| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Jun-28 10:07:31 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\0x5\Downloads\inferno.rocks\examples\example_win32_directx11\Release\example_win32_directx11.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 9/68 (Scanned on 2026-07-25 09:24:00) |
APEX:
Malicious
Bkav: W32.Malware.D2AA6343 CrowdStrike: win/malicious_confidence_60% (W) Elastic: malicious (high confidence) Google: Detected MaxSecure: Trojan.Malware.300983.susgen Microsoft: Trojan:Win32/Wacatac.B!ml Symantec: ML.Attribute.HighConfidence TrendMicro-HouseCall: Trojan.Win64.Gen.TL0101GM26ZM |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Jun-28 10:07:31 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xc8800 |
| SizeOfInitializedData | 0x7c600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000C8460 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x148000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| D3DCOMPILER_43.dll |
D3DCompile
|
| d3dx11_43.dll |
D3DX11CreateShaderResourceViewFromMemory
|
| KERNEL32.dll |
GlobalUnlock
GetModuleHandleA GetLocaleInfoA LoadLibraryA QueryPerformanceFrequency GetProcAddress VerSetConditionMask FreeLibrary QueryPerformanceCounter Sleep GetModuleHandleW GetSystemTimeAsFileTime GlobalLock ReadFile CloseHandle HeapAlloc HeapFree MapViewOfFile UnmapViewOfFile CreateFileMappingA SleepConditionVariableSRW SetUnhandledExceptionFilter GetCurrentProcessId WideCharToMultiByte GlobalFree GlobalAlloc MultiByteToWideChar GetFileSizeEx GetCurrentThreadId InitializeSListHead CreateFileA WakeAllConditionVariable ReleaseSRWLockExclusive AcquireSRWLockExclusive |
| USER32.dll |
GetCapture
ScreenToClient GetDC GetMessageExtraInfo GetKeyState UpdateWindow PostQuitMessage TranslateMessage PeekMessageW DispatchMessageW ClientToScreen ShowWindow RegisterClassExW GetKeyboardLayout CreateWindowExW DestroyWindow MonitorFromPoint DefWindowProcW SetCapture SetCursor SetProcessDPIAware IsWindowUnicode ReleaseCapture GetAsyncKeyState TrackMouseEvent SetCursorPos ReleaseDC GetCursorPos OpenClipboard CloseClipboard GetForegroundWindow UnregisterClassW EmptyClipboard GetClipboardData SetClipboardData LoadCursorW GetClientRect |
| GDI32.dll |
GetDeviceCaps
|
| SHELL32.dll |
ShellExecuteW
|
| IMM32.dll |
ImmSetCompositionWindow
ImmReleaseContext ImmGetContext ImmSetCandidateWindow |
| MSVCP140.dll |
?_Xlength_error@std@@YAXPEBD@Z
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
strchr
__std_exception_destroy __std_exception_copy strstr __std_terminate longjmp memcpy memmove memset memchr memcmp __current_exception __current_exception_context __C_specific_handler __intrinsic_setjmp _CxxThrowException strrchr |
| api-ms-win-crt-stdio-l1-1-0.dll |
ftell
__p__commode __acrt_iob_func fflush fclose fseek _set_fmode __stdio_common_vsscanf fread fwrite __stdio_common_vsprintf _wfopen __stdio_common_vfprintf |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-runtime-l1-1-0.dll |
_crt_atexit
_cexit _initialize_onexit_table _initialize_narrow_environment _seh_filter_exe _configure_narrow_argv _get_initial_narrow_environment _initterm _initterm_e exit _exit _register_onexit_function __p___argc __p___argv _c_exit _register_thread_local_exe_atexit_callback terminate _wassert _set_app_type |
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
_set_new_mode free _callnewh |
| api-ms-win-crt-string-l1-1-0.dll |
tolower
strncpy strcmp strlen strncmp |
| api-ms-win-crt-convert-l1-1-0.dll |
strtol
|
| api-ms-win-crt-math-l1-1-0.dll |
ceilf
powf logf floorf sinf cosf sqrtf __setusermatherr atan2f acosf fmodf |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-28 10:07:31 |
| Version | 0.0 |
| SizeofData | 130 |
| AddressOfRawData | 0xf9b10 |
| PointerToRawData | 0xf8710 |
| Referenced File | C:\Users\0x5\Downloads\inferno.rocks\examples\example_win32_directx11\Release\example_win32_directx11.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-28 10:07:31 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xf9b94 |
| PointerToRawData | 0xf8794 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-28 10:07:31 |
| Version | 0.0 |
| SizeofData | 852 |
| AddressOfRawData | 0xf9ba8 |
| PointerToRawData | 0xf87a8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-28 10:07:31 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1400f9f20 |
|---|---|
| EndAddressOfRawData | 0x1400f9f28 |
| AddressOfIndex | 0x14013b588 |
| AddressOfCallbacks | 0x1400ca5e0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140109040 |
| XOR Key | 0x92bd2f2a |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 18 |
| Imports (35721) | 6 |
| 253 (35721) | 1 |
| ASM objects (35721) | 4 |
| C objects (35721) | 10 |
| C++ objects (35721) | 29 |
| Imports (33145) | 12 |
| C objects (VS2022 Update 4 (17.4.5) compiler 31942) | 26 |
| Imports (21202) | 7 |
| Total imports | 172 |
| C++ objects (LTCG) (36248) | 9 |
| Resource objects (36248) | 1 |
| Linker (36248) | 1 |
No comments yet.