| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Dec-16 14:40:10 |
| Detected languages |
English - United States
|
| TLS Callbacks | 3 callback(s) detected. |
| CompanyName | PacketRaft |
| FileDescription | PacketRaft |
| FileVersion | 0.1.0 |
| LegalCopyright | Copyright © 2025 PacketRaft |
| OriginalFilename | PacketRaft.exe |
| ProductName | PacketRaft |
| ProductVersion | 0.1.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to RC5 or RC6 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .xdata |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/71 (Scanned on 2026-01-07 03:28:25) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 10 |
| TimeDateStamp | 2025-Dec-16 14:40:10 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x478e00 |
| SizeOfInitializedData | 0x36ec00 |
| SizeOfUninitializedData | 0x2600 |
| AddressOfEntryPoint | 0x00000000000013E0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x7f1000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x7f5684 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WinDivert.dll |
WinDivertOpen
WinDivertRecv WinDivertSend |
|---|---|
| advapi32.dll |
AddAce
CopySid FreeSid GetAce GetAclInformation GetSecurityDescriptorControl GetSecurityDescriptorDacl GetSecurityDescriptorGroup GetSecurityDescriptorOwner GetSecurityDescriptorSacl GetSidLengthRequired GetSidSubAuthorityCount InitializeAcl InitializeSecurityDescriptor IsValidSid RegCloseKey RegOpenKeyExW RegQueryValueExW SetSecurityDescriptorControl SetSecurityDescriptorDacl SetSecurityDescriptorGroup SetSecurityDescriptorOwner SetSecurityDescriptorSacl SystemFunction036 |
| bcrypt.dll |
BCryptGenRandom
|
| comctl32.dll |
DefSubclassProc
RemoveWindowSubclass SetWindowSubclass |
| gdi32.dll |
CreateCompatibleDC
CreateDIBSection CreateSolidBrush DeleteDC DeleteObject GetDeviceCaps SelectObject SetBkMode SetTextColor |
| kernel32.dll |
AddVectoredExceptionHandler
CancelIo CloseHandle CompareStringOrdinal ConnectNamedPipe CreateDirectoryW CreateEventW CreateFileMappingA CreateFileW CreateIoCompletionPort CreateNamedPipeW CreateProcessW CreateThread CreateToolhelp32Snapshot CreateWaitableTimerExW DeleteFileW DisconnectNamedPipe DuplicateHandle ExitProcess FindClose FindFirstFileExW FindNextFileW FlushFileBuffers FormatMessageW FreeEnvironmentStringsW FreeLibrary GetCommandLineW GetConsoleMode GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentThread GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFileType GetFinalPathNameByHandleW GetFullPathNameW GetLastError GetModuleFileNameW GetModuleHandleA GetModuleHandleW GetOverlappedResult GetProcAddress GetProcessHeap GetQueuedCompletionStatusEx GetStdHandle GetSystemDirectoryW GetSystemInfo GetSystemTimePreciseAsFileTime GetTempPathW GetWindowsDirectoryW HeapAlloc HeapFree HeapReAlloc InitOnceBeginInitialize InitOnceComplete LoadLibraryA LoadLibraryExA LoadLibraryExW LoadLibraryW LocalAlloc LocalFree MapViewOfFile Module32FirstW Module32NextW MoveFileExW MultiByteToWideChar PostQueuedCompletionStatus Process32First Process32Next QueryPerformanceCounter QueryPerformanceFrequency ReadFile ReadFileEx RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind SetConsoleMode SetFileCompletionNotificationModes SetFileInformationByHandle SetHandleInformation SetLastError SetNamedPipeHandleState SetThreadErrorMode SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer Sleep SleepEx SwitchToThread TerminateProcess TlsAlloc TlsFree TlsGetValue TlsSetValue UnmapViewOfFile WaitForMultipleObjects WaitForSingleObject WaitNamedPipeW WriteConsoleW WriteFile WriteFileEx lstrlenW |
