c39f2cc0fcc2de9b824e2b2cf0efb39c33cb5c3d6b2233465cf7d3f43e614310

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-12 07:00:53
Detected languages English - United States
Debug artifacts C:\Users\daddysschwanz\source\repos\Version2\x64\Release\Version2.pdb

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • github.com
  • https://github.com
Info Cryptographic algorithms detected in the binary: Uses known Mersenne Twister constants
Suspicious The PE is possibly packed. Unusual section name found: .fptable
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • FindWindowA
Possibly launches other programs:
  • ShellExecuteW
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 22/62 (Scanned on 2026-08-07 11:53:50) ALYac: Gen:Variant.Yogi.23199
Arcabit: Trojan.Yogi.D5A9F
BitDefender: Gen:Variant.Yogi.23199
CTX: dll.unknown.yogi
CrowdStrike: win/malicious_confidence_70% (D)
Cylance: Unsafe
Cynet: Malicious (score: 100)
ESET-NOD32: Win64/GameHack.YR potentially unsafe application
Emsisoft: Gen:Variant.Yogi.23199 (B)
GData: Gen:Variant.Yogi.23199
Lionic: Trojan.Win32.Generic.4!c
Malwarebytes: Malware.AI.1701738203
McAfeeD: ti!C39F2CC0FCC2
MicroWorld-eScan: Gen:Variant.Yogi.23199
Microsoft: Program:Win32/Wacapew.C!ml
Paloalto: generic.ml
Sophos: Generic Reputation PUA (PUA)
Symantec: ML.Attribute.HighConfidence
TrellixENS: Artemis!65DFED659B25
TrendMicro-HouseCall: TROJ_GEN.R002H09H626
VIPRE: Gen:Variant.Yogi.23199
Varist: W64/ABApplication.QVUJ-1512

Hashes

MD5 65dfed659b25f8e01da3c7df576de5cf
SHA1 e624183fb8dac627c02845f6494e97a984f777f1
SHA256 c39f2cc0fcc2de9b824e2b2cf0efb39c33cb5c3d6b2233465cf7d3f43e614310
SHA3 7392d56ae2b4dfb381f7dafe19d25d7260b14a2cad0502079adbbc84f8f7a5b9
SSDeep 12288:cQhlfOe41tZNXXEYpTPntsjh3HiUnv3orHCaJo4/VYiHnDoK4pr:cv91t3XD1/eFDnv4rHLp/6iHnDT4B
Imports Hash f65d8907440e2913e965656f1425d319

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Jul-12 07:00:53
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xab400
SizeOfInitializedData 0x3cc00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000817F0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xed000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 be41b67ab1b0ebe3bf9faf6eb7c071c2
SHA1 f7aa031de808a2f4aeac3f9831bc30ff7564a153
SHA256 bb143498039176d1fff0c3a6adae1e7d2389028192aed1ce8d7673159ecf799c
SHA3 6755cf64bed574ae4fb106e6c6cb2c3d44e8243c0b42c819ea4cd08b9722e9be
VirtualSize 0xab305
VirtualAddress 0x1000
SizeOfRawData 0xab400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.57554

.rdata

MD5 cdedf75f90c622961ebec0074bad870a
SHA1 a797fb0bc88fb3b38c6d31c2b286dc95f34f6132
SHA256 af342e008bd236b13cb918dd80c8c26fedf9ebc9d30a2e1448b581b072701363
SHA3 8da4e70cc570b91cf176597804aa9c6ddab7c65d2dadb014ae08845ec49b601c
VirtualSize 0x2def2
VirtualAddress 0xad000
SizeOfRawData 0x2e000
PointerToRawData 0xab800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.16114

.data

MD5 f7aae1433760db31daa38859a4f2593c
SHA1 1c4a152ae8d2164f28008fc1eca64226bfe101e6
SHA256 c7dc7b665bc093f252692c6822c2c8d79d3897f0be0f872de7698c38860d9636
SHA3 50eb60062ef9228534edee2f82ef01433b7c65e174a1f4f26a7a9243916b8e80
VirtualSize 0x63ec
VirtualAddress 0xdb000
SizeOfRawData 0x2800
PointerToRawData 0xd9800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.675

.pdata

MD5 427a663d3e633dabb842d28bb67be448
SHA1 7e27a7b8c1acb9e02509685da7f6ac9785971c92
SHA256 942cc4013f5d89469f4dd21df3fcda3f6264d37aca13b184f83384258d674f5b
SHA3 7a5d4276ef97b78d3c76a59e51ad192873fcf85c0b25c3994786dcacb0163e0f
VirtualSize 0x7554
VirtualAddress 0xe2000
SizeOfRawData 0x7600
PointerToRawData 0xdc000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.03692

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x100
VirtualAddress 0xea000
SizeOfRawData 0x200
PointerToRawData 0xe3600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 22ba651d05e032820af383aea2d563bb
SHA1 4553cea8b52d79a22f0d094928d45e6dd0c4bd14
SHA256 e2bc4b5599c8c015dbaa5f324fad4752846cb0f315a12e7d3d209716842e9e24
SHA3 4e785e58d9d0f9bf6c4542ce20402d9688c7106ed2d5d05a883a08beecedcdb8
VirtualSize 0x1d8
VirtualAddress 0xeb000
SizeOfRawData 0x200
PointerToRawData 0xe3800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.74579

