| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-May-28 19:51:13 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): | Microsoft Visual C++ 8.0 |
| Malicious | VirusTotal score: 19/70 (Scanned on 2026-06-19 16:31:31) |
ALYac:
Gen:Variant.Yogi.6288
Antiy-AVL: RiskWare/Win64.Agent Arcabit: Trojan.Yogi.D1890 BitDefender: Gen:Variant.Yogi.6288 CTX: dll.trojan.ulise DeepInstinct: MALICIOUS Emsisoft: Gen:Variant.Yogi.6288 (B) GData: Gen:Variant.Yogi.6288 Google: Detected McAfeeD: ti!D667061E727F MicroWorld-eScan: Gen:Variant.Yogi.6288 Sophos: Mal/Generic-S Symantec: Trojan.Gen.MBT TrellixENS: Artemis!A96789121F3F TrendMicro: Trojan.Win64.ULISE.TL0101FA26ZU TrendMicro-HouseCall: Trojan.Win64.ULISE.TL0101FA26ZU VIPRE: Gen:Variant.Yogi.6288 Varist: W64/ABTrojan.NFCK-1270 alibabacloud: Trojan:Win/Ulise.Gen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-May-28 19:51:13 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x16000 |
| SizeOfInitializedData | 0x8c00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000016380 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x22000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| python314.dll |
PyTraceBack_Here
PyList_SetSlice PyExc_RuntimeError PyMethod_New PyObject_SetAttrString PyObject_GC_UnTrack PyObject_Hash PyUnicode_Concat PyExc_UnboundLocalError PyDict_GetItemWithError PyInterpreterState_GetID PyObject_GetAttr PyModule_GetName PyObject_HasAttr _Py_NoneStruct PyTuple_New PyObject_GenericSetDict PyObject_VisitManagedDict PyDict_SetItemString PyDict_Size PyDict_SetDefaultRef PyGC_Disable PyExc_AttributeError PyTuple_GetSlice PyUnicode_New PyErr_SetString PyIter_Next PyObject_GetIter PyErr_WarnFormat PyExc_ValueError PyUnicode_InternInPlace PyDict_Next PyErr_Format PyDict_Type PyThreadState_GetUnchecked PyObject_RichCompare PyTuple_Type _Py_FalseStruct PyImport_GetModule PyModule_NewObject PyMethod_Type PyType_IsSubtype PyExc_OverflowError _Py_Dealloc PyTuple_GetItem PyImport_GetModuleDict PyModule_GetDict PyObject_Format PyErr_ExceptionMatches PyObject_ClearManagedDict PyCapsule_GetPointer PyUnicode_FindChar PyObject_GC_Del PyObject_CallFunctionObjArgs PyObject_GenericGetDict PyObject_ClearWeakRefs PyObject_Vectorcall PyUnicode_FromFormat Py_Version PyExc_RuntimeWarning PyObject_GC_IsFinalized PyType_Ready PyObject_GetAttrString PyErr_Clear PyList_Append PyObject_RichCompareBool PyException_SetTraceback PyObject_GenericGetAttr PyObject_VectorcallDict PyDict_SetItem PyDict_New PyUnicode_Type PyObject_CallFinalizerFromDealloc _PyDict_GetItem_KnownHash PyObject_VectorcallMethod PyObject_IsInstance PyMem_Free PyExc_StopIteration PyObject_GetOptionalAttr PyFrozenSet_New PyUnstable_Object_IsUniquelyReferenced PyCMethod_New PyList_Type PyErr_NoMemory PyDict_GetItemString PyObject_GetItem PyModuleDef_Init PyObject_GC_Track PyBytes_FromStringAndSize _Py_NotImplementedStruct PyExc_NotImplementedError PyUnstable_Code_NewWithPosOnlyArgs PyDict_GetItemRef PyExc_TypeError PyMem_Realloc PyType_FromMetaclass PyObject_IsTrue PyObject_Str PyExc_NameError PyTuple_Pack PyMem_Malloc PyList_AsTuple Py_EnterRecursiveCall PyExc_ImportError PyObject_CallMethodObjArgs _Py_TrueStruct PyMemoryView_FromMemory PyExc_SystemError PyObject_SetItem _PyObject_GC_New PyType_Modified PyMethodDescr_Type PyUnicode_FromString _PyType_Lookup PyUnicode_Format PyObject_Call PyObject_Repr PyType_Type PyUnicode_Substring PyUnicode_FromStringAndSize PyErr_WarnEx PyErr_GivenExceptionMatches PyObject_HasAttrWithError PyCode_NewEmpty PyDict_SetDefault PyErr_SetObject PyException_GetTraceback PyThreadState_Get PyOS_snprintf PyCFunction_Type PyUnicode_InternFromString PyObject_SetAttr PyGC_Enable PyBaseObject_Type PySequence_List PyUnstable_Object_EnableDeferredRefcount PyUnicode_CopyCharacters PyNumber_Remainder PyUnicode_DecodeUTF8 PyLong_FromSsize_t PyArg_ValidateKeywordArguments PyErr_Occurred PyImport_ImportModuleLevelObject PyBytes_AsString PyImport_ImportModule PyImport_AddModuleRef Py_LeaveRecursiveCall PyCapsule_New PyFrame_New PyList_New PyFrozenSet_Type |
|---|---|
| KERNEL32.dll |
GetCurrentProcessId
GetCurrentThreadId GetSystemTimeAsFileTime DisableThreadLibraryCalls InitializeSListHead QueryPerformanceCounter |
| VCRUNTIME140.dll |
strrchr
__C_specific_handler __std_type_info_destroy_list memset strchr memcpy memcmp |
| api-ms-win-crt-runtime-l1-1-0.dll |
_cexit
_execute_onexit_table _initialize_onexit_table _initialize_narrow_environment _configure_narrow_argv _seh_filter_dll _initterm_e _initterm |
| Ordinal | 1 |
|---|---|
| Address | 0xd850 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-28 19:51:13 |
| Version | 0.0 |
| SizeofData | 600 |
| AddressOfRawData | 0x1a6d4 |
| PointerToRawData | 0x19ad4 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x18001d000 |
| XOR Key | 0x82d76f6 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 2 |
| Imports (35721) | 2 |
| Imports (33145) | 2 |
| ASM objects (35721) | 3 |
| C objects (35721) | 8 |
| C++ objects (35721) | 12 |
| Imports (35222) | 3 |
| Total imports | 192 |
| C objects (LTCG) (36244) | 1 |
| Exports (36244) | 1 |
| Resource objects (36244) | 1 |
| Linker (36244) | 1 |
No comments yet.