| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Jul-09 15:40:58 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\shipi\source\repos\Laura\x64\Release\Laura.pdb
|
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses known Mersenne Twister constants |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 42/71 (Scanned on 2026-09-27 10:50:15) |
ALYac:
Gen:Variant.Adware.Yogi.2053
APEX: Malicious AVG: Win64:MalwareX-gen [Misc] AhnLab-V3: Malware/Win.Tedy.R784169 Arcabit: Trojan.Adware.Yogi.D805 Avast: Win64:MalwareX-gen [Misc] Avira: TR/W64.Agent BitDefender: Gen:Variant.Adware.Yogi.2053 CTX: exe.trojan.generic CrowdStrike: win/malicious_confidence_60% (D) Cylance: Unsafe Cynet: Malicious (score: 99) DeepInstinct: MALICIOUS ESET-NOD32: Win64/GameHack_AGen.ASS potentially unsafe application Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Adware.Yogi.2053 (B) F-Secure: Trojan.TR/W64.Agent Fortinet: Adware/GameHack_AGen GData: Gen:Variant.Adware.Yogi.2053 Google: Detected Gridinsoft: Hack.Win64.GameHack.cl Ikarus: Trojan.W64.Agent K7AntiVirus: Unwanted-Program ( 006d99a71 ) K7GW: Unwanted-Program ( 006d99a71 ) Lionic: Adware.Win32.GameHack.2!c Malwarebytes: Malware.AI.191149256 MaxSecure: Trojan.Malware.8328611.susgen McAfeeD: ti!F02C3E1EBF64 MicroWorld-eScan: Gen:Variant.Adware.Yogi.2053 Microsoft: Trojan:Win32/Kepavll!rfn Paloalto: generic.ml Panda: Trj/PhxIK.A Rising: Trojan.Kryptik@AI.83 (RDML:UroC+h1qPqWtzcc5gaGmcQ) SentinelOne: Static AI - Suspicious PE Skyhigh: BehavesLike.Win64.Dropper.hh Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence TrellixENS: Artemis!95B888C829E0 TrendMicro: Trojan.Win32.ZYX.USBLGE26 TrendMicro-HouseCall: Trojan.Win32.ZYX.USBLGE26 VIPRE: Gen:Variant.Adware.Yogi.2053 Varist: W64/ABApplication.MGLU-1836 |
| MD5 | 95b888c829e02b6d13298baf90a4240d 🔍 |
|---|---|
| SHA1 | b2222581e6fd68531e7414a942e5072b1e62549f 🔍 |
| SHA256 | f02c3e1ebf64945fc8c26b6e8893a151a38af266a37d5f6505dddce65abb9cc6 🔍 |
| SHA3 | 021df229254b2a8a5b7249fe4a1f78b1a3b9f4c43ca9cfed9f405970248a165a 🔍 |
| SSDeep | 12288:xOKL2dooc9v2jTVg1Ofg2URs/5XyIiVnWvi:4YR9v2jRQUnU2X1iVnWvi 🔍 |
| Imports Hash | 20b243cd56f166e22b79b071d386954f 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Jul-09 15:40:58 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x7a200 |
| SizeOfInitializedData | 0x20400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000079500 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x9f000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | f80761ce971b3e057326e725b8fcd6c8 🔍 |
|---|---|
| SHA1 | 1307fe7ebf0c480b5054386ed6741c49c06f71d5 🔍 |
| SHA256 | 5ae7bb6cb7df4ad5c7756d73c4b6e7832a8f3d94becedf2e730bd1536722d3df 🔍 |
| SHA3 | 5770e586157ea29864229d6052ad87164617351d1d253b565b526fd8bce280ce 🔍 |
| VirtualSize | 0x7a115 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x7a200 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.49849 |
| MD5 | 1e7fb32c80ebd840f16c1c76b3797405 🔍 |
|---|---|
| SHA1 | f97334d5fbee88f55c122d0a1ac72e656704945a 🔍 |
| SHA256 | 5780a18b68116fdcae7d2a2aaafd050eb23641e23d90a41e0c981c50efe0d5b8 🔍 |
| SHA3 | e2cd6b8ba7666bd1cb360822633be2bc6956c9db98d0d512b325fb1acd523ee8 🔍 |
| VirtualSize | 0x1491c |
