| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Mar-19 00:08:57 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses known Mersenne Twister constants |
| Suspicious | The PE contains functions most legitimate programs don't use. |
Possibly launches other programs:
|
| Malicious | VirusTotal score: 10/72 (Scanned on 2026-03-22 14:12:53) |
APEX:
Malicious
Bkav: W64.AIDetectMalware CrowdStrike: win/malicious_confidence_90% (W) DeepInstinct: MALICIOUS Elastic: malicious (high confidence) Malwarebytes: Malware.AI.4243833521 MaxSecure: Trojan.Malware.300983.susgen McAfeeD: ti!CEBC3C93D081 Symantec: ML.Attribute.HighConfidence TrellixENS: Artemis!1682BDAC6744 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Mar-19 00:08:57 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x16f600 |
| SizeOfInitializedData | 0x32600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000016D42C (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1a6000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WININET.dll |
InternetCloseHandle
InternetOpenA InternetReadFile InternetOpenUrlA |
|---|---|
| KERNEL32.dll |
LocalFree
FormatMessageA GetLocaleInfoEx RemoveVectoredExceptionHandler WriteProcessMemory WriteFile CreateFileW GetLastError LoadLibraryA CloseHandle GetModuleHandleA GetTempPathA CreateDirectoryW FindClose GetFileInformationByHandleEx MultiByteToWideChar WideCharToMultiByte ReleaseSRWLockExclusive AcquireSRWLockExclusive SleepConditionVariableSRW Sleep GetCurrentThreadId WakeAllConditionVariable RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent QueryPerformanceCounter GetCurrentProcessId GetSystemTimeAsFileTime InitializeSListHead GetModuleHandleW AreFileApisANSI GetFileAttributesExW FindFirstFileW |
| USER32.dll |
MessageBoxA
|
| MSVCP140.dll |
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z ?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z ?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@G@Z ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?width@ios_base@std@@QEAA_J_J@Z ?width@ios_base@std@@QEBA_JXZ ?flags@ios_base@std@@QEBAHXZ ?good@ios_base@std@@QEBA_NXZ ??7ios_base@std@@QEBA_NXZ ??Bios_base@std@@QEBA_NXZ ?always_noconv@codecvt_base@std@@QEBA_NXZ ?_Getcvt@_Locinfo@std@@QEBA?AU_Cvtvec@@XZ ?_Xbad_function_call@std@@YAXXZ ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z ?id@?$numpunct@D@std@@2V0locale@2@A ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z ??1facet@locale@std@@MEAA@XZ ??0facet@locale@std@@IEAA@_K@Z ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ ?_Incref@facet@locale@std@@UEAAXXZ ?_Gettrue@_Locinfo@std@@QEBAPEBDXZ ?_Getfalse@_Locinfo@std@@QEBAPEBDXZ ??1_Locinfo@std@@QEAA@XZ ??0_Locinfo@std@@QEAA@PEBD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ _Mtx_unlock _Query_perf_counter _Mtx_lock ?_Syserror_map@std@@YAPEBDH@Z ?_Xlength_error@std@@YAXPEBD@Z ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Winerror_map@std@@YAHH@Z ?_Xout_of_range@std@@YAXPEBD@Z ?_Id_cnt@id@locale@std@@0HA ?_Xinvalid_argument@std@@YAXPEBD@Z ?_Xbad_alloc@std@@YAXXZ ?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?uncaught_exceptions@std@@YAHXZ ?_Throw_Cpp_error@std@@YAXH@Z ??0_Lockit@std@@QEAA@H@Z ??1_Lockit@std@@QEAA@XZ _Query_perf_frequency ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__current_exception_context
_CxxThrowException __C_specific_handler memset memmove memchr memcmp __std_terminate __current_exception __std_exception_copy __std_exception_destroy memcpy _purecall |
| api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vsprintf
fgetpos setvbuf ungetc __stdio_common_vfprintf fgetc fsetpos fwrite _set_fmode fclose fflush fread _fseeki64 __acrt_iob_func _get_stream_buffer_pointers fputc __p__commode |
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
free _set_new_mode malloc calloc |
| api-ms-win-crt-math-l1-1-0.dll |
_ldsign
_dclass _fdclass _ldclass _fdsign _dsign __setusermatherr ceilf |
| api-ms-win-crt-runtime-l1-1-0.dll |
_cexit
_crt_atexit _register_onexit_function _initialize_onexit_table _initialize_narrow_environment _configure_narrow_argv _get_initial_narrow_environment _initterm abort _initterm_e exit _exit __p___argc __p___argv _c_exit _invoke_watson _register_thread_local_exe_atexit_callback system _set_app_type terminate _seh_filter_exe _errno |
| api-ms-win-crt-string-l1-1-0.dll |
wcscat_s
wcscpy_s |
| api-ms-win-crt-convert-l1-1-0.dll |
strtoul
|
| api-ms-win-crt-filesystem-l1-1-0.dll |
_unlock_file
_lock_file |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
___lc_codepage_func localeconv |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-19 00:08:57 |
| Version | 0.0 |
| SizeofData | 912 |
| AddressOfRawData | 0x1969e8 |
| PointerToRawData | 0x1953e8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-19 00:08:57 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x140196d98 |
|---|---|
| EndAddressOfRawData | 0x140196da0 |
| AddressOfIndex | 0x14019e360 |
| AddressOfCallbacks | 0x140171730 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14019d040 |
| XOR Key | 0x32ca6685 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 16 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 38 |
| Imports (35207) | 6 |
| Imports (33145) | 7 |
| Total imports | 254 |
| C++ objects (LTCG) (35223) | 8 |
| Resource objects (35223) | 1 |
| Linker (35223) | 1 |
No comments yet.