eeba994e3fdb23186fc21a12b1d6b88bbb714edb9dabcd7ba18a97d0a31da451

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Sep-23 12:12:32
Detected languages English - United States
CompanyName madcow team
FileDescription TrackDayR Mod Manager
FileVersion 1.6.0.0
InternalName TrackDayR Mod Manager
LegalCopyright Created with love by the madcow team - for the TrackDayR community
OriginalFilename TrackDayR Mod Manager.exe
ProductName TrackDayR Mod Manager
ProductVersion 1.6.0.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • android.jclass.net
  • jclass.net
  • platforms.android.jclass.net
  • webview.platforms.android.jclass.net
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Functions related to the privilege level:
  • OpenProcessToken
Enumerates local disk drives:
  • GetDriveTypeW
Suspicious The file contains overlay data. 22963900 bytes of data starting at offset 0x4da00.
The overlay data has an entropy of 7.99814 and is possibly compressed or encrypted.
Overlay data amounts for 98.6343% of the executable.
Malicious VirusTotal score: 4/70 (Scanned on 2026-09-23 14:47:42) APEX: Malicious
Bkav: W32.Malware.4F643DD1
Microsoft: Trojan:Win32/Wacatac.C!ml
Zillya: Trojan.Blank.Script.2113

Hashes

MD5 a7a755de3422ae47b8714bae553503c8 🔍
SHA1 95a373f4f5b40eabb67780a389df3705c1486e4c 🔍
SHA256 eeba994e3fdb23186fc21a12b1d6b88bbb714edb9dabcd7ba18a97d0a31da451 🔍
SHA3 38cfd163d7dc6890f975bcc3014c08d8b4838d3e247cadb96e16dfd0c15890f5 🔍
SSDeep 393216:eWb5j2+mIHjnO58GJ1SfKTZy5XMCHWUjSzOrPwm7Yx4rqmMGIwq8ABvmRWU+y/1:l5CZIHLOSg1R45XMb8Szkm49MpN5mRW 🔍
Imports Hash cf72283be50852e418ce6bbb6b645835 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Sep-23 12:12:32
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x2ca00
SizeOfInitializedData 0x20c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000000E350 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x55000
SizeOfHeaders 0x400
Checksum 0x1643044
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x1e8480
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 067ceb5950b03e18720d53a9c58d6ba0 🔍
SHA1 75309e0b3e3c095eb6c7fa96a58f32e0bd4191ad 🔍
SHA256 0ebb4a3c899d306107653c38e4ddce3e5c7a6ff58e09d456070786eea947eb70 🔍
SHA3 2fedfbb0e502ef5af40a41f5851f026551b7d03275b553e7496a32315612eeaa 🔍
VirtualSize 0x2c870
VirtualAddress 0x1000
SizeOfRawData 0x2ca00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.46815

.rdata

MD5 f9f459ee45ba46937a927e511358d6f1 🔍
SHA1 d184bb5b408ea7a36d7ed4ada755546d192df267 🔍
SHA256 a0603b5fc2e6ddebd338463d46e254827aee19d8c011b7792bb613cc5d0e128f 🔍
SHA3 2969c9ead808cf41d0f1afcae37ac95fbb6deeaa947954c23a760fe0728a76d0 🔍
VirtualSize 0x13dd0
VirtualAddress 0x2e000
SizeOfRawData 0x13e00
PointerToRawData 0x2ce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.75641

.data

MD5 fc7a7dfe669c46191736d63a76b81159 🔍
SHA1 be996d0265d3c0019fef7637f52463fbfa193973 🔍
SHA256 277e128b6c64c65117eb7da75d8ae771e332f7827e8d981243d0acf0a2786011 🔍
SHA3 17425e165a6aa9d753008db396ac5a9579d7723c3385291954ef028949224ae7 🔍
VirtualSize 0x4af0
VirtualAddress 0x42000
SizeOfRawData 0xe00
PointerToRawData 0x40c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.80995

.pdata

MD5 c42900aa9718da5e1b289126ac00aca5 🔍
SHA1 e8a7daeafd74df3b8a8fe07cfda1c5fbe53aa82c 🔍
SHA256 c853c0d60d45400916820a5c65ce12e48dab8c7ea4ac5e7a6eee26dd997723eb 🔍
SHA3 fcf33491627999108822a1154ca592ddc596eb1ffb9112f624b905e9ae2c6881 🔍
VirtualSize 0x2598
VirtualAddress 0x47000
SizeOfRawData 0x2600
PointerToRawData 0x41a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.47162

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x4a000
SizeOfRawData 0x200
PointerToRawData 0x44000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 e5f870a96699091b0fe9c7bd37016fb2 🔍
SHA1 8874098bf3d40ed3f0ee46a30e4f13f13051a5e2 🔍
SHA256 7775c71d4dec06938b9baab982348b77f2001199a9246c8fa7dc4942ad67b626 🔍
SHA3 f0c855539344e64ca6101286da9e06c66034f95b883d25b94a06dd53c5948354 🔍
VirtualSize 0x8e64
VirtualAddress 0x4b000
SizeOfRawData 0x9000
PointerToRawData 0x44200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.87024

