| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-May-23 13:30:55 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\demee\OneDrive\Bureau\TracteurClicker\x64\Release\TracteurClicker.pdb
|
| CompanyName | |
| FileDescription | Opera installer SFX |
| FileVersion | 128.0.5807.78 |
| InternalName | 7zS.sfx |
| LegalCopyright | Opera Software 2026 |
| OriginalFilename | 7zS.sfx.exe |
| ProductName | 7-Zip |
| ProductVersion | 128.0.5807.78 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA256
Uses known Mersenne Twister constants |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE is possibly a dropper. |
Resource 200 detected as a PE Executable.
Resource 201 detected as a PE Executable. |
| Malicious | VirusTotal score: 16/59 (Scanned on 2026-06-04 12:34:48) |
APEX:
Malicious
Antiy-AVL: RiskWare[RiskTool]/Multi.WinDivert Bkav: W32.Malware.983E95B2 CTX: exe.unknown.windivert CrowdStrike: win/malicious_confidence_60% (W) Cylance: Unsafe DeepInstinct: MALICIOUS Elastic: malicious (high confidence) Google: Detected Lionic: Riskware.Win32.WinDivert.1!c Malwarebytes: RiskWare.WinDivert McAfeeD: ti!B6036706B309 Paloalto: generic.ml Sophos: Generic Reputation PUA (PUA) Symantec: ML.Attribute.HighConfidence Varist: W64/ABApplication.STEE-9016 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-May-23 13:30:55 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xbf600 |
| SizeOfInitializedData | 0x125400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000008E1A8 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1e8000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| D3DCOMPILER_47.dll |
D3DCompile
|
| dwmapi.dll |
DwmSetWindowAttribute
|
| KERNEL32.dll |
RemoveDirectoryW
GetTempPathW CreateFileW GetLastError DeleteFileW CloseHandle LoadLibraryW FindResourceW GetProcAddress GetCurrentProcessId GetModuleHandleW FreeLibrary SetDllDirectoryW SetFileTime GetModuleFileNameW CreateFileA ExitProcess GetFileTime WriteProcessMemory OpenProcess CreateToolhelp32Snapshot Process32NextW Process32FirstW Module32FirstW VirtualProtectEx ReadProcessMemory Module32NextW VirtualAllocEx VirtualFreeEx VirtualQueryEx MultiByteToWideChar GlobalAlloc GlobalFree GlobalLock WideCharToMultiByte GlobalUnlock GetLocaleInfoA LoadLibraryA QueryPerformanceFrequency QueryPerformanceCounter HeapReAlloc ReadConsoleW EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW FlsFree FlsSetValue FlsGetValue FlsAlloc HeapAlloc WriteFile GetConsoleMode GetConsoleOutputCP FlushFileBuffers GetFileType SetFilePointerEx GetFileSizeEx GetStdHandle ReadFile GetModuleHandleExW FreeLibraryAndExitThread ExitThread CreateThread LoadLibraryExW TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount SetLastError RaiseException RtlPcToFileHeader RtlUnwindEx InitializeSListHead GetStartupInfoW IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess GetCurrentProcess SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext GetCPInfo GetStringTypeW LCMapStringEx DecodePointer CreateDirectoryW CreateDirectoryA GetThreadId LoadResource LockResource GetTempPathA Sleep FindResourceA SizeofResource GetProcessHeap SetStdHandle EncodePointer DeleteCriticalSection LeaveCriticalSection EnterCriticalSection FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetOEMCP GetACP IsValidCodePage HeapSize WriteConsoleW SetEndOfFile HeapFree RtlUnwind WakeConditionVariable WakeAllConditionVariable SleepConditionVariableSRW GetCurrentThreadId FormatMessageA ReleaseSRWLockExclusive AcquireSRWLockExclusive TryAcquireSRWLockExclusive WaitForSingleObjectEx GetExitCodeThread LocalFree GetLocaleInfoEx FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesExW SetFileInformationByHandle AreFileApisANSI GetFileInformationByHandleEx InitializeCriticalSectionEx GetSystemTimeAsFileTime |
| USER32.dll |
SendInput
PostThreadMessageW SetWindowsHookExW mouse_event GetKeyState GetMessageExtraInfo GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout LoadCursorW SetCapture SetCursor GetClientRect IsWindowUnicode ReleaseCapture SetCursorPos OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData MapVirtualKeyW GetWindowLongW DefWindowProcW GetWindowRect IsWindowVisible SetWindowPos CreateWindowExW ScreenToClient UnregisterClassW RegisterClassExW ShowWindow GetAsyncKeyState ChangeDisplaySettingsW PeekMessageW SetWindowDisplayAffinity EnumWindows SetWindowLongW GetWindowLongPtrA PostQuitMessage EnumDisplaySettingsW SetWindowLongPtrA UpdateWindow GetCursorPos GetMessageW CallNextHookEx GetClassNameA DispatchMessageW GetWindowTextA GetForegroundWindow UnhookWindowsHookEx TranslateMessage |
| ADVAPI32.dll |
CheckTokenMembership
RegSetValueExW RegCloseKey FreeSid AllocateAndInitializeSid RegQueryValueExW RegOpenKeyExW |
| SHELL32.dll |
SHChangeNotify
ShellExecuteExW ShellExecuteA SHGetKnownFolderPath |
| ole32.dll |
CoCreateInstance
CoTaskMemFree CoInitializeEx CoCreateGuid CoUninitialize |
| WINMM.dll |
mciSendStringA
timeBeginPeriod timeEndPeriod |
| IMM32.dll |
ImmSetCompositionWindow
ImmReleaseContext ImmGetContext ImmSetCandidateWindow |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 128.0.5807.78 |
| ProductVersion | 128.0.5807.78 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | |
| FileDescription | Opera installer SFX |
| FileVersion (#2) | 128.0.5807.78 |
| InternalName | 7zS.sfx |
| LegalCopyright | Opera Software 2026 |
| OriginalFilename | 7zS.sfx.exe |
| ProductName | 7-Zip |
| ProductVersion (#2) | 128.0.5807.78 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-23 13:30:55 |
| Version | 0.0 |
| SizeofData | 103 |
| AddressOfRawData | 0xdd44c |
| PointerToRawData | 0xdbe4c |
| Referenced File | C:\Users\demee\OneDrive\Bureau\TracteurClicker\x64\Release\TracteurClicker.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-23 13:30:55 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xdd4b4 |
| PointerToRawData | 0xdbeb4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-23 13:30:55 |
| Version | 0.0 |
| SizeofData | 1012 |
| AddressOfRawData | 0xdd4c8 |
| PointerToRawData | 0xdbec8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-23 13:30:55 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1400dd908 |
|---|---|
| EndAddressOfRawData | 0x1400dd938 |
| AddressOfIndex | 0x1400edb28 |
| AddressOfCallbacks | 0x1400c17f0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400eb100 |
| XOR Key | 0xc0d6948a |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 24 |
| ASM objects (34321) | 10 |
| C objects (34321) | 17 |
| C++ objects (34321) | 94 |
| C objects (30795) | 27 |
| C++ objects (30795) | 184 |
| C objects (CVTCIL) (30795) | 1 |
| Imports (30795) | 23 |
| Total imports | 278 |
| C++ objects (LTCG) (34436) | 15 |
| Resource objects (34436) | 1 |
| 151 | 1 |
| Linker (34436) | 1 |
No comments yet.