| ntdll.dll |
NtCancelIoFileEx
NtCreateFile NtDeviceIoControlFile NtOpenFile NtReadFile NtWriteFile RtlNtStatusToDosError |
| ole32.dll |
CoTaskMemFree
|
| oleaut32.dll |
GetErrorInfo
SysFreeString SysStringLen |
| shell32.dll |
SHGetKnownFolderPath
ShellExecuteA Shell_NotifyIconGetRect Shell_NotifyIconW |
| user32.dll |
AppendMenuW
CheckMenuItem ClientToScreen CreateAcceleratorTableW CreateIcon CreateMenu CreatePopupMenu CreateWindowExW DefWindowProcW DestroyAcceleratorTable DestroyIcon DestroyMenu DestroyWindow DrawIconEx DrawMenuBar DrawTextW FillRect GetActiveWindow GetClientRect GetCursorPos GetDC GetMenuBarInfo GetMenuItemInfoW GetWindowDC GetWindowLongPtrW GetWindowRect IsProcessDPIAware KillTimer MapWindowPoints MessageBoxW MonitorFromWindow OffsetRect PostMessageW PostQuitMessage RegisterClassW RegisterWindowMessageA ReleaseDC RemoveMenu SendInput SendMessageW SetForegroundWindow SetMenu SetMenuItemInfoW SetTimer SetWindowLongPtrW ShowWindow SystemParametersInfoA TrackPopupMenu |
| ws2_32.dll |
WSACleanup
WSAGetLastError WSAIoctl WSASend WSASocketW WSAStartup bind closesocket connect freeaddrinfo getaddrinfo getpeername getsockname getsockopt ioctlsocket recv recvfrom send sendto setsockopt shutdown socket |
| kernel32.dll (#2) |
AddVectoredExceptionHandler
CancelIo CloseHandle CompareStringOrdinal ConnectNamedPipe CreateDirectoryW CreateEventW CreateFileMappingA CreateFileW CreateIoCompletionPort CreateNamedPipeW CreateProcessW CreateThread CreateToolhelp32Snapshot CreateWaitableTimerExW DeleteFileW DisconnectNamedPipe DuplicateHandle ExitProcess FindClose FindFirstFileExW FindNextFileW FlushFileBuffers FormatMessageW FreeEnvironmentStringsW FreeLibrary GetCommandLineW GetConsoleMode GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentThread GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFileType GetFinalPathNameByHandleW GetFullPathNameW GetLastError GetModuleFileNameW GetModuleHandleA GetModuleHandleW GetOverlappedResult GetProcAddress GetProcessHeap GetQueuedCompletionStatusEx GetStdHandle GetSystemDirectoryW GetSystemInfo GetSystemTimePreciseAsFileTime GetTempPathW GetWindowsDirectoryW HeapAlloc HeapFree HeapReAlloc InitOnceBeginInitialize InitOnceComplete LoadLibraryA LoadLibraryExA LoadLibraryExW LoadLibraryW LocalAlloc LocalFree MapViewOfFile Module32FirstW Module32NextW MoveFileExW MultiByteToWideChar PostQueuedCompletionStatus Process32First Process32Next QueryPerformanceCounter QueryPerformanceFrequency ReadFile ReadFileEx RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind SetConsoleMode SetFileCompletionNotificationModes SetFileInformationByHandle SetHandleInformation SetLastError SetNamedPipeHandleState SetThreadErrorMode SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer Sleep SleepEx SwitchToThread TerminateProcess TlsAlloc TlsFree TlsGetValue TlsSetValue UnmapViewOfFile WaitForMultipleObjects WaitForSingleObject WaitNamedPipeW WriteConsoleW WriteFile WriteFileEx lstrlenW |
| bcryptprimitives.dll |
