| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Aug-20 23:08:12 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\Elijah\Desktop\srcs\steeze free\x64\Release\Steeze.pdb
|
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses known Mersenne Twister constants |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 42/70 (Scanned on 2026-09-24 13:17:23) |
ALYac:
Gen:Variant.Tedy.989081
APEX: Malicious AVG: Win64:MalwareX-gen [Cryp] AhnLab-V3: Trojan/Win.Generic.R785946 Alibaba: Trojan:Win64/GenKryptik.a5a6e76c Arcabit: Trojan.Tedy.DF1799 Avast: Win64:MalwareX-gen [Cryp] Avira: TR/W64.MalwareX BitDefender: Gen:Variant.Tedy.989081 Bkav: W32.Malware.20AF7D66 CTX: exe.trojan.malwarex Cylance: Unsafe Cynet: Malicious (score: 99) DeepInstinct: MALICIOUS ESET-NOD32: Win64/GenKryptik_AGen.EPA trojan Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Tedy.989081 (B) F-Secure: Trojan.TR/W64.MalwareX Fortinet: W64/GenKryptik_AGen.EPA!tr GData: Gen:Variant.Tedy.989081 Google: Detected K7AntiVirus: Trojan ( 006e3af81 ) K7GW: Trojan ( 006e3af81 ) Lionic: Trojan.Win32.Generic.4!c Malwarebytes: Malware.AI.4234359912 McAfeeD: ti!CBBDD190773E MicroWorld-eScan: Gen:Variant.Tedy.989081 Microsoft: Trojan:Win32/Ravartar!rfn Paloalto: generic.ml Panda: Trj/CI.A Rising: Trojan.Kryptik!8.8 (TFE:5:qrEeEGfeCzP) SentinelOne: Static AI - Suspicious PE Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence Tencent: Malware.Win32.Gencirc.14b42daf TrellixENS: Artemis!A333E557CEA7 TrendMicro: Trojan.Win64.TEDY.TL0101HN26ZZ TrendMicro-HouseCall: Trojan.Win64.TEDY.TL0101HN26ZZ VIPRE: Gen:Variant.Tedy.989081 Varist: W64/ABApplication.PTPS-5976 ViRobot: Trojan.Win.Z.Upatre.901120 alibabacloud: Trojan:Win/GenKryptik_AGen.EXZ |
| MD5 | a333e557cea7e1e915000715b009491d 🔍 |
|---|---|
| SHA1 | 9d10009823d779b54405fa1263abea4dfbceeeec 🔍 |
| SHA256 | cbbdd190773e63df3bce6e10b3f50650af347154d18fc121be51a6b39c142996 🔍 |
| SHA3 | 11ee28e23f3b1eb8d5416ff8381c26f10c47c7281a2cc1efc5331ebf0a4312ee 🔍 |
| SSDeep | 24576:mp7qtOjyaylDXFLQxT9ynstXfsQi+nIC5iIdh+YW232:mpWMyaylzWtQOkN+nz5iEh+z232 🔍 |
| Imports Hash | 12ae47f6dc01672fdaeecb561b85ce10 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Aug-20 23:08:12 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x8a400 |
| SizeOfInitializedData | 0x53800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000891B8 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xe3000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 157b171671b6cc6694642a93823dcf37 🔍 |
|---|---|
| SHA1 | dbf8157df4f4d7b0ef7ca5804ef3069ee9c8a33c 🔍 |
| SHA256 | e5edc5963c1ecc1ddf67b8e3e7e3e279076bfe86566afa99e1c7e534f0613686 🔍 |
| SHA3 | 7ecd80094ff2b13c2b3673974f4121e9eb4d0620afc08ea930b2d23e35687c0d 🔍 |
| VirtualSize | 0x8a383 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x8a400 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.52913 |
| MD5 | 9c044c4952a6251cf31f1dddc7c37ecd 🔍 |
|---|---|
| SHA1 | a2716e339224c547831a3fe09a3cf6d9507ea4c8 🔍 |
| SHA256 | cb73fa974f2e9bbe0c0e111b609a84dfc83011b9aceb0db5e7bb0bc4862f49a9 🔍 |
| SHA3 | 11946964de84378c1889cf26ae627697a40bdb54cf83737e388af7462156a27f 🔍 |
| VirtualSize | 0x17370 |
| VirtualAddress | 0x8c000 |
| SizeOfRawData | 0x17400 |
| PointerToRawData | 0x8a800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.07785 |
