilf
atan2f fmodf asinf cosf atanf sqrtf acosf sinf __setusermatherr powf tanf |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-May-28 09:26:28 |
| Version | 0.0 |
| SizeofData | 126 |
| AddressOfRawData | 0xbd7bc |
| PointerToRawData | 0xbc3bc |
| Referenced File | C:\Users\Lenovo\Desktop\Developer\valorant-example-external-main\x64\Release\ValorantExternalFree.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-May-28 09:26:28 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xbd83c |
| PointerToRawData | 0xbc43c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-May-28 09:26:28 |
| Version | 0.0 |
| SizeofData | 912 |
| AddressOfRawData | 0xbd850 |
| PointerToRawData | 0xbc450 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-May-28 09:26:28 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1400bdc00 |
|---|---|
| EndAddressOfRawData | 0x1400bdc08 |
| AddressOfIndex | 0x1400c7e18 |
| AddressOfCallbacks | 0x1400ac8c0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400c7040 |
| XOR Key | 0x72916314 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 20 |
| Imports (33218) | 6 |
| C++ objects (33218) | 36 |
| C objects (33218) | 10 |
| ASM objects (33218) | 4 |
| Imports (30795) | 19 |
| Total imports | 312 |
| C++ objects (LTCG) (33523) | 13 |
| Resource objects (33523) | 1 |
| Linker (33523) | 1 |
No comments yet.