| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Apr-11 18:33:37 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
Madium.pdb
|
| CompanyName | madium |
| FileDescription | Madium |
| FileVersion | 0.1.0 |
| ProductName | Madium |
| ProductVersion | 0.1.0 |
| Suspicious | PEiD Signature: | UPolyX V0.1 -> Delikon |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA1
Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to RC5 or RC6 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .taubndl |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/65 (Scanned on 2026-05-24 01:37:23) |
ESET-NOD32:
Win64/GameHack.UO potentially unsafe application
Trapmine: malicious.high.ml.score |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Apr-11 18:33:37 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x977e00 |
| SizeOfInitializedData | 0x58fc00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000094C66C (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xf0c000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetCurrentProcess
GetModuleHandleW GetUserDefaultUILanguage LCIDToLocaleName CreateJobObjectW AssignProcessToJobObject GetLastError SetInformationJobObject QueryFullProcessImageNameW CreateToolhelp32Snapshot Process32FirstW Process32NextW GetCurrentThreadId InitializeCriticalSectionEx EncodePointer OpenProcess FlsSetValue FlsGetValue FlsAlloc RaiseException RtlPcToFileHeader RtlUnwindEx SetUnhandledExceptionFilter InitializeSListHead GetSystemTimeAsFileTime SleepConditionVariableSRW WakeAllConditionVariable AcquireSRWLockExclusive ReleaseSRWLockExclusive DeleteCriticalSection TerminateProcess FlsFree CloseHandle |
|---|---|
| VERSION.dll |
VerQueryValueW
GetFileVersionInfoSizeW GetFileVersionInfoW |
| USER32.dll |
DispatchMessageW
SendMessageW LoadCursorW SetWindowPos EnumWindows AdjustWindowRectEx CreateWindowExW IsWindow RegisterTouchWindow RegisterClassExW GetMessageA DispatchMessageA EnumChildWindows IsIconic InvalidateRgn SetCursorPos InvalidateRect TranslateMessage GetActiveWindow GetForegroundWindow AdjustWindowRect GetWindowThreadProcessId IsWindowVisible MapVirtualKeyW GetMessageW DefWindowProcW FlashWindowEx ChangeDisplaySettingsExW SetWindowPlacement GetWindowPlacement TranslateAcceleratorW GetCursorPos PostThreadMessageW ValidateRect SetCursor GetUpdateRect UpdateWindow ClientToScreen GetClientRect GetWindowLongW MonitorFromWindow ScreenToClient PostMessageW MonitorFromRect GetMonitorInfoW GetSystemMetrics FillRect SystemParametersInfoW TrackMouseEvent DestroyWindow PeekMessageW RedrawWindow GetTouchInputInfo CloseTouchInputHandle |
| ADVAPI32.dll |
OpenProcessToken
GetTokenInformation |
| SHELL32.dll |
ShellExecuteW
|
| bcryptprimitives.dll |
ProcessPrng
|
| advapi32.dll |
RegQueryValueExW
RegCloseKey EventUnregister RegGetValueW RegOpenKeyExW EventRegister SystemFunction036 EventWriteTransfer EventSetInformation |
| ntdll.dll |
RtlGetVersion
RtlNtStatusToDosError NtReadFile NtCreateFile NtCancelIoFileEx NtDeviceIoControlFile NtOpenFile NtCreateNamedPipeFile NtWriteFile |
| kernel32.dll |
DuplicateHandle
SetHandleInformation FreeLibrary LoadLibraryExW HeapFree GetProcessHeap SetFileTime GetModuleFileNameW FindNextFileW RtlLookupFunctionEntry RtlCaptureContext GetProcessId GetExitCodeProcess GetSystemInfo QueryPerformanceCounter GetSystemTimePreciseAsFileTime WriteFileEx CreateProcessW GetWindowsDirectoryW GetSystemDirectoryW CompareStringOrdinal FreeEnvironmentStringsW SleepEx ReadFileEx WaitForMultipleObjects CreateThread WaitForSingleObject SetWaitableTimer CreateWaitableTimerExW SetFileInformationByHandle LoadLibraryExA OutputDebugStringW HeapAlloc OutputDebugStringA GetStdHandle WriteConsoleW MultiByteToWideChar ReleaseMutex FormatMessageW CancelIo CreateMutexA QueryPerformanceFrequency ExitProcess GetTempPathW GetFullPathNameW SetThreadStackGuarantee GetCurrentProcessId FindClose FindFirstFileExW DeleteFileW CreateEventW SwitchToThread WaitForSingleObjectEx GetFileInformationByHandleEx GetFinalPathNameByHandleW CreateDirectoryW MoveFileExW CreatePipe CreateIoCompletionPort PostQueuedCompletionStatus GetQueuedCompletionStatusEx GetOverlappedResult ReadFile WideCharToMultiByte HeapReAlloc GetEnvironmentVariableW SetFileCompletionNotificationModes GetFileAttributesW CreateFileW GetFileInformationByHandle GetConsoleMode GetCommandLineW AddVectoredExceptionHandler lstrlenW LoadLibraryA LoadLibraryW GetConsoleOutputCP GetModuleHandleA RtlVirtualUnwind SetEnvironmentVariableW Sleep GetEnvironmentStringsW GetCurrentDirectoryW SetLastError GetCurrentThread GetProcAddress |
