ea8e190a048aecacda6c206e8b0b001514eac6790af57c658ded364dfebfa4f3

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2063-Apr-30 23:25:13
Comments
CompanyName Atlas Playbook v0.5.0
FileDescription celerity
FileVersion 1.0.0.0
InternalName celerity.exe
LegalCopyright Copyright © Atlas Playbook v0.5.0 2026
LegalTrademarks
OriginalFilename celerity.exe
ProductName celerity
ProductVersion 1.0.0.0
Assembly Version 1.0.0.0

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • virus
Contains domain names:
  • High-Logic.com
  • Logic.com
  • Z-google.golang.org
  • acutedotcomb.cn
  • apple.com
  • breveacutecomb.cn
  • brevegravecomb.cn
  • brevetildecomb.cn
  • circumflexacutecomb.cn
  • circumflexgravecomb.cn
  • circumflexhookcomb.cn
  • circumflextildecomb.cn
  • commaaccentright.cn
  • commaaccentrotate.cn
  • fontawesome.com
  • github.com
  • golang.org
  • google.com
  • google.golang.org
  • googleapis.com
  • googleprod.com
  • http://schemas.microsoft.com
  • http://schemas.microsoft.com/expression/blend/2008
  • http://schemas.microsoft.com/winfx/2006/xaml
  • http://schemas.microsoft.com/winfx/2006/xaml/presentation
  • http://schemas.openxmlformats.org
  • http://schemas.openxmlformats.org/markup-compatibility/2006
  • http://www.apple.com
  • http://www.apple.com/
  • http://www.apple.com/Copyright
  • http://www.apple.com/http
  • http://www.google.com
  • http://www.google.com/get/noto/Monotype
  • http://www.monotype.com
  • http://www.monotype.com/studiohttp
  • http://www.styleseven.comFreeware
  • http://www.styleseven.comSmallest
  • http://www.w3.org
  • http://www.w3.org/2000/svg
  • https://fontawesome.com
  • https://fontawesome.comVersion
  • https://github.com
  • https://openfontlicense.orgThis
  • https://openfontlicense.orghttp
  • https://openfontlicense.orghttps
  • https://rsms.me
  • https://t.me
  • macrondieresiscomb.cn
  • microsoft.com
  • monotype.com
  • openxmlformats.org
  • schemas.microsoft.com
  • schemas.openxmlformats.org
  • tildecross.cn
  • tonos.top
  • type.googleapis.com
  • type.googleprod.com
  • uni02E5.cn
  • uni02E6.cn
  • uni02E7.cn
  • uni02E8.cn
  • uni02E9.cn
  • www.apple.com
  • www.google.com
  • www.monotype.com
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to RC5 or RC6
Uses known Mersenne Twister constants
Suspicious The PE is possibly packed. The PE only has 0 import(s).
Malicious VirusTotal score: 23/54 (Scanned on 2026-08-22 11:01:16) ALYac: Generic.Dacic.18276.E3C5F2A7
Antiy-AVL: RiskWare/Win64.Gamehack
Bkav: W32.Malware.551915A6
CTX: exe.trojan.dacic
CrowdStrike: win/malicious_confidence_70% (W)
Cylance: Unsafe
Elastic: malicious (high confidence)
Fortinet: Adware/GameHack
Gridinsoft: Trojan.Win64.Wacatac.cl
K7AntiVirus: Unwanted-Program ( 005ceb201 )
Kingsoft: Win32.Troj.kepavll.v
Lionic: Trojan.Win32.Dacic.4!c
Malwarebytes: Malware.AI.3786873401
McAfeeD: ti!EA8E190A048A
Microsoft: Trojan:Win32/Kepavll!rfn
Paloalto: generic.ml
Sangfor: Trojan.Win32.Agent.Vdo4
Sophos: Generic Reputation PUA (PUA)
Symantec: ML.Attribute.HighConfidence
TrendMicro: Trojan.Win64.KEPAVLL.USBLHD26
TrendMicro-HouseCall: Trojan.Win64.KEPAVLL.USBLHD26
VIPRE: Generic.Dacic.18276.E3C5F2A7
Webroot: W32.Trojan.Gen

