| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Dec-12 07:28:52 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
instant_delay.pdb
|
| CompanyName | instantdelay |
| FileDescription | InstantDelay |
| FileVersion | 1.0.2 |
| ProductName | InstantDelay |
| ProductVersion | 1.0.2 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA256
Uses constants related to SHA512 Uses constants related to RC5 or RC6 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .taubndl |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/70 (Scanned on 2026-01-25 11:42:08) |
Bkav:
W64.AIDetectMalware
Trapmine: malicious.moderate.ml.score |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2025-Dec-12 07:28:52 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xa28e00 |
| SizeOfInitializedData | 0x423200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000009F9820 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xe51000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
TlsFree
CompareStringOrdinal InitializeSListHead GetExitCodeProcess WaitForMultipleObjects SwitchToThread WaitForSingleObject SetWaitableTimer Sleep GetSystemTimePreciseAsFileTime TlsSetValue SetLastError HeapReAlloc UnhandledExceptionFilter SetUnhandledExceptionFilter AcquireSRWLockExclusive GetCurrentThreadId ReleaseSRWLockExclusive ReleaseMutex GetUserDefaultUILanguage LCIDToLocaleName FreeEnvironmentStringsW GetEnvironmentStringsW QueryPerformanceFrequency GetCommandLineW GetEnvironmentVariableW GetCurrentDirectoryW RtlVirtualUnwind GetProcessId LoadLibraryA GetProcAddress GetCurrentProcess IsWow64Process RtlCaptureContext AddVectoredExceptionHandler TlsGetValue SetEnvironmentVariableW TlsAlloc QueryPerformanceCounter EncodePointer LoadLibraryExA WakeAllConditionVariable RtlUnwindEx GetModuleHandleW GetLastError RaiseException GetCurrentThread DeleteCriticalSection HeapAlloc RtlPcToFileHeader CloseHandle GetFileAttributesW CreateProcessW ReadFile CancelIo CreateEventW ReadFileEx WriteFileEx CreateThread IsProcessorFeaturePresent GetFinalPathNameByHandleW GetTempPathW GetFileInformationByHandleEx LoadLibraryW GetModuleHandleA MultiByteToWideChar RtlLookupFunctionEntry WaitForSingleObjectEx GetCurrentProcessId WideCharToMultiByte HeapFree GetModuleFileNameW SetHandleInformation SleepEx ExitProcess GetSystemDirectoryW GetWindowsDirectoryW DuplicateHandle GetFileInformationByHandle CreateFileW GetFullPathNameW CreateDirectoryW CreateMutexA WriteConsoleW GetConsoleOutputCP GetConsoleMode GetStdHandle SetFileCompletionNotificationModes CreateIoCompletionPort GetQueuedCompletionStatusEx CreatePipe FindClose FindNextFileW FindFirstFileExW InitializeCriticalSectionAndSpinCount SetFileInformationByHandle DeleteFileW CreateMutexW PostQueuedCompletionStatus TerminateProcess GetOverlappedResult CreateWaitableTimerExW IsDebuggerPresent GetSystemTimeAsFileTime lstrlenW SetThreadStackGuarantee SleepConditionVariableSRW GetSystemInfo FormatMessageW GetProcessHeap FreeLibrary LoadLibraryExW OutputDebugStringW OutputDebugStringA |
|---|---|
| advapi32.dll |
RegGetValueW
RegCreateKeyExW RegDeleteValueW RegSetValueExW RegCloseKey RegQueryValueExW RegOpenKeyExW |
| oleaut32.dll |
GetErrorInfo
SysStringLen SysFreeString SetErrorInfo |
| bcryptprimitives.dll |
ProcessPrng
|
| ntdll.dll |
NtCreateFile
RtlNtStatusToDosError RtlGetVersion NtOpenFile NtDeviceIoControlFile NtWriteFile NtCancelIoFileEx NtCreateNamedPipeFile NtReadFile |
| api-ms-win-core-synch-l1-2-0.dll |
WakeByAddressAll
WaitOnAddress WakeByAddressSingle |
| shell32.dll |
SHGetKnownFolderPath
SHAppBarMessage Shell_NotifyIconW ShellExecuteW Shell_NotifyIconGetRect DragFinish ShellExecuteExW DragQueryFileW |
| ole32.dll |
CoInitializeEx
CoInitialize RegisterDragDrop CoCreateInstance CoTaskMemAlloc CoTaskMemFree RevokeDragDrop CoCreateFreeThreadedMarshaler OleInitialize CoUninitialize |
| user32.dll |
GetWindowTextW