| api-ms-win-core-synch-l1-2-0.dll |
WaitOnAddress
WakeByAddressSingle WakeByAddressAll |
| ole32.dll |
OleInitialize
CoCreateFreeThreadedMarshaler CoInitializeEx CoCreateInstance CoInitialize RevokeDragDrop CoTaskMemAlloc RegisterDragDrop CoTaskMemFree CoUninitialize |
| comctl32.dll |
DefSubclassProc
TaskDialogIndirect RemoveWindowSubclass SetWindowSubclass |
| gdi32.dll |
CreateDIBSection
SelectObject CreateSolidBrush BitBlt SetBkMode SetTextColor DeleteDC CreateRectRgn CombineRgn GetDeviceCaps DeleteObject CreateCompatibleDC |
| dwmapi.dll |
DwmGetWindowAttribute
DwmEnableBlurBehindWindow DwmSetWindowAttribute |
| shlwapi.dll |
SHCreateMemStream
|
| shell32.dll |
DragFinish
SHAppBarMessage SHGetKnownFolderPath ShellExecuteExW ILCreateFromPathW ILFree SHOpenFolderAndSelectItems DragQueryFileW |
| user32.dll |
GetSystemMenu
ShowCursor GetMenu EnableMenuItem GetClipCursor ClipCursor RegisterRawInputDevices ReleaseCapture SetCapture MsgWaitForMultipleObjectsEx RegisterWindowMessageA SetParent MapWindowPoints GetWindow SetFocus ShowWindow ReleaseDC EnableWindow IsWindowEnabled GetWindowRect SetWindowLongPtrW GetParent GetWindowLongPtrW SetPropW FindWindowExW SetWindowRgn IsProcessDPIAware GetDC SetWindowDisplayAffinity SetWindowLongW DrawTextW GetWindowDC OffsetRect GetMenuBarInfo DestroyMenu CheckMenuItem RemoveMenu CreatePopupMenu CreateMenu SetMenuItemInfoW AppendMenuW InsertMenuW TrackPopupMenu PostQuitMessage CreateAcceleratorTableW DestroyAcceleratorTable DrawMenuBar SetMenu DrawIconEx GetMenuItemInfoW CreateIcon GetKeyboardLayout ToUnicodeEx GetKeyState GetAsyncKeyState GetKeyboardState MapVirtualKeyExW GetRawInputData SetWindowTextW GetWindowTextW GetWindowTextLengthW SendInput SetForegroundWindow DestroyIcon EnumDisplayMonitors MonitorFromPoint SystemParametersInfoA |
| oleaut32.dll |
SysFreeString
GetErrorInfo SysStringLen SetErrorInfo |
| ws2_32.dll |
WSAStartup
closesocket recv WSASend send getsockname getpeername getsockopt accept setsockopt ioctlsocket connect WSACleanup WSAIoctl WSASocketW bind listen shutdown WSAGetLastError socket freeaddrinfo getaddrinfo |
| bcrypt.dll |
BCryptGenRandom
|
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
pow roundf trunc floor round |
| api-ms-win-crt-string-l1-1-0.dll |
wcslen
_wcsicmp strcpy_s wcscmp wcsncat |
| api-ms-win-crt-convert-l1-1-0.dll |
_ultow_s
_wtoi wcstol |
| api-ms-win-crt-runtime-l1-1-0.dll |
__p___argv
_initialize_narrow_environment __p___argc _cexit _c_exit _register_thread_local_exe_atexit_callback _seh_filter_exe _set_app_type exit abort _configure_narrow_argv _initialize_onexit_table terminate _crt_atexit _exit _get_initial_narrow_environment _initterm _initterm_e _register_onexit_function |
| api-ms-win-crt-stdio-l1-1-0.dll |
_set_fmode
__p__commode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-heap-l1-1-0.dll |
free
_set_new_mode malloc _callnewh calloc |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.1.0.0 |
| ProductVersion | 0.1.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | madium |
| FileDescription | Madium |
| FileVersion (#2) | 0.1.0 |
| ProductName | Madium |
| ProductVersion (#2) | 0.1.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-11 18:33:37 |
| Version | 0.0 |
| SizeofData | 35 |
| AddressOfRawData | 0xc526cc |
| PointerToRawData | 0xc518cc |
| Referenced File | Madium.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-11 18:33:37 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xc526f0 |
| PointerToRawData | 0xc518f0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-11 18:33:37 |
| Version | 0.0 |
| SizeofData | 1068 |
| AddressOfRawData | 0xc52704 |
| PointerToRawData | 0xc51904 |
| StartAddressOfRawData | 0x140c52b78 |
|---|---|
| EndAddressOfRawData | 0x140c52d74 |
| AddressOfIndex | 0x140e66d90 |
| AddressOfCallbacks | 0x140979d10 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x0000000140908540
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140e647c0 |
| XOR Key | 0x4a227d70 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 14 |
| ASM objects (35403) | 9 |
| C objects (35403) | 13 |
| C++ objects (35403) | 46 |
| Imports (30151) | 4 |
| C objects (35728) | 12 |
| Imports (33145) | 11 |
| Total imports | 463 |
| Unmarked objects (#2) | 674 |
| Resource objects (35728) | 1 |
| Linker (35728) | 1 |
No comments yet.