| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Mar-21 02:38:52 |
| Detected languages |
English - United States
|
| Suspicious | This PE is packed with VMProtect |
Section .textbss is both writable and executable.
Unusual section name found: .msvcjmc Unusual section name found: .fptable Unusual section name found: .vmp0 Unusual section name found: .vmp1 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 18/70 (Scanned on 2026-03-31 18:31:04) |
Bkav:
W32.AIDetectMalware
CrowdStrike: win/malicious_confidence_70% (D) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS ESET-NOD32: Win32/Packed.VMProtect.ACR trojan Elastic: malicious (high confidence) Gridinsoft: Trojan.Heur!.03296020 MaxSecure: Trojan.Malware.300983.susgen McAfeeD: ti!C8793CC86FAD Microsoft: Trojan:Win32/Sabsik.EN.A!ml Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Malicious PE Skyhigh: BehavesLike.Win32.Injector.rc Sophos: Generic ML PUA (PUA) Symantec: ML.Attribute.HighConfidence Trapmine: malicious.high.ml.score VBA32: BScope.Trojan.Ymacco |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 12 |
| TimeDateStamp | 2026-Mar-21 02:38:52 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x17ce00 |
| SizeOfInitializedData | 0x4a400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x007E0E56 (Section: .vmp1) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x1000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x8d3000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WS2_32.dll |
recv
connect send setsockopt closesocket freeaddrinfo getaddrinfo WSACleanup WSAStartup socket |
|---|---|
| KERNEL32.dll |
ReadFile
GetConsoleMode GetConsoleOutputCP FlushFileBuffers GetDiskFreeSpaceExA CloseHandle QueryPerformanceCounter QueryPerformanceFrequency CreateThread OpenProcess DisableThreadLibraryCalls GetLogicalDriveStringsA QueryFullProcessImageNameA GetComputerNameA CreateToolhelp32Snapshot ReadConsoleW Process32Next EnumSystemLocalesW SetStdHandle SetFilePointerEx GetFileSizeEx SetEnvironmentVariableW FreeEnvironmentStringsW CreateFileW GetTimeZoneInformation FindClose FindFirstFileExW FindNextFileW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetOEMCP GetUserDefaultLCID IsValidLocale GetLocaleInfoW GetACP Process32First GetLastError FormatMessageA WideCharToMultiByte EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection LocalFree GetLocaleInfoEx EncodePointer DecodePointer MultiByteToWideChar LCMapStringEx GetStringTypeW CompareStringEx GetCPInfo GetCurrentThreadId IsProcessorFeaturePresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsDebuggerPresent RaiseException GetCurrentProcessId GetSystemTimeAsFileTime InitializeSListHead GetStartupInfoW GetModuleHandleW LCMapStringW HeapAlloc HeapFree GetProcessHeap VirtualQuery FreeLibrary GetProcAddress RtlUnwind InterlockedPushEntrySList InterlockedFlushSList GetModuleFileNameW LoadLibraryExW SetLastError InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree HeapValidate GetSystemInfo GetModuleHandleExW ExitProcess GetCurrentThread HeapReAlloc HeapSize HeapQueryInformation GetStdHandle GetFileType WriteFile OutputDebugStringW WriteConsoleW SetConsoleCtrlHandler GetTempPathW FlsAlloc FlsGetValue FlsSetValue FlsFree IsThreadAFiber VirtualProtect GetDateFormatW GetTimeFormatW CompareStringW IsValidCodePage |
| USER32.dll |
GetWindowTextA
EnumWindows GetWindowThreadProcessId IsWindowVisible |
| ADVAPI32.dll |
RegCloseKey
RegQueryValueExA RegOpenKeyExA GetUserNameA |
| ole32.dll |
CoCreateInstance
CoInitializeSecurity CoInitializeEx |
| OLEAUT32.dll |
SysAllocString
SysFreeString VariantClear GetErrorInfo VariantInit VariantChangeType SetErrorInfo CreateErrorInfo |
| IPHLPAPI.DLL |
GetAdaptersInfo
|
| WTSAPI32.dll |
WTSSendMessageW
|
| KERNEL32.dll (#2) |
ReadFile
