| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jul-12 07:00:53 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\daddysschwanz\source\repos\Version2\x64\Release\Version2.pdb
|
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses known Mersenne Twister constants |
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 22/62 (Scanned on 2026-08-07 11:53:50) |
ALYac:
Gen:Variant.Yogi.23199
Arcabit: Trojan.Yogi.D5A9F BitDefender: Gen:Variant.Yogi.23199 CTX: dll.unknown.yogi CrowdStrike: win/malicious_confidence_70% (D) Cylance: Unsafe Cynet: Malicious (score: 100) ESET-NOD32: Win64/GameHack.YR potentially unsafe application Emsisoft: Gen:Variant.Yogi.23199 (B) GData: Gen:Variant.Yogi.23199 Lionic: Trojan.Win32.Generic.4!c Malwarebytes: Malware.AI.1701738203 McAfeeD: ti!C39F2CC0FCC2 MicroWorld-eScan: Gen:Variant.Yogi.23199 Microsoft: Program:Win32/Wacapew.C!ml Paloalto: generic.ml Sophos: Generic Reputation PUA (PUA) Symantec: ML.Attribute.HighConfidence TrellixENS: Artemis!65DFED659B25 TrendMicro-HouseCall: TROJ_GEN.R002H09H626 VIPRE: Gen:Variant.Yogi.23199 Varist: W64/ABApplication.QVUJ-1512 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Jul-12 07:00:53 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xab400 |
| SizeOfInitializedData | 0x3cc00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000817F0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xed000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
CreateToolhelp32Snapshot
Sleep GetLastError HeapReAlloc CloseHandle HeapAlloc HeapDestroy GetThreadContext GetProcAddress GetCurrentProcessId GetModuleHandleW FlushInstructionCache SetThreadContext OpenThread GetModuleFileNameA FindFirstFileA FindNextFileA FindClose FreeLibraryAndExitThread GetModuleHandleA DisableThreadLibraryCalls DeleteFileA WritePrivateProfileStringA CreateThread GetPrivateProfileIntA GetPrivateProfileStringA OutputDebugStringA MultiByteToWideChar GlobalAlloc GlobalFree GlobalLock WideCharToMultiByte GlobalUnlock GetLocaleInfoA LoadLibraryA QueryPerformanceFrequency IsDBCSLeadByte SuspendThread QueryPerformanceCounter WriteConsoleW SetEndOfFile HeapSize GetStringTypeW SetStdHandle CreateFileW GetProcessHeap FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetCPInfo GetOEMCP GetACP IsValidCodePage FindNextFileW FindFirstFileExW GetFileSizeEx GetConsoleOutputCP WriteFile FlushFileBuffers ReadConsoleW GetConsoleMode SetFilePointerEx GetFileType GetStdHandle GetCurrentThreadId Thread32First Thread32Next GetCurrentProcess HeapFree VirtualProtect LCMapStringW HeapCreate VirtualQuery GetSystemInfo VirtualFree ResumeThread VirtualAlloc FreeLibrary LoadLibraryExW ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW SetUnhandledExceptionFilter GetStartupInfoW GetSystemTimeAsFileTime InitializeSListHead WaitForSingleObjectEx GetExitCodeThread RtlLookupFunctionEntry RtlUnwindEx RtlPcToFileHeader RaiseException InterlockedFlushSList SetLastError FlsAlloc FlsGetValue FlsSetValue FlsFree EncodePointer EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection ExitThread GetModuleHandleExW ReadFile ExitProcess TerminateProcess GetModuleFileNameW IsProcessorFeaturePresent RtlCaptureContext RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter |
|---|---|
| USER32.dll |
ScreenToClient
GetAsyncKeyState FindWindowA GetCursorPos SetWindowLongPtrW DefWindowProcW GetKeyState GetMessageExtraInfo GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow LoadCursorW SetCapture SetCursor GetClientRect IsWindowUnicode ReleaseCapture SetCursorPos OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData CallWindowProcW keybd_event |
| ADVAPI32.dll |
GetUserNameA
|
| SHELL32.dll |
ShellExecuteW
|
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
| IMM32.dll |
ImmReleaseContext
ImmSetCompositionWindow ImmSetCandidateWindow ImmGetContext |
| D3DCOMPILER_47.dll |
D3DCompile
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-12 07:00:53 |
| Version | 0.0 |
| SizeofData | 94 |
| AddressOfRawData | 0xce980 |
| PointerToRawData | 0xcd180 |
| Referenced File | C:\Users\daddysschwanz\source\repos\Version2\x64\Release\Version2.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-12 07:00:53 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xce9e0 |
| PointerToRawData | 0xcd1e0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-12 07:00:53 |
| Version | 0.0 |
| SizeofData | 952 |
| AddressOfRawData | 0xce9f4 |
| PointerToRawData | 0xcd1f4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-12 07:00:53 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1800cedf8 |
|---|---|
| EndAddressOfRawData | 0x1800cee00 |
| AddressOfIndex | 0x1800dd838 |
| AddressOfCallbacks | 0x1800ad5f8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1800db040 |
| XOR Key | 0x58736d7c |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 163 |
| C objects (33145) | 27 |
| ASM objects (33145) | 23 |
| ASM objects (35721) | 10 |
| C objects (35721) | 15 |
| C++ objects (35721) | 55 |
| Imports (33145) | 19 |
| Total imports | 189 |
| C objects (LTCG) (36248) | 17 |
| Resource objects (36248) | 1 |
| Linker (36248) | 1 |
No comments yet.