Hashes

MD5 35b1310ad58633c188177d59425497e9 🔍
SHA1 c2e30925970f8fa27ab2a9c0caf51c7e2e00b8da 🔍
SHA256 ea8e190a048aecacda6c206e8b0b001514eac6790af57c658ded364dfebfa4f3 🔍
SHA3 33ac069bc8629a207ac4191bc2aba9f13c2961718faf838942b3362f25f632d0 🔍
SSDeep 196608:JfOSQ/v5n8v8YfTbF0iaokPBOHEwnFvMYH87rYGScjh3WrXCbPaZ16v8324YEBa:Jmh/v58v8YfTbF0iaokPBOHEwnFvMYH 🔍
Imports Hash d41d8cd98f00b204e9800998ecf8427e 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 2
TimeDateStamp 2063-Apr-30 23:25:13
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 48.0
SizeOfCode 0x8f9e00
SizeOfInitializedData 0x9c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000000000 (Section: ?)
BaseOfCode 0x2000
ImageBase 0x140000000
SectionAlignment 0x2000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x906000
SizeOfHeaders 0x200
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x400000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x2000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 036aa05b67bd30b92d71e22cf84ee5d9 🔍
SHA1 0fd586dac863a3409e5bea7e745ebb60bd4a6bec 🔍
SHA256 1a9135788402bf25f34d7159097fe0acb50e8367f3868a29c3842bed4d4d6c94 🔍
SHA3 7ba40e7be9f2d7004f9201bbf051fa9ceda4ff8e3f48d9ba84eb7c2ca6269b7c 🔍
VirtualSize 0x8f9c0c
VirtualAddress 0x2000
SizeOfRawData 0x8f9e00
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.66537

.rsrc

MD5 9b42fcdbbc2783d89a2b77056b2a07cb 🔍
SHA1 69308ebbbb8cb26231f32ae25581fa7138e7eb31 🔍
SHA256 2c2a121bf947b497102a89ea35ca1be4507736b14be855799ba354cc2183ac15 🔍
SHA3 0e098b488a1af2918754dc4ab1bf1f71dcae70c55fad5f5c01e1fc91bafccb2b 🔍
VirtualSize 0x9b4c
VirtualAddress 0x8fc000
SizeOfRawData 0x9c00
PointerToRawData 0x8fa000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.29184

Imports

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.17341
MD5 12cca7c1bf287f53b9b344a28fa6f69e 🔍
SHA1 bb4e20fbfb5a385c03131d65af705e8cc392353f 🔍
SHA256 d9c7b6455db616ded87b2ee62032b11cd4865cc2127085cbd9daf5b6cd2c77a4 🔍
SHA3 ec1efa88f6dbe68e7f891dfaef70e34a909e08d37a865cf9cdba2eaedde01771 🔍

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Icon file
MD5 fcf5da4bc7867f13b4025ad65c455f48 🔍
SHA1 b2d8d91f2a4a2c3c504f8b87d417c382838e0f2f 🔍
SHA256 8b10bf294e8d3fe252a5488ea8ae69fe8f06837079a5c6a4e84312a5ec334dee 🔍
SHA3 6f3bc5d6f0ea376c2c039a4e19233fe2a6f6731b870dac96b33a0768bc563742 🔍

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x370
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28198
MD5 d826636c6bf2ce7cf20f4913ad79f6a6 🔍
SHA1 c51f8f65a553bf8dc03cfc2d8d458279c75e28b7 🔍
SHA256 ad13c5fd427a0c5e30e9ef52d6c84c553d67cf76075b76ae8b347321cfaece07 🔍
SHA3 32b241bd1ede0891608b5d598130f4b05c52e7a1a3d78172bb02bd450e7d2be7 🔍

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x1ea
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.00112
MD5 b7db84991f23a680df8e95af8946f9c9 🔍
SHA1 cac699787884fb993ced8d7dc47b7c522c7bc734 🔍
SHA256 539dc26a14b6277e87348594ab7d6e932d16aabb18612d77f29fe421a9f1d46a 🔍
SHA3 4f72877413d13a67b52b292a8524e2c43a15253c26aaf6b5d0166a65bc615cff 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments
CompanyName Atlas Playbook v0.5.0
FileDescription celerity
FileVersion (#2) 1.0.0.0
InternalName celerity.exe
LegalCopyright Copyright © Atlas Playbook v0.5.0 2026
LegalTrademarks
OriginalFilename celerity.exe
ProductName celerity
ProductVersion (#2) 1.0.0.0
Assembly Version 1.0.0.0
Resource LangID UNKNOWN

UNKNOWN

Characteristics 0
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

Load Configuration

RICH Header

Errors

Leave a comment

No comments yet.