GetConsoleMode GetConsoleOutputCP FlushFileBuffers GetDiskFreeSpaceExA CloseHandle QueryPerformanceCounter QueryPerformanceFrequency CreateThread OpenProcess DisableThreadLibraryCalls GetLogicalDriveStringsA QueryFullProcessImageNameA GetComputerNameA CreateToolhelp32Snapshot ReadConsoleW Process32Next EnumSystemLocalesW SetStdHandle SetFilePointerEx GetFileSizeEx SetEnvironmentVariableW FreeEnvironmentStringsW CreateFileW GetTimeZoneInformation FindClose FindFirstFileExW FindNextFileW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetOEMCP GetUserDefaultLCID IsValidLocale GetLocaleInfoW GetACP Process32First GetLastError FormatMessageA WideCharToMultiByte EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection LocalFree GetLocaleInfoEx EncodePointer DecodePointer MultiByteToWideChar LCMapStringEx GetStringTypeW CompareStringEx GetCPInfo GetCurrentThreadId IsProcessorFeaturePresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsDebuggerPresent RaiseException GetCurrentProcessId GetSystemTimeAsFileTime InitializeSListHead GetStartupInfoW GetModuleHandleW LCMapStringW HeapAlloc HeapFree GetProcessHeap VirtualQuery FreeLibrary GetProcAddress RtlUnwind InterlockedPushEntrySList InterlockedFlushSList GetModuleFileNameW LoadLibraryExW SetLastError InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree HeapValidate GetSystemInfo GetModuleHandleExW ExitProcess GetCurrentThread HeapReAlloc HeapSize HeapQueryInformation GetStdHandle GetFileType WriteFile OutputDebugStringW WriteConsoleW SetConsoleCtrlHandler GetTempPathW FlsAlloc FlsGetValue FlsSetValue FlsFree IsThreadAFiber VirtualProtect GetDateFormatW GetTimeFormatW CompareStringW IsValidCodePage |
| USER32.dll (#2) |
GetWindowTextA
EnumWindows GetWindowThreadProcessId IsWindowVisible |
| KERNEL32.dll (#3) |
ReadFile
GetConsoleMode GetConsoleOutputCP FlushFileBuffers GetDiskFreeSpaceExA CloseHandle QueryPerformanceCounter QueryPerformanceFrequency CreateThread OpenProcess DisableThreadLibraryCalls GetLogicalDriveStringsA QueryFullProcessImageNameA GetComputerNameA CreateToolhelp32Snapshot ReadConsoleW Process32Next EnumSystemLocalesW SetStdHandle SetFilePointerEx GetFileSizeEx SetEnvironmentVariableW FreeEnvironmentStringsW CreateFileW GetTimeZoneInformation FindClose FindFirstFileExW FindNextFileW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetOEMCP GetUserDefaultLCID IsValidLocale GetLocaleInfoW GetACP Process32First GetLastError FormatMessageA WideCharToMultiByte EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection LocalFree GetLocaleInfoEx EncodePointer DecodePointer MultiByteToWideChar LCMapStringEx GetStringTypeW CompareStringEx GetCPInfo GetCurrentThreadId IsProcessorFeaturePresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsDebuggerPresent RaiseException GetCurrentProcessId GetSystemTimeAsFileTime InitializeSListHead GetStartupInfoW GetModuleHandleW LCMapStringW HeapAlloc HeapFree GetProcessHeap VirtualQuery FreeLibrary GetProcAddress RtlUnwind InterlockedPushEntrySList InterlockedFlushSList GetModuleFileNameW LoadLibraryExW SetLastError InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree HeapValidate GetSystemInfo GetModuleHandleExW ExitProcess GetCurrentThread HeapReAlloc HeapSize HeapQueryInformation GetStdHandle GetFileType WriteFile OutputDebugStringW WriteConsoleW SetConsoleCtrlHandler GetTempPathW FlsAlloc FlsGetValue FlsSetValue FlsFree IsThreadAFiber VirtualProtect GetDateFormatW GetTimeFormatW CompareStringW IsValidCodePage |
| USER32.dll (#3) |
GetWindowTextA
EnumWindows GetWindowThreadProcessId IsWindowVisible |
| Ordinal | 1 |
|---|---|
| Address | 0xb6d82 |
| Ordinal | 2 |
|---|---|
| Address | 0xb598c |
| Ordinal | 3 |
|---|---|
| Address | 0xb6a80 |
| Ordinal | 4 |
|---|---|
| Address | 0xb6f44 |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1026b040 |
| SEHandlerTable | 0 |
| SEHandlerCount | 0 |
No comments yet.