| MD5 | 930dcd896143814499b8d14eba1350c5 🔍 |
|---|---|
| SHA1 | bf73fc7be4533ab691290cf0b4e8bef495f4da53 🔍 |
| SHA256 | 009eb61418744fad720a72bde194869495f7a7ba231b318cfb507d92d2ffba8e 🔍 |
| SHA3 | 3f5f87e91db2bee29776c16eef19c8ae7e76d5925edf01f3031c8e0032919e56 🔍 |
| VirtualSize | 0x36a80 |
| VirtualAddress | 0xa4000 |
| SizeOfRawData | 0x34c00 |
| PointerToRawData | 0xa1c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 6.87669 |
| MD5 | 518c36a8696bc4d9af4384966ff29c8e 🔍 |
|---|---|
| SHA1 | 05ef2e96e4ef354c2c98093640d61dbc2e5af447 🔍 |
| SHA256 | 87c01c9da42ca6b55fa7e54a5b9f2b4de663979585e6e587bf9a48f116886020 🔍 |
| SHA3 | e3bf4f447c446b2eae19d977937ebc5f7dadb9b4c629971b84a50b6c928c9aa6 🔍 |
| VirtualSize | 0x510c |
| VirtualAddress | 0xdb000 |
| SizeOfRawData | 0x5200 |
| PointerToRawData | 0xd6800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.95332 |
| MD5 | 9525f77b51081d2cfad69be410a7bfa1 🔍 |
|---|---|
| SHA1 | de2c307e7551a0753c6cbb6450fcc418e8286b44 🔍 |
| SHA256 | 2edcb81f68ab9ccba4df63783a92503a4d162a8da6e3e1ea506ada9a1dd7585c 🔍 |
| SHA3 | 5d945e77cfa13f012dc8f5462f3b3e1f5bdfa0403e40477e227d04ae8039bfd1 🔍 |
| VirtualSize | 0x1e8 |
| VirtualAddress | 0xe1000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0xdba00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.77204 |
| MD5 | 6fbacdb7684b1a1e61b32ea9892fca4c 🔍 |
|---|---|
| SHA1 | f4d45aaa01c83bc128e0b9cbbb5bb83859cf9b8e 🔍 |
| SHA256 | a7c50811b89577dce602c18d06cb8dd80bfa0dc14f3af4e5699ff97e5368e3ee 🔍 |
| SHA3 | 5b0eef5540f043fdf83436f9fda604d549929ae85d8feae8cc0667195edcab5f 🔍 |
| VirtualSize | 0x27c |
| VirtualAddress | 0xe2000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0xdbc00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 3.92295 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| XINPUT1_4.dll |
#2
|
| KERNEL32.dll |
GetCurrentProcess
GetCurrentThreadId CreateToolhelp32Snapshot IsDebuggerPresent Sleep WaitForSingleObject ReadFile CancelIo SetConsoleTextAttribute SetConsoleTitleA GetStdHandle DeviceIoControl CreateFileW CreateEventW GetLastError Process32NextW Process32FirstW GetOverlappedResult Beep CreateProcessA lstrcmpiW MultiByteToWideChar GlobalAlloc GlobalFree WideCharToMultiByte GlobalUnlock GetLocaleInfoA QueryPerformanceFrequency FreeLibrary QueryPerformanceCounter TerminateProcess GetModuleHandleA WakeAllConditionVariable GetModuleHandleW GetCurrentProcessId GetProcAddress CloseHandle LoadLibraryA AcquireSRWLockExclusive ReleaseSRWLockExclusive GlobalLock SleepConditionVariableSRW UnhandledExceptionFilter SetUnhandledExceptionFilter GetSystemTimeAsFileTime InitializeSListHead IsProcessorFeaturePresent |
| USER32.dll |
ScreenToClient
GetKeyState MessageBoxA GetCursorPos FindWindowA ClientToScreen GetKeyboardLayout GetForegroundWindow LoadCursorW SetCursor GetClientRect GetWindowLongA UpdateWindow PeekMessageW SetMenu SetWindowLongA DispatchMessageW GetAsyncKeyState ShowWindow GetSystemMetrics SetWindowPos SetClipboardData GetClipboardData EmptyClipboard CloseClipboard OpenClipboard SetCursorPos SetLayeredWindowAttributes TranslateMessage |
| SHELL32.dll |
ShellExecuteA
|
| ole32.dll |
CoInitialize
|
| MSVCP140.dll |
_Query_perf_counter
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?uncaught_exceptions@std@@YAHXZ ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A ?_Random_device@std@@YAIXZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z _Query_perf_frequency ?_Xlength_error@std@@YAXPEBD@Z |