SetWindowTextW ClipCursor RedrawWindow GetClipCursor ShowCursor ScreenToClient MonitorFromRect SetPropW GetMenu ToUnicodeEx FindWindowExW GetKeyboardLayout RegisterWindowMessageA GetClientRect FillRect ReleaseCapture MapVirtualKeyExW GetKeyState GetAsyncKeyState GetKeyboardState DestroyIcon CreateIcon DrawTextW GetWindowDC OffsetRect MapWindowPoints GetMenuBarInfo SetWindowLongW EnableMenuItem RemoveMenu CreatePopupMenu GetParent SystemParametersInfoW SetCapture TrackMouseEvent DestroyWindow GetWindowLongW CreateMenu GetSystemMenu IsProcessDPIAware TrackPopupMenu SetMenu CheckMenuItem PostQuitMessage ShowWindow SystemParametersInfoA CreateAcceleratorTableW DestroyAcceleratorTable DrawMenuBar SetMenuItemInfoW DrawIconEx ReleaseDC GetDC AppendMenuW InsertMenuW GetMenuItemInfoW SetWindowRgn RegisterClassW DestroyMenu EnumChildWindows DispatchMessageA GetMessageA KillTimer GetWindowTextLengthW AdjustWindowRect SetTimer GetWindow SetWindowDisplayAffinity RegisterTouchWindow IsWindow AdjustWindowRectEx UpdateWindow InvalidateRect SetParent SetCursorPos SendInput SetForegroundWindow GetForegroundWindow GetWindowRect GetActiveWindow IsWindowEnabled MonitorFromPoint EnumDisplayMonitors IsIconic IsWindowVisible EnableWindow InvalidateRgn GetWindowPlacement SetWindowPlacement ChangeDisplaySettingsExW LoadCursorW FlashWindowEx MsgWaitForMultipleObjectsEx DispatchMessageW TranslateMessage GetMessageW GetUpdateRect PeekMessageW PostThreadMessageW MapVirtualKeyW ValidateRect GetRawInputData DefWindowProcW GetWindowLongPtrW SendMessageW SetWindowLongPtrW CreateWindowExW RegisterClassExW FindWindowW TranslateAcceleratorW RegisterRawInputDevices SetWindowPos PostMessageW SetCursor ClientToScreen GetMonitorInfoW MonitorFromWindow GetCursorPos GetSystemMetrics CloseTouchInputHandle GetTouchInputInfo SetFocus |
| comctl32.dll |
TaskDialogIndirect
DefSubclassProc SetWindowSubclass RemoveWindowSubclass |
| gdi32.dll |
SetBkMode
CreateSolidBrush CombineRgn DeleteObject SetTextColor BitBlt DeleteDC SelectObject CreateDIBSection CreateCompatibleDC GetDeviceCaps CreateRectRgn |
| dwmapi.dll |
DwmGetWindowAttribute
DwmSetWindowAttribute DwmEnableBlurBehindWindow |
| shlwapi.dll |
SHCreateMemStream
|
| ws2_32.dll |
shutdown
send recv freeaddrinfo WSACleanup WSAStartup getaddrinfo accept socket getsockopt WSASend listen getsockname WSAGetLastError getpeername bind WSAIoctl setsockopt ioctlsocket WSASocketW closesocket connect |
| SHELL32.dll |
#155
SHOpenFolderAndSelectItems #190 |
| bcrypt.dll |
BCryptGenRandom
|
| ADVAPI32.dll |
EventUnregister
EventWriteTransfer EventSetInformation EventRegister SystemFunction036 |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
roundf trunc round floor pow |
| api-ms-win-crt-string-l1-1-0.dll |
strcmp
strcpy_s wcsncmp wcscmp wcsncat _wcsicmp wcslen strlen |
| api-ms-win-crt-convert-l1-1-0.dll |
_ultow_s
wcstol _wtoi |
| api-ms-win-crt-runtime-l1-1-0.dll |
_initterm
exit _exit abort __p___argc __p___argv _cexit _c_exit terminate _get_initial_narrow_environment _initialize_narrow_environment _crt_atexit _initialize_onexit_table _configure_narrow_argv _set_app_type _seh_filter_exe _register_onexit_function _initterm_e _register_thread_local_exe_atexit_callback |
| api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
_set_fmode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
_set_new_mode free calloc malloc |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.2.0 |
| ProductVersion | 1.0.2.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | instantdelay |
| FileDescription | InstantDelay |
| FileVersion (#2) | 1.0.2 |
| ProductName | InstantDelay |
| ProductVersion (#2) | 1.0.2 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-12 07:28:52 |
| Version | 0.0 |
| SizeofData | 42 |
| AddressOfRawData | 0xbef974 |
| PointerToRawData | 0xbeeb74 |
| Referenced File | instant_delay.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-12 07:28:52 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xbef9a0 |
| PointerToRawData | 0xbeeba0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-12 07:28:52 |
| Version | 0.0 |
| SizeofData | 1068 |
| AddressOfRawData | 0xbef9b4 |
| PointerToRawData | 0xbeebb4 |
| StartAddressOfRawData | 0x140befe28 |
|---|---|
| EndAddressOfRawData | 0x140bf009c |
| AddressOfIndex | 0x140dcabfc |
| AddressOfCallbacks | 0x140a2acf8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x0000000140870190
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140dc8640 |
| XOR Key | 0x90b68ed1 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 14 |
| ASM objects (35207) | 9 |
| C objects (35207) | 13 |
| C++ objects (35207) | 47 |
| Imports (30795) | 7 |
| Total imports | 386 |
| C objects (35222) | 12 |
| Unmarked objects (#2) | 63 |
| Resource objects (35222) | 1 |
| Linker (35222) | 1 |