ProcessPrng
|
| api-ms-win-core-synch-l1-2-0.dll |
WaitOnAddress
WakeByAddressAll WakeByAddressSingle |
| libcairo-2.dll |
cairo_move_to
cairo_rel_curve_to cairo_rel_line_to cairo_set_dash cairo_set_line_cap cairo_set_line_width cairo_set_source_rgb cairo_status cairo_stroke |
| libfontconfig-1.dll |
FcConfigAppFontAddFile
|
| libgdk_pixbuf-2.0-0.dll |
gdk_pixbuf_new_from_resource_at_scale
|
| libgio-2.0-0.dll |
g_application_activate
g_application_command_line_get_is_remote g_application_flags_get_type g_application_get_is_registered g_application_run g_async_initable_get_type g_bus_get_sync g_dbus_connection_call_sync g_initable_get_type g_resource_new_from_data g_resource_unref g_resources_lookup_data g_resources_register |
| libglib-2.0-0.dll |
g_bytes_get_data
g_bytes_new g_bytes_new_static g_bytes_ref g_bytes_unref g_bytes_unref_to_data g_error_free g_free g_getenv g_main_context_acquire g_main_context_default g_main_context_invoke_full g_main_context_is_owner g_main_context_iteration g_main_context_pop_thread_default g_main_context_push_thread_default g_main_context_ref g_main_context_ref_thread_default g_main_context_release g_main_context_unref g_quark_to_string g_realloc g_setenv g_source_add_child_source g_source_attach g_source_destroy g_source_get_context g_source_new g_source_ref g_source_set_callback g_source_set_priority g_source_set_ready_time g_source_unref g_strfreev g_strndup g_timeout_add_full g_timeout_source_new g_variant_unref |
| libgobject-2.0-0.dll |
g_initially_unowned_get_type
g_object_class_find_property g_object_get_type g_object_new_with_properties g_object_ref g_object_ref_sink g_object_set_property g_object_unref g_param_spec_get_name g_param_spec_ref_sink g_param_spec_unref g_param_value_validate g_signal_connect_data g_signal_emitv g_signal_handler_block g_signal_handler_disconnect g_signal_handler_unblock g_signal_lookup g_signal_query g_strv_get_type g_type_check_value_holds g_type_class_ref g_type_class_unref g_type_is_a g_type_name g_type_test_flags g_value_dup_object g_value_get_object g_value_init g_value_set_boolean g_value_set_enum g_value_set_flags g_value_set_float g_value_set_int g_value_set_object g_value_set_uint g_value_take_boxed g_value_take_object g_value_take_string g_value_unset |
| libgtk-4-1.dll |
gdk_clipboard_set_text
gdk_display_create_gl_context gdk_display_get_clipboard gdk_display_get_default gdk_display_prepare_gl gdk_gl_context_clear_current gdk_gl_context_make_current gdk_surface_destroy gdk_surface_new_toplevel gdk_texture_new_for_pixbuf gsk_renderer_new_for_surface gsk_renderer_unrealize gtk_align_get_type gtk_application_add_window gtk_application_get_active_window gtk_application_get_type gtk_application_window_get_type gtk_box_append gtk_box_get_type gtk_box_new gtk_box_set_homogeneous gtk_button_get_type gtk_button_set_child gtk_button_set_label gtk_css_provider_load_from_string gtk_css_provider_new gtk_drawing_area_get_type gtk_drawing_area_set_draw_func gtk_drop_down_get_model gtk_drop_down_get_selected gtk_drop_down_new gtk_drop_down_new_from_strings gtk_drop_down_set_model gtk_drop_down_set_selected gtk_editable_get_text gtk_editable_set_text gtk_entry_get_type gtk_entry_grab_focus_without_selecting gtk_event_controller_key_new gtk_fixed_get_type gtk_fixed_put gtk_flow_box_append