| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2025-Apr-05 18:57:07 |
| Detected languages |
English - United States
|
| CompanyName | Microsoft Corporation |
| FileDescription | Windows NT BASE API Client DLL |
| FileVersion | 10.0.26100.3323 (WinBuild.160101.0800) |
| InternalName | kernel32 |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | kernel32 |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 10.0.26100.3323 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: 04f5be18-91cc-40c4-9002-4eb30ffa9fc7
Issuer: 04f5be18-91cc-40c4-9002-4eb30ffa9fc7 |
| Malicious | VirusTotal score: 34/72 (Scanned on 2025-04-07 15:41:14) |
ALYac:
Gen:Variant.Jaik.76520
AVG: Win32:SpywareX-gen [Trj] Antiy-AVL: GrayWare/Win32.Wacapew Arcabit: Trojan.Jaik.D12AE8 Avast: Win32:SpywareX-gen [Trj] BitDefender: Gen:Variant.Jaik.76520 CTX: exe.trojan.jaik CrowdStrike: win/malicious_confidence_90% (W) Cylance: Unsafe DeepInstinct: MALICIOUS Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Jaik.76520 (B) FireEye: Gen:Variant.Jaik.76520 Fortinet: W32/PossibleThreat GData: Gen:Variant.Jaik.76520 Google: Detected K7AntiVirus: Spyware ( 0052ae1c1 ) K7GW: Spyware ( 0052ae1c1 ) Kaspersky: UDS:Trojan-Spy.Win32.Xegumumune.gen Kingsoft: malware.kb.a.913 Lionic: Trojan.Win32.Xegumumune.l!c Malwarebytes: Generic.Malware/Suspicious McAfee: Artemis!E89DBBA95890 McAfeeD: ti!7D056B282B13 MicroWorld-eScan: Gen:Variant.Jaik.76520 Microsoft: Program:Win32/Wacapew.C!ml Panda: Trj/Chgt.AD Rising: Spyware.Xegumumune!8.10962 (CLOUD) Sangfor: Trojan.Win32.Save.a Sophos: Generic Reputation PUA (PUA) Symantec: ML.Attribute.HighConfidence TrendMicro-HouseCall: TROJ_GEN.R002H09D525 VIPRE: Gen:Variant.Jaik.76520 Varist: W32/ABTrojan.UXKZ-0902 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2025-Apr-05 18:57:07 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x23800 |
| SizeOfInitializedData | 0xe000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00007597 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x25000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x35000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x31d87 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| USER32.dll |
OpenClipboard
GetWindowTextW GetForegroundWindow MapVirtualKeyA GetAsyncKeyState GetKeyState GetClipboardData CloseClipboard ShowWindow |
|---|---|
| KERNEL32.dll |
TlsSetValue
WriteConsoleW HeapSize CreateFileW GetProcessHeap SetStdHandle SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetOEMCP Sleep GlobalUnlock GlobalLock GetConsoleWindow WideCharToMultiByte EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection EncodePointer DecodePointer MultiByteToWideChar LCMapStringEx GetStringTypeW GetCPInfo IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW GetModuleHandleW GetCurrentProcess TerminateProcess GetACP RaiseException RtlUnwind GetLastError SetLastError InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue SetEndOfFile TlsFree FreeLibrary GetProcAddress LoadLibraryExW GetStdHandle WriteFile GetModuleFileNameW ExitProcess GetModuleHandleExW GetCommandLineA GetCommandLineW HeapAlloc HeapFree CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetFileType CloseHandle FlushFileBuffers GetConsoleOutputCP GetConsoleMode ReadFile GetFileSizeEx SetFilePointerEx ReadConsoleW HeapReAlloc FindClose FindFirstFileExW FindNextFileW IsValidCodePage |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 10.0.26100.3323 |
| ProductVersion | 10.0.26100.3323 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Windows NT BASE API Client DLL |
| FileVersion (#2) | 10.0.26100.3323 (WinBuild.160101.0800) |
| InternalName | kernel32 |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | kernel32 |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion (#2) | 10.0.26100.3323 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Apr-05 18:57:07 |
| Version | 0.0 |
| SizeofData | 792 |
| AddressOfRawData | 0x2d910 |
| PointerToRawData | 0x2c510 |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x430080 |
| SEHandlerTable | 0x42d7f8 |
| SEHandlerCount | 18 |
| XOR Key | 0xc3bc5006 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 11 |
| C++ objects (30795) | 173 |
| C objects (30795) | 21 |
| ASM objects (33808) | 21 |
| C objects (33808) | 18 |
| Imports (30795) | 5 |
| Total imports | 102 |
| C++ objects (33808) | 77 |
| C++ objects (34123) | 1 |
| Linker (34123) | 1 |