b473c3e7fe0736531be831543e89e4c20831325399bd3b4868ae8f7e06858b9a

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Jul-20 23:47:09
Detected languages English - United States

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Interesting strings found in the binary: Contains domain names:
  • github.com
  • https://github.com
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Possibly launches other programs:
  • ShellExecuteW
  • system
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
Manipulates other processes:
  • ReadProcessMemory
  • WriteProcessMemory
  • Process32FirstW
  • Process32NextW
  • OpenProcess
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious The file contains overlay data. 122 bytes of data starting at offset 0x7d600.
Malicious VirusTotal score: 34/69 (Scanned on 2026-07-29 13:35:27) ALYac: Trojan.GenericKD.80928164
APEX: Malicious
AVG: FileRepMalware [Misc]
Antiy-AVL: RiskWare/Win64.Gamehack
Arcabit: Trojan.Generic.D4D2DDA4
Avast: FileRepMalware [Misc]
BitDefender: Trojan.GenericKD.80928164
Bkav: W32.Malware.90596586
CTX: exe.trojan.agen
CrowdStrike: win/malicious_confidence_90% (W)
Cylance: Unsafe
ESET-NOD32: Win64/GameHack_AGen.AUB potentially unsafe application
Elastic: malicious (high confidence)
Emsisoft: Trojan.GenericKD.80928164 (B)
Fortinet: Adware/GameHack_AGen
GData: Trojan.GenericKD.80928164
Google: Detected
K7AntiVirus: Unwanted-Program ( 006da7891 )
K7GW: Unwanted-Program ( 006da7891 )
Lionic: Trojan.Win32.GameHack.4!c
Malwarebytes: RiskWare.GameHack
MaxSecure: Trojan.Malware.689169083.susgen
McAfeeD: ti!B473C3E7FE07
MicroWorld-eScan: Trojan.GenericKD.80928164
Microsoft: Trojan:Win32/Wacatac.B!ml
Paloalto: generic.ml
Rising: Trojan.Kryptik@AI.100 (RDML:mjpnivvPW5/BdzaAdbFeqA)
SentinelOne: Static AI - Malicious PE
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
TrellixENS: Artemis!412C3F19F955
VIPRE: Trojan.GenericKD.80928164
Varist: W64/ABApplication.WUNX-3691
Webroot: Win.Trojan.Gen

Hashes

MD5 412c3f19f9558ea8f2ff02b1e0e083b0
SHA1 82ca33192eafc000c88705abbb44adaf3d7f3345
SHA256 b473c3e7fe0736531be831543e89e4c20831325399bd3b4868ae8f7e06858b9a
SHA3 8c1c4fe0b557a14be7e8c398a24047e29c9aaa91373db0f8d702ae57c93d37ef
SSDeep 12288:AkH0PjawCBjGn5MN1xKZrBs61WEYiEnmq:AkHOahS5MXgZrX1WDiEnmq
Imports Hash 29dca07cad4192616fb4835bdd263947

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jul-20 23:47:09
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x62400
SizeOfInitializedData 0x1b600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000062364 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x83000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 849aa7d5c7a60cbaf71bcc904de55e18
SHA1 bf89a661514c0a813710ed5c03c1b1b357a6df90
SHA256 25a95bb8bac4e9c83ff96d4f94ed0250b03707b1df08c3bd6b4d256b12666c33
SHA3 bba8a75d6849dc25103f41cd37e4695007746132bc4ab6057a323bb5ced10bc0
VirtualSize 0x623c0
VirtualAddress 0x1000
SizeOfRawData 0x62400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.56645

.rdata

MD5 38b0b1574cd1a79bb9741e6f830d7142
SHA1 9c6b1160ddca433bf1fcb3d2130047a279f3c2f3
SHA256 5ac063c19f812d2279d631c63ce85bcea09a6dd328872342f4eac124e1a5760a
SHA3 8fcde05df4cf357c35d4c1fd53ffa4b9914dcc4604901abcf989c0c023780081
VirtualSize 0x1628e
VirtualAddress 0x64000
SizeOfRawData 0x16400
PointerToRawData 0x62800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.34599

.data

MD5 32b62cd5d555a4a5ff8e5541d54284d5
SHA1 b7a25aaaf3691c540980fd776c563abaebb3b371
SHA256 0e3e29d3de406a39b831a8a72eeb8dc15f85dcef092c28e670277f518cb24adc
SHA3 0df69b15e0a524e3f2b64181ab8ca3bc75d706a76f97e36688d3449128ef8a99
VirtualSize 0x9b0
VirtualAddress 0x7b000
SizeOfRawData 0x200
PointerToRawData 0x78c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.37133

.pdata

MD5 51972dc34ccfb8cf10ccfd2dccd03146
SHA1 5627e8f2e89d2958f2f8ee70cfcb3b37d86f0e2f
SHA256 9b729df6fa8e05f1ae5e3eb0f74aa426d44fafa8a86c844c6a56a098f847747b
SHA3 89874cb6d47a58db7e18b2cbb05d794685685163f18bfc733fb1f8a6bb347fac
VirtualSize 0x4044
VirtualAddress 0x7c000
SizeOfRawData 0x4200
PointerToRawData 0x78e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.79276