.reloc

MD5 39668fd101775493909e3ca249db5592 🔍
SHA1 32b99e8ed662456b7d3f9918adcdfba2eb0860f7 🔍
SHA256 a2fb9b93a2d558c5640b2738af0d6a671cda8db6155be5005e37f3e3099582e8 🔍
SHA3 f78cf1178671ee2bffa6ff6a7ba299471e1baa8506f6d81f04fe60b2023751a4 🔍
VirtualSize 0x768
VirtualAddress 0x54000
SizeOfRawData 0x800
PointerToRawData 0x4d200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.25258

Imports

USER32.dll CreateWindowExW
ShutdownBlockReasonCreate
MsgWaitForMultipleObjects
ShowWindow
DestroyWindow
RegisterClassW
DefWindowProcW
PeekMessageW
DispatchMessageW
TranslateMessage
GetMonitorInfoW
MonitorFromPoint
GetCursorPos
GetSystemMetrics
PostMessageW
GetMessageW
MessageBoxW
MessageBoxA
SystemParametersInfoW
DestroyIcon
SetWindowLongPtrW
GetWindowLongPtrW
GetClientRect
InvalidateRect
ReleaseDC
GetDC
DrawTextW
GetDialogBaseUnits
EndDialog
DialogBoxIndirectParamW
MoveWindow
SendMessageW
COMCTL32.dll #380
KERNEL32.dll GetACP
IsValidCodePage
GetStringTypeW
GetFileAttributesExW
SetEnvironmentVariableW
FlushFileBuffers
LCMapStringW
CompareStringW
VirtualProtect
GetCurrentDirectoryW
HeapAlloc
GetFileSizeEx
GetConsoleOutputCP
GetOEMCP
GetCPInfo
GetLastError
FreeLibrary
GetProcAddress
LoadLibraryExW
GetModuleHandleW
MulDiv
FormatMessageW
GetModuleFileNameW
GetEnvironmentStringsW
CreateSymbolicLinkW
SetErrorMode
CreateDirectoryW
GetCommandLineW
GetEnvironmentVariableW
ExpandEnvironmentStringsW
DeleteFileW
FindClose
FindFirstFileW
FindNextFileW
GetDriveTypeW
RemoveDirectoryW
GetTempPathW
CloseHandle
QueryPerformanceCounter
QueryPerformanceFrequency
WaitForSingleObject
Sleep
GetCurrentProcess
TerminateProcess
GetExitCodeProcess
CreateProcessW
GetStartupInfoW
LocalFree
SetConsoleCtrlHandler
K32EnumProcessModules
K32GetModuleFileNameExW
CreateFileW
FindFirstFileExW
GetFinalPathNameByHandleW
MultiByteToWideChar
WideCharToMultiByte
SetFilePointerEx
FreeEnvironmentStringsW
GetProcessHeap
GetTimeZoneInformation
HeapSize
HeapReAlloc
WriteConsoleW
SetEndOfFile
SetDllDirectoryW
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
SetUnhandledExceptionFilter
RtlUnwindEx
SetLastError
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
RtlLookupFunctionEntry
EncodePointer
RaiseException
RtlPcToFileHeader
GetCommandLineA
GetFileInformationByHandle
GetFileType
PeekNamedPipe
SystemTimeToTzSpecificLocalTime
FileTimeToSystemTime
ReadFile
GetFullPathNameW
SetStdHandle
GetStdHandle
WriteFile
ExitProcess
GetModuleHandleExW
IsProcessorFeaturePresent
RtlCaptureContext
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
HeapFree
GetConsoleMode
ReadConsoleW
ADVAPI32.dll OpenProcessToken
GetTokenInformation
ConvertStringSecurityDescriptorToSecurityDescriptorW
ConvertSidToStringSidW
GDI32.dll SelectObject
DeleteObject
CreateFontIndirectW

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x25d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.5818
Detected Filetype PNG graphic file
MD5 32c3a6a9de3889760234bf319ea8656d 🔍
SHA1 2145904c27d5d6aeda2bab3ee3cc9e1ee18376a7 🔍
SHA256 10d99426ad487fab19582d10ee9d7b1e8e1768139a11541b884ab09e043f2a3b 🔍
SHA3 f7722f88d986cb631f800968684c58b81a8b8cfd50bee66e25558ab9268f1ba3 🔍

2

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3fc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.76148
Detected Filetype PNG graphic file
MD5 89db8ec4431d8e33a8edd26168fa95ac 🔍
SHA1 52fe61c868d22d1e0b0a1cb7f171d32faf77cbb0 🔍
SHA256 8203cad0d639a7b02ad260572217bd9564b35dff52dcd8269caf1d0f7b5125ab 🔍
SHA3 9be2455e1bfcb79116f49dc9b1b619410c10658187a48ca59fcd44c54e65e139 🔍

