| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jul-28 18:38:47 |
| Detected languages |
English - United States
Korean - Korea |
| Suspicious | The PE is possibly packed. |
Unusual section name found: \x00
Section \x00 is both writable and executable. Unusual section name found: .idata Unusual section name found: wnkyludi Section wnkyludi is both writable and executable. Unusual section name found: jdlovuen Section jdlovuen is both writable and executable. The PE only has 2 import(s). |
| Info | The PE's resources present abnormal characteristics. |
Resource 161 is possibly compressed or encrypted.
Resource 171 is possibly compressed or encrypted. Resource 180 is possibly compressed or encrypted. Resource 182 is possibly compressed or encrypted. Resource 188 is possibly compressed or encrypted. Resource 190 is possibly compressed or encrypted. Resource 192 is possibly compressed or encrypted. Resource 196 is possibly compressed or encrypted. Resource 197 is possibly compressed or encrypted. Resource 198 is possibly compressed or encrypted. Resource 209 is possibly compressed or encrypted. Resource 210 is possibly compressed or encrypted. |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x148 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2026-Jul-28 18:38:47 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x34ee00 |
| SizeOfInitializedData | 0x2b9a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x009C0000 (Section: jdlovuen) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x350000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x9c1000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x5a383f |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
lstrcpy
|
|---|---|
| comctl32.dll |
InitCommonControls
|