.rsrc

MD5 e73ca378742e6b073379dfc7ae4fd5a2
SHA1 c5a2f00df10c971bca2b77b1f320d60e07c650ea
SHA256 b0815696cbce275964e5682ec99a0d891c7b31c2382e679f1791ef06b50a86a3
SHA3 42307fa36e9b2d45466b01bc11f9687c801b63a543f79db280965da145fde68c
VirtualSize 0x1e8
VirtualAddress 0x81000
SizeOfRawData 0x200
PointerToRawData 0x7d000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.77204

.reloc

MD5 28a9b8f1d28c3428adfb8b1e4d38338a
SHA1 c8d290366e2603f35bf0fb67f529db5fc14025c6
SHA256 d8139011e366cc69bf459442f1dd31b561da3c0ce85ad1f9c973a2ce2890deb8
SHA3 7925f882b3df39fb11ad3007c12fc6059c840792a9a78b75eeb2509775b25bf3
VirtualSize 0x224
VirtualAddress 0x82000
SizeOfRawData 0x400
PointerToRawData 0x7d200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 3.45644

Imports

KERNEL32.dll GlobalAlloc
GlobalFree
GlobalLock
WideCharToMultiByte
GlobalUnlock
GetLocaleInfoA
LoadLibraryA
QueryPerformanceFrequency
IsDBCSLeadByte
GetProcAddress
FreeLibrary
QueryPerformanceCounter
InitializeSListHead
GetSystemTimeAsFileTime
OutputDebugStringA
GetCurrentProcessId
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
GetCurrentProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
SleepConditionVariableSRW
WakeAllConditionVariable
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
VirtualQueryEx
GetModuleHandleW
MultiByteToWideChar
ReadProcessMemory
WriteProcessMemory
CloseHandle
Process32FirstW
Process32NextW
Sleep
CreateToolhelp32Snapshot
OpenProcess
GetCurrentThreadId
USER32.dll SetCursorPos
ReleaseCapture
IsWindowUnicode
SetWindowPos
GetKeyState
GetMessageExtraInfo
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
LoadCursorW
SetCapture
SetWindowLongPtrW
CreateWindowExW
ScreenToClient
GetSystemMetrics
UnregisterClassW
GetWindowLongPtrW
RegisterClassExW
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
DefWindowProcW
DestroyWindow
GetAsyncKeyState
DispatchMessageW
PeekMessageW
SetLayeredWindowAttributes
TranslateMessage
mouse_event
GetClientRect
PostQuitMessage
GetCursorPos
SetCursor
GDI32.dll CreateSolidBrush
SHELL32.dll ShellExecuteW
MSVCP140.dll ?good@ios_base@std@@QEBA_NXZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@G@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
_Mtx_unlock
_Thrd_detach
?_Throw_Cpp_error@std@@YAXH@Z
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?uncaught_exception@std@@YA_NXZ
?_Xout_of_range@std@@YAXPEBD@Z
?_Xlength_error@std@@YAXPEBD@Z
_Mtx_lock
_Cnd_do_broadcast_at_thread_exit
d3d11.dll D3D11CreateDeviceAndSwapChain
dwmapi.dll DwmExtendFrameIntoClientArea
IMM32.dll ImmGetContext
ImmSetCandidateWindow
ImmSetCompositionWindow
ImmReleaseContext
D3DCOMPILER_47.dll D3DCompile
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __current_exception_context
__current_exception
_CxxThrowException
__std_exception_destroy
__std_exception_copy
__std_terminate
memmove
__C_specific_handler
memset
memcpy
memchr
memcmp
api-ms-win-crt-utility-l1-1-0.dll qsort
srand
rand
api-ms-win-crt-runtime-l1-1-0.dll _cexit
_seh_filter_exe
_set_app_type
_get_initial_narrow_environment
_initterm
_initterm_e
exit
_exit
_invoke_watson
__p___argc
__p___argv
_c_exit
_register_thread_local_exe_atexit_callback
_register_onexit_function
_initialize_onexit_table
_beginthreadex
system
terminate
_crt_atexit
_configure_narrow_argv
_initialize_narrow_environment
api-ms-win-crt-string-l1-1-0.dll strncmp
_wcsicmp
strncpy
strcmp
api-ms-win-crt-stdio-l1-1-0.dll _set_fmode
ftell
__stdio_common_vsprintf_s
__stdio_common_vsscanf
fread
__stdio_common_vsprintf
_wfopen
fwrite
__acrt_iob_func
fflush
__stdio_common_vfprintf
fseek
fclose
__p__commode
api-ms-win-crt-time-l1-1-0.dll _time64
api-ms-win-crt-heap-l1-1-0.dll _callnewh
free
_set_new_mode
malloc
api-ms-win-crt-convert-l1-1-0.dll atof
api-ms-win-crt-math-l1-1-0.dll sqrtf
logf
fmodf
sinf
powf
cosf
ceilf
acosf
tanf
__setusermatherr
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-20 23:47:09
Version 0.0
SizeofData 892
AddressOfRawData 0x71f08
PointerToRawData 0x70708

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jul-20 23:47:09
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1400722a8
EndAddressOfRawData 0x1400722b0
AddressOfIndex 0x14007b788
AddressOfCallbacks 0x1400646b0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14007b040

RICH Header

XOR Key 0x570ff12d
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 18
ASM objects (35207) 4
C objects (35207) 10
C++ objects (35207) 29
Imports (35207) 6
Imports (33145) 17
Total imports 205
C++ objects (LTCG) (35222) 7
Resource objects (35222) 1
Linker (35222) 1

Errors

Leave a comment

No comments yet.