gtk_flow_box_get_type gtk_flow_box_remove_all gtk_header_bar_new gtk_header_bar_pack_start gtk_header_bar_set_title_widget gtk_image_get_type gtk_image_new_from_resource gtk_is_initialized gtk_justification_get_type gtk_label_get_label gtk_label_get_type gtk_label_new gtk_label_set_label gtk_orientable_set_orientation gtk_orientation_get_type gtk_overflow_get_type gtk_overlay_add_overlay gtk_overlay_get_type gtk_overlay_new gtk_overlay_set_child gtk_picture_new_for_paintable gtk_picture_new_for_resource gtk_picture_set_content_fit gtk_policy_type_get_type gtk_progress_bar_get_type gtk_progress_bar_set_fraction gtk_scrollbar_get_adjustment gtk_scrollbar_get_type gtk_scrollbar_set_adjustment gtk_scrolled_window_get_type gtk_scrolled_window_get_vscrollbar gtk_selection_mode_get_type gtk_settings_get_default gtk_stack_add_child gtk_stack_new gtk_stack_remove gtk_stack_set_transition_type gtk_stack_set_visible_child gtk_style_context_add_provider_for_display gtk_switch_get_active gtk_switch_get_type gtk_switch_new gtk_switch_set_active gtk_tooltip_set_custom gtk_widget_add_controller gtk_widget_add_css_class gtk_widget_get_first_child gtk_widget_get_name gtk_widget_get_parent gtk_widget_get_type gtk_widget_grab_focus gtk_widget_queue_draw gtk_widget_remove_css_class gtk_widget_set_css_classes gtk_widget_set_default_direction gtk_widget_set_direction gtk_widget_set_halign gtk_widget_set_has_tooltip gtk_widget_set_hexpand gtk_widget_set_sensitive gtk_widget_set_tooltip_text gtk_widget_set_valign gtk_widget_set_visible gtk_window_close gtk_window_get_titlebar gtk_window_get_type gtk_window_present gtk_window_set_child gtk_window_set_titlebar gtk_window_set_transient_for |
| IPHLPAPI.DLL |
CreateIpForwardEntry2
CreateUnicastIpAddressEntry FreeMibTable GetAdaptersAddresses GetAdaptersInfo GetExtendedTcpTable GetExtendedUdpTable GetIpForwardTable2 GetIpInterfaceEntry InitializeIpForwardEntry InitializeIpInterfaceEntry InitializeUnicastIpAddressEntry SetInterfaceDnsSettings SetIpForwardEntry2 SetIpInterfaceEntry |
| KERNEL32.dll |
DeleteCriticalSection
EnterCriticalSection InitializeCriticalSection LeaveCriticalSection RaiseException RtlUnwindEx VirtualProtect VirtualQuery __C_specific_handler |
| msvcrt.dll |
__getmainargs
__initenv __iob_func __set_app_type __setusermatherr _amsg_exit _cexit _commode _errno _fmode _fpreset _initterm abort atexit calloc ceilf exit fprintf free ldexp malloc memcmp memcpy memmove memset signal strlen strncmp vfprintf wcslen |
| ntdll.dll (#2) |
NtCancelIoFileEx
NtCreateFile NtDeviceIoControlFile NtOpenFile NtReadFile NtWriteFile RtlNtStatusToDosError |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.1.0.0 |
| ProductVersion | 0.1.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | PacketRaft |
| FileDescription | PacketRaft |
| FileVersion (#2) | 0.1.0 |
| LegalCopyright | Copyright © 2025 PacketRaft |
| OriginalFilename | PacketRaft.exe |
| ProductName | PacketRaft |
| ProductVersion (#2) | 0.1.0 |
| Resource LangID | English - United States |
|---|
| StartAddressOfRawData | 0x1407ce000 |
|---|---|
| EndAddressOfRawData | 0x1407ce008 |
| AddressOfIndex | 0x1407c747c |
| AddressOfCallbacks | 0x1407510b0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x00000001403D6620
0x0000000140470DC0 0x0000000140470DA0 |