| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Jul-20 23:47:09 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. | 122 bytes of data starting at offset 0x7d600. |
| Malicious | VirusTotal score: 34/69 (Scanned on 2026-07-29 13:35:27) |
ALYac:
Trojan.GenericKD.80928164
APEX: Malicious AVG: FileRepMalware [Misc] Antiy-AVL: RiskWare/Win64.Gamehack Arcabit: Trojan.Generic.D4D2DDA4 Avast: FileRepMalware [Misc] BitDefender: Trojan.GenericKD.80928164 Bkav: W32.Malware.90596586 CTX: exe.trojan.agen CrowdStrike: win/malicious_confidence_90% (W) Cylance: Unsafe ESET-NOD32: Win64/GameHack_AGen.AUB potentially unsafe application Elastic: malicious (high confidence) Emsisoft: Trojan.GenericKD.80928164 (B) Fortinet: Adware/GameHack_AGen GData: Trojan.GenericKD.80928164 Google: Detected K7AntiVirus: Unwanted-Program ( 006da7891 ) K7GW: Unwanted-Program ( 006da7891 ) Lionic: Trojan.Win32.GameHack.4!c Malwarebytes: RiskWare.GameHack MaxSecure: Trojan.Malware.689169083.susgen McAfeeD: ti!B473C3E7FE07 MicroWorld-eScan: Trojan.GenericKD.80928164 Microsoft: Trojan:Win32/Wacatac.B!ml Paloalto: generic.ml Rising: Trojan.Kryptik@AI.100 (RDML:mjpnivvPW5/BdzaAdbFeqA) SentinelOne: Static AI - Malicious PE Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence TrellixENS: Artemis!412C3F19F955 VIPRE: Trojan.GenericKD.80928164 Varist: W64/ABApplication.WUNX-3691 Webroot: Win.Trojan.Gen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Jul-20 23:47:09 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x62400 |
| SizeOfInitializedData | 0x1b600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000062364 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x83000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GlobalAlloc
GlobalFree GlobalLock WideCharToMultiByte GlobalUnlock GetLocaleInfoA LoadLibraryA QueryPerformanceFrequency IsDBCSLeadByte GetProcAddress FreeLibrary QueryPerformanceCounter InitializeSListHead GetSystemTimeAsFileTime OutputDebugStringA GetCurrentProcessId IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess GetCurrentProcess SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext SleepConditionVariableSRW WakeAllConditionVariable AcquireSRWLockExclusive ReleaseSRWLockExclusive VirtualQueryEx GetModuleHandleW MultiByteToWideChar ReadProcessMemory WriteProcessMemory CloseHandle Process32FirstW Process32NextW Sleep CreateToolhelp32Snapshot OpenProcess GetCurrentThreadId |
|---|---|
| USER32.dll |
SetCursorPos
ReleaseCapture IsWindowUnicode SetWindowPos GetKeyState GetMessageExtraInfo GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow LoadCursorW SetCapture SetWindowLongPtrW CreateWindowExW ScreenToClient GetSystemMetrics UnregisterClassW GetWindowLongPtrW RegisterClassExW OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData DefWindowProcW DestroyWindow GetAsyncKeyState DispatchMessageW PeekMessageW SetLayeredWindowAttributes TranslateMessage mouse_event GetClientRect PostQuitMessage GetCursorPos SetCursor |
| GDI32.dll |
CreateSolidBrush
|
| SHELL32.dll |
ShellExecuteW
|
| MSVCP140.dll |
?good@ios_base@std@@QEBA_NXZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@G@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ _Mtx_unlock _Thrd_detach ?_Throw_Cpp_error@std@@YAXH@Z ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?uncaught_exception@std@@YA_NXZ ?_Xout_of_range@std@@YAXPEBD@Z ?_Xlength_error@std@@YAXPEBD@Z _Mtx_lock _Cnd_do_broadcast_at_thread_exit |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| IMM32.dll |
ImmGetContext
ImmSetCandidateWindow ImmSetCompositionWindow ImmReleaseContext |
| D3DCOMPILER_47.dll |
D3DCompile
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__current_exception_context
__current_exception _CxxThrowException __std_exception_destroy __std_exception_copy __std_terminate memmove __C_specific_handler memset memcpy memchr memcmp |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
srand rand |
| api-ms-win-crt-runtime-l1-1-0.dll |
_cexit
_seh_filter_exe _set_app_type _get_initial_narrow_environment _initterm _initterm_e exit _exit _invoke_watson __p___argc __p___argv _c_exit _register_thread_local_exe_atexit_callback _register_onexit_function _initialize_onexit_table _beginthreadex system terminate _crt_atexit _configure_narrow_argv _initialize_narrow_environment |
| api-ms-win-crt-string-l1-1-0.dll |
strncmp
_wcsicmp strncpy strcmp |
| api-ms-win-crt-stdio-l1-1-0.dll |
_set_fmode
ftell __stdio_common_vsprintf_s __stdio_common_vsscanf fread __stdio_common_vsprintf _wfopen fwrite __acrt_iob_func fflush __stdio_common_vfprintf fseek fclose __p__commode |
| api-ms-win-crt-time-l1-1-0.dll |
_time64
|
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
free _set_new_mode malloc |
| api-ms-win-crt-convert-l1-1-0.dll |
atof
|
| api-ms-win-crt-math-l1-1-0.dll |
sqrtf
logf fmodf sinf powf cosf ceilf acosf tanf __setusermatherr |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-20 23:47:09 |
| Version | 0.0 |
| SizeofData | 892 |
| AddressOfRawData | 0x71f08 |
| PointerToRawData | 0x70708 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-20 23:47:09 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1400722a8 |
|---|---|
| EndAddressOfRawData | 0x1400722b0 |
| AddressOfIndex | 0x14007b788 |
| AddressOfCallbacks | 0x1400646b0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14007b040 |
| XOR Key | 0x570ff12d |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 18 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 29 |
| Imports (35207) | 6 |
| Imports (33145) | 17 |
| Total imports | 205 |
| C++ objects (LTCG) (35222) | 7 |
| Resource objects (35222) | 1 |
| Linker (35222) | 1 |
No comments yet.