b68e5b3586ffd2a57c680a0426818e71b06eadc3ce60b80507f42679892b3558

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Feb-23 03:54:45
Detected languages English - United States
FileDescription geanswag massinha
FileVersion 1.0.0.0
InternalName version.dll
OriginalFilename version.dll
ProductName geanswag massinha
ProductVersion 1.0.0.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 8.0
MASM/TASM - sig1(h)
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Malicious VirusTotal score: 23/70 (Scanned on 2026-06-17 00:11:45) ALYac: Gen:Variant.Tedy.914244
AVG: Other:Malware-gen [Trj]
Arcabit: Trojan.Tedy.DDF344
Avast: Other:Malware-gen [Trj]
Avira: TR/Malware
BitDefender: Gen:Variant.Tedy.914244
CTX: dll.trojan.dllinject
Cynet: Malicious (score: 100)
DeepInstinct: MALICIOUS
F-Secure: Trojan.TR/Malware
GData: Gen:Variant.Tedy.914244
Google: Detected
Gridinsoft: Trojan.Win64.Gen.cl
Lionic: Trojan.UKP.Generic.4!c
MicroWorld-eScan: Gen:Variant.Tedy.914244
Microsoft: HackTool:Win32/DllInject!MTB
Sophos: Generic Reputation PUA (PUA)
Symantec: Trojan.Gen.MBT
TrendMicro-HouseCall: TROJ_GEN.R002H09CM26
VIPRE: Gen:Variant.Tedy.914244
Varist: W64/ABApplication.HNEL-1842
Webroot: Win.Trojan.Gen
alibabacloud: Trojan:Win/DllInject.Gen

Hashes

MD5 483b736504403233ed7d06ed3e3d83a9
SHA1 49fb4253a37280ee2c3f790a80d3be93257b835e
SHA256 b68e5b3586ffd2a57c680a0426818e71b06eadc3ce60b80507f42679892b3558
SHA3 7d3d6581dcc9f7404992d6f5ae75d45c8f9ad4a0f38d9a251d49cb8e630ec71d
SSDeep 6144:LwzSjVD9ZJs/7Tpz0kn2AvSG0GDkLTtVJfJthTW:8z6D9Zoxt0Ov
Imports Hash e97f354e2ec14d8ca329113bfd25baae

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Feb-23 03:54:45
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x1d400
SizeOfInitializedData 0x44a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000001D744 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x66000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 3402b6b4c08f1330a6af3be5873d673d
SHA1 693365ef64d553e1ad262b3723194c39919d547f
SHA256 7e77b70ed00796123bd2bc6cc29f954da6749bf62bd0c0f210818ba0e5d3dd17
SHA3 06aa4fdf2c76aa5de0d5e7133cf58d6ef3bdc03b3b6bd52ad85e7cc76ef52749
VirtualSize 0x1d2c8
VirtualAddress 0x1000
SizeOfRawData 0x1d400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.0184

.rdata

MD5 d048de2fabf9bb21356c78ca8b203d9f
SHA1 bafc15090937d79a43fa4a160b329d5069c1d907
SHA256 b568be21ae161ae4abf704a114277561ebe9087a7d65847eaa84a3af911e0520
SHA3 e8319f6e9539cd60060143e6c062c557ebfb7088b10a614bd1aba37e0339cb25
VirtualSize 0x1907e
VirtualAddress 0x1f000
SizeOfRawData 0x19200
PointerToRawData 0x1d800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.99549

.data

MD5 1db072f7c0b9b1c7e8074225fb5e0a59
SHA1 0fb9a6766e2644d66111b82c0e4eb72b78525579
SHA256 c41db8ebd53895a59b8de64ad15e9c4a06beb07dd62793f21ce3a9b06ba566d2
SHA3 bd438ea1891aa8eec6d9ba06e41a2a32ed21d08752e063bab999d1831fdaa0c2
VirtualSize 0x298a0
VirtualAddress 0x39000
SizeOfRawData 0x3600
PointerToRawData 0x36a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.00106

.pdata

MD5 dd9d68f882b74c2db304b492b4004d86
SHA1 0d048f56f2f7a2ad7a151dde2dd1c585a6b61de2
SHA256 847d23a335fdf374a5251499ac8e054ad801e050881fbf4d0919c34719ffe0fe
SHA3 257c78743ad2e04354c9b2622baca3e3e3ba9fa1db720694b2ff186386a560cb
VirtualSize 0x870
VirtualAddress 0x63000
SizeOfRawData 0xa00
PointerToRawData 0x3a000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.39603

.rsrc

MD5 1d66ed86e447c1a4b192056e44082e2d
SHA1 6292a924a376e5b2105084fed164314543d9a331
SHA256 5ee88b2780543ea01d2ce955b3ccff79f7794bf1d592230a3c9b726b2283f31c
SHA3 1ecad0f4c275dd4cab80efe9e7c3c9fdb9158feb17444a9d23df3d57b3cc77e7
VirtualSize 0x468
VirtualAddress 0x64000
SizeOfRawData 0x600
PointerToRawData 0x3aa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.37344

