| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Mar-07 10:24:29 |
| Detected languages |
English - United States
|
| Suspicious | The PE is possibly packed. |
Unusual section name found: .fptable
Unusual section name found: .xn; Unusual section name found: .x*< Unusual section name found: ._Ib |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 45/71 (Scanned on 2026-06-10 21:33:41) |
ALYac:
Trojan.GenericKD.80014895
APEX: Malicious AVG: Win64:MalwareX-gen [Misc] Alibaba: Packed:Win32/VMProtect.b0fb3f92 Arcabit: Trojan.Generic.D4C4EE2F Avast: Win64:MalwareX-gen [Misc] Avira: TR/W64.Agent BitDefender: Trojan.GenericKD.80014895 Bkav: W32.Malware.919DE0F CTX: exe.trojan.vmprotect CrowdStrike: win/malicious_confidence_100% (W) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS ESET-NOD32: Win32/Packed.VMProtect.ACX trojan Elastic: malicious (high confidence) Emsisoft: Trojan.GenericKD.80014895 (B) F-Secure: Trojan.TR/W64.Agent Fortinet: W32/PossibleThreat GData: Trojan.GenericKD.80014895 Google: Detected Gridinsoft: Trojan.Heur!.02212023 Ikarus: Trojan.Win32.VMProtect K7AntiVirus: Riskware ( 005cdde21 ) K7GW: Riskware ( 005cdde21 ) Lionic: Trojan.Win32.VMProtect.4!c Malwarebytes: Malware.AI.1339289844 MaxSecure: Trojan.Malware.300983.susgen McAfeeD: Real Protect-LS!F3E8F4300B5D MicroWorld-eScan: Trojan.GenericKD.80014895 Microsoft: Trojan:Win32/Phonzy.A!ml Paloalto: generic.ml Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Malicious PE Skyhigh: BehavesLike.Win64.Injector.tc Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence Trapmine: suspicious.low.ml.score TrellixENS: Artemis!F3E8F4300B5D TrendMicro: TROJ_FRS.VSNTDD26 TrendMicro-HouseCall: TROJ_FRS.VSNTDD26 VIPRE: Trojan.GenericKD.80014895 Varist: W64/ABTrojan.IIEG-4341 ViRobot: Trojan.Win.Z.Agent.9871360.E alibabacloud: VirTool:Win/Wacatac.B9nj |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 11 |
| TimeDateStamp | 2026-Mar-07 10:24:29 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x42a00 |
| SizeOfInitializedData | 0x1e400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000B361CB (Section: ._Ib) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xf8f000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
CreateFileA
GetSystemDirectoryA Process32FirstW CloseHandle Module32FirstW GetProcAddress LocalFree ExitProcess GetModuleHandleW Module32NextW CreateFileMappingW MapViewOfFile GetExitCodeProcess VirtualQueryEx GetCurrentProcessId HeapSize SetStdHandle GetProcessHeap SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetOEMCP GetACP IsValidCodePage HeapReAlloc CreateProcessW WaitForSingleObject ReadConsoleW ReadFile GetConsoleMode Process32NextW GetLastError FormatMessageW CreateToolhelp32Snapshot Sleep SetProcessMitigationPolicy GetModuleHandleA UnmapViewOfFile GetCurrentProcess VirtualProtect WriteConsoleW GetModuleFileNameA GetConsoleOutputCP FlushFileBuffers SetFilePointerEx GetFileSizeEx GetFileType EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW FlsFree FlsSetValue FormatMessageA MultiByteToWideChar GetLocaleInfoEx CreateFileW FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesExW AreFileApisANSI GetFileInformationByHandleEx WideCharToMultiByte GetStringTypeW GetCurrentThreadId EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection EncodePointer DecodePointer LCMapStringEx ReleaseSRWLockExclusive WakeAllConditionVariable QueryPerformanceCounter GetSystemTimeAsFileTime GetCPInfo UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW InitializeSListHead RtlUnwindEx RtlPcToFileHeader RaiseException SetLastError InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW CreateThread ExitThread FreeLibraryAndExitThread GetModuleHandleExW GetModuleFileNameW GetStdHandle WriteFile HeapAlloc HeapFree FlsAlloc FlsGetValue RtlUnwind |
|---|---|
| USER32.dll |
PostQuitMessage
TranslateMessage SetFocus MessageBoxA GetWindowTextW DispatchMessageW ShowWindow SetWindowTextW SendMessageW CreateWindowExW PostMessageW EnableWindow RegisterClassW DefWindowProcW GetWindowThreadProcessId GetWindow IsWindowVisible EnumWindows GetWindowTextLengthW GetMessageW |
| GDI32.dll |
SetTextColor
SetBkMode CreateSolidBrush GetStockObject |
| ADVAPI32.dll |
AdjustTokenPrivileges
RegCloseKey OpenProcessToken RegOpenKeyExW RegQueryValueExW LookupPrivilegeValueW |
| SHELL32.dll |
ShellExecuteW
|
| ntdll.dll |
RtlLookupFunctionEntry
RtlCaptureContext RtlVirtualUnwind |
| WINHTTP.dll |
WinHttpReceiveResponse
WinHttpOpen WinHttpReadData WinHttpOpenRequest WinHttpCloseHandle WinHttpSendRequest WinHttpQueryDataAvailable WinHttpConnect |
| KERNEL32.dll (#2) |
CreateFileA
GetSystemDirectoryA Process32FirstW CloseHandle Module32FirstW GetProcAddress LocalFree ExitProcess GetModuleHandleW Module32NextW CreateFileMappingW MapViewOfFile GetExitCodeProcess VirtualQueryEx GetCurrentProcessId HeapSize SetStdHandle GetProcessHeap SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetOEMCP GetACP IsValidCodePage HeapReAlloc CreateProcessW WaitForSingleObject ReadConsoleW ReadFile GetConsoleMode Process32NextW GetLastError FormatMessageW CreateToolhelp32Snapshot Sleep SetProcessMitigationPolicy GetModuleHandleA UnmapViewOfFile GetCurrentProcess VirtualProtect WriteConsoleW GetModuleFileNameA GetConsoleOutputCP FlushFileBuffers SetFilePointerEx GetFileSizeEx GetFileType EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW FlsFree FlsSetValue FormatMessageA MultiByteToWideChar GetLocaleInfoEx CreateFileW FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesExW AreFileApisANSI GetFileInformationByHandleEx WideCharToMultiByte GetStringTypeW GetCurrentThreadId EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection EncodePointer DecodePointer LCMapStringEx ReleaseSRWLockExclusive WakeAllConditionVariable QueryPerformanceCounter GetSystemTimeAsFileTime GetCPInfo UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW InitializeSListHead RtlUnwindEx RtlPcToFileHeader RaiseException SetLastError InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW CreateThread ExitThread FreeLibraryAndExitThread GetModuleHandleExW GetModuleFileNameW GetStdHandle WriteFile HeapAlloc HeapFree FlsAlloc FlsGetValue RtlUnwind |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14005b040 |
No comments yet.