| VirtualAddress | 0x7c000 |
| SizeOfRawData | 0x14a00 |
| PointerToRawData | 0x7a600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.99451 |
| MD5 | 52a9184b494866f87a09d4253f956750 🔍 |
|---|---|
| SHA1 | 198b8664c3a4b0a40d33861d6a302581cd194b2a 🔍 |
| SHA256 | 4ebf9091f7e405f3bac5905f54b00ab46861497095a263588495009ec083af92 🔍 |
| SHA3 | 68f2bc2f7310e17e768e90eb22491452487bcd94a76ad9511b53db85ebd9854e 🔍 |
| VirtualSize | 0x65e8 |
| VirtualAddress | 0x91000 |
| SizeOfRawData | 0x800 |
| PointerToRawData | 0x8f000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.11344 |
| MD5 | 4e3309b4f40edbf4894050bb92b6077e 🔍 |
|---|---|
| SHA1 | 6ba71e953d0f93b16b96bd4959820f0dba3caa98 🔍 |
| SHA256 | 1c24114ecebd782ce75861b3ce9dd10a1c62d19f5330e3bee1c4d6e9de290e6c 🔍 |
| SHA3 | e1115f1c5e342053c557e0c1e666402411c7ac219c0acb160ab978e0799eced3 🔍 |
| VirtualSize | 0x4df4 |
| VirtualAddress | 0x98000 |
| SizeOfRawData | 0x4e00 |
| PointerToRawData | 0x8f800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.88502 |
| MD5 | 912b76bed2c62eceb7d3360a1fa3f3df 🔍 |
|---|---|
| SHA1 | 49def09fc45dac879753b07a9f5b11e8da5c7c26 🔍 |
| SHA256 | 5bdf945476950a1f4145d23db9010f9e7ee240db23e21f0d7ad8636526cc37bd 🔍 |
| SHA3 | 9eabd4836e586aa8dddb7b61e1ce07a58f93b8c6558a951ebbef87aa27351617 🔍 |
| VirtualSize | 0x1e0 |
| VirtualAddress | 0x9d000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x94600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.71377 |
| MD5 | dfadcf1467c1d718af5c1aa41e22f9ff 🔍 |
|---|---|
| SHA1 | 4179fa0e89f5d73c7b1585cfb4b09c265340fc36 🔍 |
| SHA256 | e649c87e53fcd35e1b54e0697997d1f6f139acc5d1509ea39240aa22a5158c3d 🔍 |
| SHA3 | cd728d6a5663b0937715a77ed70781c146aa6d33466be951005ffb9c3aeaf6ea 🔍 |
| VirtualSize | 0x2d0 |
| VirtualAddress | 0x9e000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x94800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 4.39316 |
| d3d11.dll |
D3D11CreateDevice
|
|---|---|
| KERNEL32.dll |
QueryPerformanceFrequency
GetProcAddress FreeLibrary QueryPerformanceCounter ReadFile Sleep CreateFileA WaitForSingleObjectEx CloseHandle GetFileSize GetModuleHandleW CreateDirectoryA GetTickCount DeleteFileA GetModuleFileNameA GetCurrentProcess GetCurrentProcessId FindFirstFileA FindNextFileA FindClose GlobalLock GetLocaleInfoA FindFirstFileW CreateFile2 GetLocaleInfoEx FormatMessageA AreFileApisANSI GetLastError LocalFree InitializeSListHead GetFileInformationByHandleEx GetSystemTimeAsFileTime GetCurrentThreadId SetUnhandledExceptionFilter GlobalFree GlobalAlloc SleepConditionVariableSRW WakeAllConditionVariable AcquireSRWLockExclusive LoadLibraryA GetModuleHandleA GlobalUnlock WideCharToMultiByte MultiByteToWideChar ReleaseSRWLockExclusive GetFileAttributesExW |
| USER32.dll |
CloseClipboard
GetAsyncKeyState PostQuitMessage FindWindowW SetLayeredWindowAttributes GetClipboardData SetClipboardData MoveWindow ShowWindow RegisterClassExW CreateWindowExW DefWindowProcW GetWindowLongW EmptyClipboard DispatchMessageW PeekMessageW OpenClipboard GetCursorPos SetCursorPos ReleaseCapture IsWindowUnicode GetClientRect SetWindowDisplayAffinity SetCursor SetCapture LoadCursorW GetForegroundWindow GetKeyboardLayout TrackMouseEvent ClientToScreen GetCapture TranslateMessage mouse_event SetWindowLongW GetKeyState GetMessageExtraInfo ScreenToClient |