.reloc

MD5 2e5a3cd4a9d72ba80497cfdc8786b4a9
SHA1 eaf5b17f49b95b3519a2b664aac7c216f305bbed
SHA256 aca91abbfed43d3cbf34ee5a2dafb6d1354e23029551aa11b5d4bdcad0583dfa
SHA3 0a7d077d9582e0ef05f79b63162837b7a794dbe9a83701f2fed81a5ce9734841
VirtualSize 0xd10
VirtualAddress 0x65000
SizeOfRawData 0xe00
PointerToRawData 0x3b000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.3462

Imports

OPENGL32.dll wglGetCurrentDC
glGetString
glTexParameterf
glHint
glGetIntegerv
glDisable
wglGetProcAddress
KERNEL32.dll VirtualFree
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
Sleep
CreateThread
GetSystemDirectoryA
DisableThreadLibraryCalls
FreeLibrary
GetModuleHandleA
GetProcAddress
LoadLibraryA
CloseHandle
GetLastError
HeapCreate
HeapDestroy
HeapAlloc
HeapReAlloc
HeapFree
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
OpenThread
SuspendThread
ResumeThread
GetThreadContext
SetThreadContext
FlushInstructionCache
VirtualProtect
CreateToolhelp32Snapshot
Thread32First
Thread32Next
GetSystemInfo
VirtualAlloc
VirtualQuery
RtlCaptureContext
VCRUNTIME140.dll __std_type_info_destroy_list
memset
memcpy
__C_specific_handler
api-ms-win-crt-string-l1-1-0.dll strcat_s
api-ms-win-crt-runtime-l1-1-0.dll _initterm_e
_execute_onexit_table
_initialize_onexit_table
_cexit
_initialize_narrow_environment
_configure_narrow_argv
_seh_filter_dll
_initterm

Delayed Imports

GetFileVersionInfoA

Ordinal 1
Address 0x19f0

GetFileVersionInfoByHandle

Ordinal 2
Address 0x1a10

GetFileVersionInfoExA

Ordinal 3
Address 0x1a30

GetFileVersionInfoExW

Ordinal 4
Address 0x1a40

GetFileVersionInfoSizeA

Ordinal 5
Address 0x1a50

GetFileVersionInfoSizeExA

Ordinal 6
Address 0x1a60

GetFileVersionInfoSizeExW

Ordinal 7
Address 0x1a70

GetFileVersionInfoSizeW

Ordinal 8
Address 0x1a80

GetFileVersionInfoW

Ordinal 9
Address 0x1a90

VerFindFileA

Ordinal 10
Address 0x1ab0

VerFindFileW

Ordinal 11
Address 0x1ac0

VerInstallFileA

Ordinal 12
Address 0x1ad0

VerInstallFileW

Ordinal 13
Address 0x1ae0

VerLanguageNameA

Ordinal 14
Address 0x1af0

VerLanguageNameW

Ordinal 15
Address 0x1b00

VerQueryValueA

Ordinal 16
Address 0x1b10

VerQueryValueW

Ordinal 17
Address 0x1b20

proxy_GetFileVersionInfoA

Ordinal 18
Address 0x19f0

proxy_GetFileVersionInfoByHandle

Ordinal 19
Address 0x1a10

proxy_GetFileVersionInfoExA

Ordinal 20
Address 0x1a30

proxy_GetFileVersionInfoExW

Ordinal 21
Address 0x1a40

proxy_GetFileVersionInfoSizeA

Ordinal 22
Address 0x1a50

proxy_GetFileVersionInfoSizeExA

Ordinal 23
Address 0x1a60

proxy_GetFileVersionInfoSizeExW

Ordinal 24
Address 0x1a70

proxy_GetFileVersionInfoSizeW

Ordinal 25
Address 0x1a80

proxy_GetFileVersionInfoW

Ordinal 26
Address 0x1a90

proxy_VerFindFileA

Ordinal 27
Address 0x1ab0

proxy_VerFindFileW

Ordinal 28
Address 0x1ac0

proxy_VerInstallFileA

Ordinal 29
Address 0x1ad0

proxy_VerInstallFileW

Ordinal 30
Address 0x1ae0

proxy_VerLanguageNameA

Ordinal 31
Address 0x1af0

proxy_VerLanguageNameW

Ordinal 32
Address 0x1b00

proxy_VerQueryValueA

Ordinal 33
Address 0x1b10

proxy_VerQueryValueW

Ordinal 34
Address 0x1b20

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x248
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23614
MD5 d8d52a2de1ef61a8a5d989936175f163
SHA1 07a7fe577a442dca01ce8f45003e1abaf17efddf
SHA256 2a9feeeae2b8e664788524993f6bbd3fd8d861e3970089c8b33bc6969b321995
SHA3 01f67ddd5d0dae5bbf461527dc9bc85d96c3d50c5a3c35cc9c86b1b576440af2

2

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
FileDescription geanswag massinha
FileVersion (#2) 1.0.0.0
InternalName version.dll
OriginalFilename version.dll
ProductName geanswag massinha
ProductVersion (#2) 1.0.0.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Feb-23 03:54:45
Version 0.0
SizeofData 600
AddressOfRawData 0x36b48
PointerToRawData 0x35348

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x18003c540

RICH Header

XOR Key 0x561ad3e0
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 6
Imports (35207) 2
ASM objects (35207) 3
C objects (35207) 8
C++ objects (35207) 19
Imports (30795) 5
Total imports 81
C objects (35222) 5
C++ objects (35222) 2
Exports (35222) 1
Resource objects (35222) 1
151 1
Linker (35222) 1

Errors

Leave a comment

No comments yet.