| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Sep-25 21:42:12 |
| Detected languages |
English - United States
|
| TLS Callbacks | 2 callback(s) detected. |
| Debug artifacts |
...................................................................................................................
|
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA256 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 16/66 (Scanned on 2026-09-27 21:41:59) |
ALYac:
Trojan.GenericKD.81583065
Arcabit: Trojan.Generic.D4DCDBD9 BitDefender: Trojan.GenericKD.81583065 CTX: dll.trojan.generic Cynet: Malicious (score: 100) Emsisoft: Trojan.GenericKD.81583065 (B) Fortinet: PossibleThreat.RF GData: Trojan.GenericKD.81583065 Google: Detected Ikarus: Trojan.W64.MalwareX McAfeeD: ti!CD29C7ECF562 MicroWorld-eScan: Trojan.GenericKD.81583065 Microsoft: Trojan:Win32/Wacatac.B!ml Trapmine: suspicious.low.ml.score TrellixENS: Artemis!714F7872C2E4 VIPRE: Trojan.GenericKD.81583065 |
| MD5 | 714f7872c2e441e5e3fbf80315c63fa5 🔍 |
|---|---|
| SHA1 | 24da3004c96f181fd33969e7ed08079e3ae5326d 🔍 |
| SHA256 | cd29c7ecf5623aa33d05d771b3fd7b7f79c51de8d8a97b7ea856d9dd7ee9d854 🔍 |
| SHA3 | 97de236ea672802e1c9c5d0af1ebac1f74abebea7ec6e1a763ca117a6928682b 🔍 |
| SSDeep | 24576:8DPTH/ol3r+GqaeNz26ahBAdEZKTQpfinG2zpD84Ezcn0SlFQ:yPTo8GCz26ahBAdsInG2J+zcn 🔍 |
| Imports Hash | c9aefb2d9198a04f89664284def6fb9e 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Sep-25 21:42:12 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x100e00 |
| SizeOfInitializedData | 0x8e400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000C9170 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x193000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 0dd2e80dee6773b44fbb9eb9389bb06b 🔍 |
|---|---|
| SHA1 | 5763b7ff0d29aaa776adf548def6434585d50612 🔍 |
| SHA256 | 0af9bc930f7de383d5964f4ff21a3d5e659693e0c54b5c0b261944c3a45eea1a 🔍 |
| SHA3 | 499e40d71be8c614a4bf56af26119aa879e7b26973c0b6e1dc2e986791e53340 🔍 |
| VirtualSize | 0x100c4c |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x100e00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.55791 |
| MD5 | 4445d736dafe5e34e3732d94cc392044 🔍 |
|---|---|
| SHA1 | bb9b09761efd6c5e7738bcf8c3946684995fe725 🔍 |
| SHA256 | de0482c787c45b79cb6691c16c3cda64c5ad680764b257bbf899717085e9a015 🔍 |
| SHA3 | a5701bebba3e971407512e85c0473288597b74351417e90322339c6e13ce0d9c 🔍 |
| VirtualSize | 0x75afa |
| VirtualAddress | 0x102000 |
| SizeOfRawData | 0x75c00 |
| PointerToRawData | 0x101200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.73391 |
| MD5 | 0e84cfd56853784624a4882caba42293 🔍 |
|---|---|
| SHA1 | 681416d4336a32b884cbfb50c7868a7088243315 🔍 |
| SHA256 | b701c71f66cec58463bade147e2a900548cd7be4eeae0b683335173d3059cb07 🔍 |
| SHA3 | 93605b2b279463a89d2c5a6506c66c503a0d8590c862a5141f3cb2fc17bb303f 🔍 |
| VirtualSize | 0x5e88 |
| VirtualAddress | 0x178000 |
| SizeOfRawData | 0x2600 |
| PointerToRawData | 0x176e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 2.88013 |
| MD5 | 818b3c24b2fcd903c793f7f46ad24462 🔍 |
|---|---|
| SHA1 | 938122db36ff3bf9c82c75ac551398205a0def33 🔍 |
| SHA256 | 4a4f78e365ff89a5a62f8a1db6a0a0b791012d05f5219df2fe5c5530f941f539 🔍 |
| SHA3 | 85a9d7aaf98aefc006bb55230fe1b0ea5a3d413f096d2701e1c4ec111a349b3c 🔍 |
| VirtualSize | 0xa398 |
| VirtualAddress | 0x17e000 |
