| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jul-18 20:32:54 |
| Detected languages |
English - United States
|
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Jul-18 20:32:54 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x91800 |
| SizeOfInitializedData | 0x3f400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000006B318 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xd6000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| d3d12.dll |
#101
|
| dxgi.dll |
CreateDXGIFactory1
|
| USER32.dll |
SendInput
RegisterClassExA GetAsyncKeyState SetCursorPos UnregisterClassA DefWindowProcW GetKeyState GetMessageExtraInfo LoadCursorA ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow SetCapture SetCursor IsWindowUnicode ReleaseCapture GetClientRect GetCursorPos OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData DestroyWindow CallWindowProcA DefWindowProcA CreateWindowExA SetWindowLongPtrA |
| KERNEL32.dll |
FreeEnvironmentStringsW
GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetCPInfo GetOEMCP GetACP IsValidCodePage FindNextFileW FindFirstFileExW FindClose GetFileSizeEx GetConsoleOutputCP WriteFile FlushFileBuffers LCMapStringW InitializeCriticalSectionEx FlsFree FlsSetValue FlsGetValue FlsAlloc ReadConsoleW GetProcessHeap GetStringTypeW Sleep DisableThreadLibraryCalls CreateThread GetModuleHandleW GetTickCount SetStdHandle GetModuleHandleA OutputDebugStringA MultiByteToWideChar GlobalAlloc GlobalFree GlobalLock WideCharToMultiByte GlobalUnlock GetLocaleInfoA LoadLibraryA QueryPerformanceFrequency IsDBCSLeadByte GetProcAddress FreeLibrary QueryPerformanceCounter CloseHandle VirtualFree VirtualAlloc GetSystemInfo VirtualQuery HeapCreate VirtualProtect HeapFree GetCurrentProcess Thread32Next Thread32First GetCurrentThreadId SuspendThread ResumeThread CreateToolhelp32Snapshot GetLastError HeapReAlloc HeapAlloc HeapDestroy GetThreadContext GetCurrentProcessId FlushInstructionCache SetThreadContext OpenThread GetModuleHandleExW ExitProcess GetConsoleMode CreateFileW HeapSize WriteConsoleW WaitForSingleObject SetEndOfFile SetFilePointerEx GetFileType GetStdHandle CreateEventA RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW RtlUnwindEx InterlockedFlushSList RtlPcToFileHeader RaiseException SetLastError EncodePointer EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree LoadLibraryExW ReadFile GetModuleFileNameW |
| SHELL32.dll |
ShellExecuteW
|
| IMM32.dll |
ImmGetContext
ImmSetCandidateWindow ImmSetCompositionWindow ImmReleaseContext |
| D3DCOMPILER_47.dll |
D3DCompile
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-18 20:32:54 |
| Version | 0.0 |
| SizeofData | 892 |
| AddressOfRawData | 0xadaa8 |
| PointerToRawData | 0xac6a8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-18 20:32:54 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1800ade70 |
|---|---|
| EndAddressOfRawData | 0x1800ade78 |
| AddressOfIndex | 0x1800ba464 |
| AddressOfCallbacks | 0x180093588 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1800b9040 |
| XOR Key | 0xd8b7e09c |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 160 |
| C objects (33145) | 28 |
| ASM objects (33145) | 28 |
| ASM objects (35207) | 10 |
| C objects (35207) | 15 |
| C++ objects (35207) | 39 |
| Imports (33145) | 21 |
| Total imports | 179 |
| C++ objects (LTCG) (35228) | 18 |
| Resource objects (35228) | 1 |
| Linker (35228) | 1 |
No comments yet.