| ntdll.dll |
RtlCaptureContext
RtlVirtualUnwind RtlLookupFunctionEntry |
| HID.DLL |
HidD_GetHidGuid
HidD_GetPreparsedData HidP_GetCaps HidD_GetAttributes HidD_FreePreparsedData |
| SETUPAPI.dll |
SetupDiGetClassDevsW
SetupDiEnumDeviceInterfaces SetupDiDestroyDeviceInfoList SetupDiGetDeviceInterfaceDetailW |
| IMM32.dll |
ImmSetCompositionWindow
ImmReleaseContext ImmGetContext ImmSetCandidateWindow |
| D3DCOMPILER_47.dll |
D3DCompile
|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
memcmp
memchr memset _CxxThrowException __C_specific_handler __current_exception_context __current_exception strchr strstr __std_terminate __std_exception_destroy memmove memcpy __std_exception_copy |
| api-ms-win-crt-runtime-l1-1-0.dll |
_exit
__p___argc __p___argv _c_exit _register_thread_local_exe_atexit_callback _initterm _get_initial_narrow_environment terminate _set_app_type _invoke_watson exit _seh_filter_exe _cexit _crt_atexit _initterm_e _configure_narrow_argv _register_onexit_function _initialize_onexit_table _initialize_narrow_environment system |
| api-ms-win-crt-string-l1-1-0.dll |
toupper
strncmp strcmp strncpy |
| api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vsscanf
_wfopen fclose __stdio_common_vfprintf fseek __acrt_iob_func ftell __stdio_common_vsprintf fwrite __p__commode _set_fmode fflush fread |
| api-ms-win-crt-filesystem-l1-1-0.dll |
remove
|
| api-ms-win-crt-heap-l1-1-0.dll |
realloc
_set_new_mode malloc free _callnewh |
| api-ms-win-crt-convert-l1-1-0.dll |
strtol
atof |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-math-l1-1-0.dll |
pow
powf fmaxf ldexp fmodf tan sinf sqrt cosf ceilf sqrtf logf atan2f atan2 asin __setusermatherr acosf log |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x188 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.89623 |
| MD5 | b8e76ddb52d0eb41e972599ff3ca431b 🔍 |
| SHA1 | fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍 |
| SHA256 | 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍 |
| SHA3 | 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-20 23:08:12 |
| Version | 0.0 |
| SizeofData | 88 |
| AddressOfRawData | 0x98438 |
| PointerToRawData | 0x96c38 |
| Referenced File | C:\Users\Elijah\Desktop\srcs\steeze free\x64\Release\Steeze.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-20 23:08:12 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x98490 |
| PointerToRawData | 0x96c90 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-20 23:08:12 |
| Version | 0.0 |
| SizeofData | 912 |
| AddressOfRawData | 0x984a4 |
| PointerToRawData | 0x96ca4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-20 23:08:12 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x140098858 |
|---|---|
| EndAddressOfRawData | 0x140098888 |
| AddressOfIndex | 0x1400d91bc |
| AddressOfCallbacks | 0x14008c7c0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400a4040 |
| XOR Key | 0x64da92a2 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 20 |
| Imports (35207) | 6 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 37 |
| Imports (33145) | 31 |
| Total imports | 376 |
| C++ objects (LTCG) (35221) | 26 |
| Resource objects (35221) | 1 |
| Linker (35221) | 1 |
No comments yet.