3

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x5cb
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.81162
Detected Filetype PNG graphic file
MD5 c45f3bd4c0ca723f5bfd9756069c3568 🔍
SHA1 dfd9000ad763b4ed2cae85cc75af543da535b28f 🔍
SHA256 f2e42c108016afea937656c18d906c701965c0b2e14b64b8a2e3739721337014 🔍
SHA3 5f2346804a67ed135e7dd6defae2bccdbebed466f39ad42c73f93fbc878e7df3 🔍

4

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x918
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.85955
Detected Filetype PNG graphic file
MD5 d229db8bd3a46f3ea3f58ec2ef6b3219 🔍
SHA1 c1f25f9da20e87efadaf66ca2b7739e16a925b94 🔍
SHA256 9b10ba4b2c7a4d6fbe434e4977412212825bba8f4873cb83fe965e31f5ab7b3e 🔍
SHA3 a39230740f4102ca243f98567a8388df518abc2ce68cba6b5f3786d6acc0cce6 🔍

5

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xceb
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92826
Detected Filetype PNG graphic file
MD5 12bd6c6ebd61fd08daf3d0cd19752fda 🔍
SHA1 43798983902c19a70c6f701d6b41a406c9da420f 🔍
SHA256 aaf5e18dd4c251417cef8d07391a41b33abbce2ee13f407798c75c29d0b06d59 🔍
SHA3 3cc5898a87254ae43ec62b817da0f16c2a3c13d15c46dd0e8d39ade2e15d5070 🔍

6

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1cd1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.95391
Detected Filetype PNG graphic file
MD5 216be6bc28a9ad5ee5d6bd43d4164da4 🔍
SHA1 a739440910990c537eaa5cb3b638311613bcb31d 🔍
SHA256 522caf168112c99fb53fe476dc372229b2453803752adc88f87e50248b591f71 🔍
SHA3 c1fc3a0f6cef21b59402c308b41774ba1788198a99ae435dd44918ba173936b5 🔍

7

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x442d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9091
Detected Filetype PNG graphic file
MD5 27c80103a8da2f06e7b8693ee0636df2 🔍
SHA1 23d09f188fb16fd534f25196c2a8b7364f46170a 🔍
SHA256 06b83e27dbdbbbe876ce49f3e082851455cdbcc907c25ec64d69c4ef99897a33 🔍
SHA3 9d9cac872d819381b24971c3e3b42b90387df3f3ce09782b23d5cbeba968a021 🔍

1 (#2)

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.65771
Detected Filetype Icon file
MD5 567c70b879a344b67f8f5e88e86b4483 🔍
SHA1 54b366e2e9d3b26c48e9608011f45b32379e135e 🔍
SHA256 904d4dacc465e63be2d6b3b09a9941ed3097d461cc468e2a79b90e6df82a3869 🔍
SHA3 0d0434465a532ca73630c5254c9257e1f2c88bcd9176a93f0dec7a45f1dea6db 🔍

1 (#3)

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x36c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.40881
MD5 16931ad328adfaf238c541dfdde50722 🔍
SHA1 41872a352e24fcf2fa000b18d5b3b01d5cff4f30 🔍
SHA256 faddf4cb76e391f62c994aa7d13cbfa595077ad9baac6f8c20e5ef31a0cad529 🔍
SHA3 03e7cca4da4e36628cd1d053d1f72ee052e5ef631afcab6ba3b4dcd7398b5f1b 🔍

1 (#4)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x50d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.25791
MD5 84da8dee6b319ea0b10b6de5489c6aae 🔍
SHA1 5f8991f3e065fd95614859a293f88b9c70e4bb23 🔍
SHA256 abf8f2022f12f350789d961aceaf9ccfd53e7ec58d8c9934cfce77779b4eac11 🔍
SHA3 08f0562915b54bedce5a84e9d32cb2efcc538268785103b1852338e20a3b4606 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.6.0.0
ProductVersion 1.6.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName madcow team
FileDescription TrackDayR Mod Manager
FileVersion (#2) 1.6.0.0
InternalName TrackDayR Mod Manager
LegalCopyright Created with love by the madcow team - for the TrackDayR community
OriginalFilename TrackDayR Mod Manager.exe
ProductName TrackDayR Mod Manager
ProductVersion (#2) 1.6.0.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Sep-23 12:12:32
Version 0.0
SizeofData 816
AddressOfRawData 0x3e0b8
PointerToRawData 0x3ceb8

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140042040
GuardCFCheckFunctionPointer 5368898736
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x1ffff8b2
Unmarked objects 0
C++ objects (33145) 183
C objects (33145) 12
ASM objects (33145) 11
253 (35721) 3
ASM objects (35721) 9
C objects (35721) 17
C++ objects (35721) 39
Imports (33145) 11
Total imports 158
C objects (36246) 29
Linker (36246) 1

Errors

Leave a comment

No comments yet.