.reloc

MD5 9415d8ebdd6ed8ac03b78d2f4ae6d52e
SHA1 174bc63d1ab5cb6863ec769c42ce65de48068b04
SHA256 8322702626b012b87e498ae9cf5bc6a94ec83838abd465f7946b04ba3173f62b
SHA3 e0e83ebf005f63b22f90a1474e405adb1b70d2264878419960a097843ddcef9e
VirtualSize 0xc44
VirtualAddress 0xec000
SizeOfRawData 0xe00
PointerToRawData 0xe3a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.17426

Imports

KERNEL32.dll CreateToolhelp32Snapshot
Sleep
GetLastError
HeapReAlloc
CloseHandle
HeapAlloc
HeapDestroy
GetThreadContext
GetProcAddress
GetCurrentProcessId
GetModuleHandleW
FlushInstructionCache
SetThreadContext
OpenThread
GetModuleFileNameA
FindFirstFileA
FindNextFileA
FindClose
FreeLibraryAndExitThread
GetModuleHandleA
DisableThreadLibraryCalls
DeleteFileA
WritePrivateProfileStringA
CreateThread
GetPrivateProfileIntA
GetPrivateProfileStringA
OutputDebugStringA
MultiByteToWideChar
GlobalAlloc
GlobalFree
GlobalLock
WideCharToMultiByte
GlobalUnlock
GetLocaleInfoA
LoadLibraryA
QueryPerformanceFrequency
IsDBCSLeadByte
SuspendThread
QueryPerformanceCounter
WriteConsoleW
SetEndOfFile
HeapSize
GetStringTypeW
SetStdHandle
CreateFileW
GetProcessHeap
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
GetCommandLineA
GetCPInfo
GetOEMCP
GetACP
IsValidCodePage
FindNextFileW
FindFirstFileExW
GetFileSizeEx
GetConsoleOutputCP
WriteFile
FlushFileBuffers
ReadConsoleW
GetConsoleMode
SetFilePointerEx
GetFileType
GetStdHandle
GetCurrentThreadId
Thread32First
Thread32Next
GetCurrentProcess
HeapFree
VirtualProtect
LCMapStringW
HeapCreate
VirtualQuery
GetSystemInfo
VirtualFree
ResumeThread
VirtualAlloc
FreeLibrary
LoadLibraryExW
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
SetUnhandledExceptionFilter
GetStartupInfoW
GetSystemTimeAsFileTime
InitializeSListHead
WaitForSingleObjectEx
GetExitCodeThread
RtlLookupFunctionEntry
RtlUnwindEx
RtlPcToFileHeader
RaiseException
InterlockedFlushSList
SetLastError
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
EncodePointer
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
ExitThread
GetModuleHandleExW
ReadFile
ExitProcess
TerminateProcess
GetModuleFileNameW
IsProcessorFeaturePresent
RtlCaptureContext
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
USER32.dll ScreenToClient
GetAsyncKeyState
FindWindowA
GetCursorPos
SetWindowLongPtrW
DefWindowProcW
GetKeyState
GetMessageExtraInfo
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
LoadCursorW
SetCapture
SetCursor
GetClientRect
IsWindowUnicode
ReleaseCapture
SetCursorPos
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
CallWindowProcW
keybd_event
ADVAPI32.dll GetUserNameA
SHELL32.dll ShellExecuteW
d3d11.dll D3D11CreateDeviceAndSwapChain
IMM32.dll ImmReleaseContext
ImmSetCompositionWindow
ImmSetCandidateWindow
ImmGetContext
D3DCOMPILER_47.dll D3DCompile

Delayed Imports

2

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x173
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.05368
MD5 95ecd4b653fa71bb58c8cb06e4b9c02a
SHA1 2572acbef32cee3cf3fbafb7101c51e52fc71284
SHA256 492e3c8d40bde5bfb80cf9f611fc735b717009f7b3dc6994531fd865e16e3dd6
SHA3 807530f20688414e48da1c1082d53a45ec10f566e19e7e2488ef5ad2b4d11f84

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jul-12 07:00:53
Version 0.0
SizeofData 94
AddressOfRawData 0xce980
PointerToRawData 0xcd180
Referenced File C:\Users\daddysschwanz\source\repos\Version2\x64\Release\Version2.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jul-12 07:00:53
Version 0.0
SizeofData 20
AddressOfRawData 0xce9e0
PointerToRawData 0xcd1e0

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-12 07:00:53
Version 0.0
SizeofData 952
AddressOfRawData 0xce9f4
PointerToRawData 0xcd1f4

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jul-12 07:00:53
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1800cedf8
EndAddressOfRawData 0x1800cee00
AddressOfIndex 0x1800dd838
AddressOfCallbacks 0x1800ad5f8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1800db040

RICH Header

XOR Key 0x58736d7c
Unmarked objects 0
C++ objects (33145) 163
C objects (33145) 27
ASM objects (33145) 23
ASM objects (35721) 10
C objects (35721) 15
C++ objects (35721) 55
Imports (33145) 19
Total imports 189
C objects (LTCG) (36248) 17
Resource objects (36248) 1
Linker (36248) 1

Errors

Leave a comment

No comments yet.