| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Feb-25 19:36:30 |
| Detected languages |
English - United States
|
| FileDescription | geanswag massinha |
| FileVersion | 1.0.0.0 |
| InternalName | version.dll |
| OriginalFilename | version.dll |
| ProductName | geanswag massinha |
| ProductVersion | 1.0.0.0 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 13/71 (Scanned on 2026-08-01 03:46:53) |
AVG:
Other:PUP-gen [PUP]
Avast: Other:PUP-gen [PUP] Avira: PUA/PUP Cynet: Malicious (score: 99) DeepInstinct: MALICIOUS F-Secure: PotentialRisk.PUA/PUP Gridinsoft: Trojan.Win64.Agent.cl MaxSecure: Trojan.Malware.8328611.susgen Skyhigh: BehavesLike.Win64.Injector.dh Sophos: Generic Reputation PUA (PUA) TrellixENS: Artemis!D5FD0BEE7C6B TrendMicro-HouseCall: Trojan.Win64.Gen.TL0101EM26Z9 Webroot: Win.Trojan.Gen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Feb-25 19:36:30 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x1d200 |
| SizeOfInitializedData | 0x44400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000001D674 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x65000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| OPENGL32.dll |
glGetString
wglGetCurrentDC glTexParameterf glTexEnvf glHint glGetIntegerv glGetError glDisable wglGetProcAddress |
|---|---|
| KERNEL32.dll |
VirtualAlloc
RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent VirtualQuery VirtualFree Sleep CreateThread GetSystemDirectoryA DisableThreadLibraryCalls FreeLibrary GetModuleHandleA GetProcAddress LoadLibraryA CloseHandle GetLastError HeapCreate HeapDestroy HeapAlloc HeapReAlloc HeapFree GetCurrentProcess GetCurrentProcessId GetCurrentThreadId OpenThread SuspendThread ResumeThread GetThreadContext SetThreadContext FlushInstructionCache VirtualProtect CreateToolhelp32Snapshot Thread32First Thread32Next GetSystemInfo RtlCaptureContext |
| VCRUNTIME140.dll |
__std_type_info_destroy_list
memset memcpy __C_specific_handler |
| api-ms-win-crt-string-l1-1-0.dll |
strcat_s
|
| api-ms-win-crt-runtime-l1-1-0.dll |
_initterm_e
_execute_onexit_table _initialize_onexit_table _cexit _initialize_narrow_environment _configure_narrow_argv _seh_filter_dll _initterm |
| Ordinal | 1 |
|---|---|
| Address | 0x1a00 |
| Ordinal | 2 |
|---|---|
| Address | 0x1a10 |
| Ordinal | 3 |
|---|---|
| Address | 0x1a20 |
| Ordinal | 4 |
|---|---|
| Address | 0x1a30 |
| Ordinal | 5 |
|---|---|
| Address | 0x1a40 |
| Ordinal | 6 |
|---|---|
| Address | 0x1a50 |
| Ordinal | 7 |
|---|---|
| Address | 0x1a00 |
| Ordinal | 8 |
|---|---|
| Address | 0x1a10 |
| Ordinal | 9 |
|---|---|
| Address | 0x1a20 |
| Ordinal | 10 |
|---|---|
| Address | 0x1a30 |
| Ordinal | 11 |
|---|---|
| Address | 0x1a40 |
| Ordinal | 12 |
|---|---|
| Address | 0x1a50 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| FileDescription | geanswag massinha |
| FileVersion (#2) | 1.0.0.0 |
| InternalName | version.dll |
| OriginalFilename | version.dll |
| ProductName | geanswag massinha |
| ProductVersion (#2) | 1.0.0.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Feb-25 19:36:30 |
| Version | 0.0 |
| SizeofData | 600 |
| AddressOfRawData | 0x36a48 |
| PointerToRawData | 0x35048 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x18003b500 |
| XOR Key | 0x561ad3e6 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 6 |
| Imports (35207) | 2 |
| ASM objects (35207) | 3 |
| C objects (35207) | 8 |
| C++ objects (35207) | 19 |
| Imports (30795) | 5 |
| Total imports | 83 |
| C objects (35222) | 5 |
| C++ objects (35222) | 2 |
| Exports (35222) | 1 |
| Resource objects (35222) | 1 |
| 151 | 1 |
| Linker (35222) | 1 |
No comments yet.