| SHELL32.dll |
ShellExecuteW
|
| IMM32.dll |
ImmSetCandidateWindow
ImmReleaseContext ImmGetContext ImmSetCompositionWindow |
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| D3DCOMPILER_47.dll |
D3DCompile
|
| WINMM.dll |
timeEndPeriod
timeBeginPeriod |
| MSVCP140.dll |
?_Syserror_map@std@@YAPEBDH@Z
?_Winerror_map@std@@YAHH@Z _Thrd_yield _Query_perf_counter ?_Xlength_error@std@@YAXPEBD@Z _Query_perf_frequency |
| dcomp.dll |
DCompositionCreateDevice
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
memcpy
memchr memset memcmp __current_exception_context __current_exception __C_specific_handler strrchr strstr __std_exception_copy __std_exception_destroy strchr __std_terminate memmove _CxxThrowException |
| api-ms-win-crt-stdio-l1-1-0.dll |
__acrt_iob_func
__p__commode _set_fmode ftell fflush fopen_s fclose fgets fseek __stdio_common_vsprintf_s __stdio_common_vsscanf fread __stdio_common_vsprintf _wfopen fwrite __stdio_common_vfprintf |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-heap-l1-1-0.dll |
free
_callnewh _set_new_mode malloc |
| api-ms-win-crt-convert-l1-1-0.dll |
atoi
atof strtoull |
| api-ms-win-crt-time-l1-1-0.dll |
_localtime64_s
_time64 |
| api-ms-win-crt-math-l1-1-0.dll |
pow
fmodf fmaxf sinf sqrtf logf __setusermatherr fminf acosf atan2f log ceilf cosf floorf powf |
| api-ms-win-crt-string-l1-1-0.dll |
strcpy_s
_wcsicmp wcslen _wcsnicmp strcmp strlen strncmp strncpy strncpy_s |
| api-ms-win-crt-runtime-l1-1-0.dll |
_configure_narrow_argv
abort _initialize_narrow_environment terminate _initialize_onexit_table _register_thread_local_exe_atexit_callback _c_exit __p___argv __p___argc _register_onexit_function _exit exit _initterm_e _initterm _get_initial_narrow_environment _set_app_type _seh_filter_exe _cexit _crt_atexit |
| api-ms-win-crt-locale-l1-1-0.dll |
___lc_codepage_func
_configthreadlocale |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-09 15:40:58 |
| Version | 0.0 |
| SizeofData | 80 |
| AddressOfRawData | 0x86ef4 |
| PointerToRawData | 0x854f4 |
| Referenced File | C:\Users\shipi\source\repos\Laura\x64\Release\Laura.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-09 15:40:58 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x86f44 |
| PointerToRawData | 0x85544 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-09 15:40:58 |
| Version | 0.0 |
| SizeofData | 892 |
| AddressOfRawData | 0x86f58 |
| PointerToRawData | 0x85558 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-09 15:40:58 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1400872f8 |
|---|---|
| EndAddressOfRawData | 0x140087300 |
| AddressOfIndex | 0x1400916d8 |
| AddressOfCallbacks | 0x14007c708 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140091040 |
| XOR Key | 0xcb8a95a2 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 18 |
| Imports (35721) | 6 |
| ASM objects (35721) | 4 |
| C objects (35721) | 10 |
| C++ objects (35721) | 34 |
| Imports (33145) | 21 |
| Total imports | 230 |
| C++ objects (LTCG) (36248) | 15 |
| ASM objects (36244) | 1 |
| Resource objects (36248) | 1 |
| Linker (36248) | 1 |
No comments yet.