| SizeOfRawData | 0xa400 |
| PointerToRawData | 0x179400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.11397 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x100 |
| VirtualAddress | 0x189000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x183800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 0f8b2f050e005d83645a7f1dd0409892 🔍 |
|---|---|
| SHA1 | 1c258ab4faae33c02d28566b39276967c3540409 🔍 |
| SHA256 | 80320d1d5405658d12ff0f0237e4e9382ca1d4628140141f98af0155ce4d9aa1 🔍 |
| SHA3 | bd5171bfa0c2d94a39711da54653c39616a3481e10b2c13916bd79560916d4e2 🔍 |
| VirtualSize | 0x4e20 |
| VirtualAddress | 0x18a000 |
| SizeOfRawData | 0x5000 |
| PointerToRawData | 0x183a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 7.9119 |
| MD5 | 1fb4cf5fa51756022569e081997744b0 🔍 |
|---|---|
| SHA1 | b689a493f3cb966379216da22059e935d69ffc5a 🔍 |
| SHA256 | 1f813463516904d407df61ee67ee1e7a4a3c52efe20256420b2d60e1a3c86cb8 🔍 |
| SHA3 | 4f3b1b2d0a7e919d6bbe545e695094d0be8c4e9d25438d8d09307ca553f4834d 🔍 |
| VirtualSize | 0x3120 |
| VirtualAddress | 0x18f000 |
| SizeOfRawData | 0x3200 |
| PointerToRawData | 0x188a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.38913 |
| d3d12.dll |
#101
|
|---|---|
| dxgi.dll |
CreateDXGIFactory1
|
| D3DCOMPILER_47.dll |
D3DCompile
|
| IMM32.dll |
ImmGetContext
ImmReleaseContext ImmSetCompositionWindow ImmSetCandidateWindow |
| SHELL32.dll |
SHGetKnownFolderPath
ShellExecuteW |
| ole32.dll |
CoCreateInstance
CoUninitialize CoInitializeEx CoTaskMemFree |
| KERNEL32.dll |
GetProcessHeap
SetStdHandle HeapSize SetEnvironmentVariableW GetTimeZoneInformation ReadConsoleW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetOEMCP SizeofResource GetPhysicallyInstalledSystemMemory GetModuleHandleExW GetTickCount64 LockResource GetNativeSystemInfo LoadResource FindResourceW GetProcAddress GlobalMemoryStatusEx GetModuleHandleW CloseHandle CreateThread CreateDirectoryW WritePrivateProfileStringW GetModuleFileNameW GetFileAttributesW GetPrivateProfileStringW GetLastError GetCurrentProcessId GetModuleHandleA CreateToolhelp32Snapshot Module32FirstW MoveFileExW WideCharToMultiByte Module32NextW GetTickCount VirtualQuery WaitForSingleObject GetCurrentThreadId CreateEventW OutputDebugStringA MultiByteToWideChar GlobalAlloc GlobalFree GlobalLock GlobalUnlock LoadLibraryA GetLocaleInfoA QueryPerformanceFrequency IsDBCSLeadByte FreeLibrary QueryPerformanceCounter SetLastError WriteFile WriteConsoleW CreateFileW Sleep GetLocalTime VirtualFree VirtualAlloc GetSystemInfo HeapCreate VirtualProtect HeapFree GetCurrentProcess Thread32Next Thread32First SuspendThread ResumeThread HeapReAlloc HeapAlloc GetThreadContext FlushInstructionCache SetThreadContext OpenThread EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW LoadLibraryExW GetConsoleMode GetConsoleOutputCP FlushFileBuffers SetFilePointerEx GetFileSizeEx GetFileType GetStdHandle UnhandledExceptionFilter IsDebuggerPresent RtlVirtualUnwind RtlCaptureContext IsValidCodePage TerminateProcess ExitProcess IsProcessorFeaturePresent ReadFile FlsFree FlsSetValue FlsGetValue FlsAlloc InterlockedFlushSList RaiseException RtlPcToFileHeader RtlUnwindEx RtlLookupFunctionEntry InitializeSListHead GetSystemTimeAsFileTime GetStartupInfoW SetUnhandledExceptionFilter SleepConditionVariableSRW WakeAllConditionVariable GetCPInfo GetACP SetEndOfFile GetEnvironmentVariableW RtlUnwind LocalFree FormatMessageA GetLocaleInfoEx FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesExW CreateFile2 AreFileApisANSI GetFileInformationByHandleEx ReleaseSRWLockExclusive AcquireSRWLockExclusive EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection EncodePointer DecodePointer LCMapStringEx GetStringTypeW |
| USER32.dll |
UnregisterClassW
GetWindowLongPtrW RegisterClassW DefWindowProcW GetKeyState GetMessageExtraInfo GetCapture TrackMouseEvent GetKeyboardLayout LoadCursorW SetCapture IsWindowUnicode ReleaseCapture OpenClipboard SetWindowLongPtrW EmptyClipboard GetClipboardData SetClipboardData PostMessageW ScreenToClient GetCursor IsWindow ClientToScreen ClipCursor SetCursor GetClientRect RegisterWindowMessageW IsIconic SetCursorPos GetWindowThreadProcessId MapVirtualKeyW GetAsyncKeyState GetForegroundWindow SendInput DestroyWindow CreateWindowExW CloseClipboard CallWindowProcW GetCursorPos |
| Ordinal | 1 |
|---|---|
| Address | 0x52760 |
| Ordinal | 2 |
|---|---|
| Address | 0x52b10 |
| Ordinal | 3 |
|---|---|
| Address | 0x518b0 |
| Ordinal | 4 |
|---|---|
| Address | 0xc1f90 |
| Ordinal | 5 |
|---|---|
| Address | 0x52ad0 |
| Ordinal | 6 |
|---|---|
| Address | 0x52770 |
| Ordinal | 7 |
|---|---|
| Address | 0x52190 |
| Ordinal | 8 |
|---|---|
| Address | 0x52aa0 |
| Ordinal | 9 |
|---|---|
| Address | 0x52b00 |
| Ordinal | 10 |
|---|---|
| Address | 0xc1fb0 |
| Type |
RT_RCDATA
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x4c00 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 7.98018 |
| Detected Filetype | PNG graphic file |
| MD5 | 39c0c88742bd26f1daa0a8051881e572 🔍 |
| SHA1 | 3f0fa448d2e1fb1722f4bc8a6c66d48795d7ef40 🔍 |
| SHA256 | ead29f8c2b8d9ab5f7f2f2c10b90dfee19e331b71a7180cca87db53a0e5c7dae 🔍 |
| SHA3 | 03ab084f4453c0efbb01c7ef1b6add042438fe578656acc5165008949b7a33be 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Sep-25 21:42:12 |
| Version | 0.0 |
| SizeofData | 140 |
| AddressOfRawData | 0x165228 |
| PointerToRawData | 0x164428 |
| Referenced File | ................................................................................................................... |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Sep-25 21:42:12 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x1652b4 |
| PointerToRawData | 0x1644b4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Sep-25 21:42:12 |
| Version | 0.0 |
| SizeofData | 1108 |
| AddressOfRawData | 0x1652c8 |
| PointerToRawData | 0x1644c8 |
| StartAddressOfRawData | 0x180165770 |
|---|---|
| EndAddressOfRawData | 0x1801658c8 |
| AddressOfIndex | 0x18017a9c8 |
| AddressOfCallbacks | 0x180102840 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks |
0x00000001800C8C00
0x00000001800C8CE0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1801780c0 |
| XOR Key | 0x6726201e |
|---|---|
| Unmarked objects | 0 |
| C objects (33145) | 34 |
| ASM objects (33145) | 23 |
| ASM objects (35721) | 10 |
| C objects (35721) | 15 |
| C++ objects (35721) | 86 |
| C objects (CVTCIL) (33145) | 1 |
| Imports (33145) | 21 |
| Total imports | 230 |
| C++ objects (33145) | 184 |
| C++ objects (LTCG) (36252) | 18 |
| Exports (36252) | 1 |
| Resource objects (36252) | 1 |
| 151 | 1 |
| Linker (36252) | 1 |
No comments yet.