f02c3e1ebf64945fc8c26b6e8893a151a38af266a37d5f6505dddce65abb9cc6

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Jul-09 15:40:58
Detected languages English - United States
Debug artifacts C:\Users\shipi\source\repos\Laura\x64\Release\Laura.pdb

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • github.com
  • https://github.com
Info Cryptographic algorithms detected in the binary: Uses known Mersenne Twister constants
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • FindWindowW
Code injection capabilities (PowerLoader):
  • FindWindowW
  • GetWindowLongW
Possibly launches other programs:
  • ShellExecuteW
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • GetForegroundWindow
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 42/71 (Scanned on 2026-09-27 10:50:15) ALYac: Gen:Variant.Adware.Yogi.2053
APEX: Malicious
AVG: Win64:MalwareX-gen [Misc]
AhnLab-V3: Malware/Win.Tedy.R784169
Arcabit: Trojan.Adware.Yogi.D805
Avast: Win64:MalwareX-gen [Misc]
Avira: TR/W64.Agent
BitDefender: Gen:Variant.Adware.Yogi.2053
CTX: exe.trojan.generic
CrowdStrike: win/malicious_confidence_60% (D)
Cylance: Unsafe
Cynet: Malicious (score: 99)
DeepInstinct: MALICIOUS
ESET-NOD32: Win64/GameHack_AGen.ASS potentially unsafe application
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Adware.Yogi.2053 (B)
F-Secure: Trojan.TR/W64.Agent
Fortinet: Adware/GameHack_AGen
GData: Gen:Variant.Adware.Yogi.2053
Google: Detected
Gridinsoft: Hack.Win64.GameHack.cl
Ikarus: Trojan.W64.Agent
K7AntiVirus: Unwanted-Program ( 006d99a71 )
K7GW: Unwanted-Program ( 006d99a71 )
Lionic: Adware.Win32.GameHack.2!c
Malwarebytes: Malware.AI.191149256
MaxSecure: Trojan.Malware.8328611.susgen
McAfeeD: ti!F02C3E1EBF64
MicroWorld-eScan: Gen:Variant.Adware.Yogi.2053
Microsoft: Trojan:Win32/Kepavll!rfn
Paloalto: generic.ml
Panda: Trj/PhxIK.A
Rising: Trojan.Kryptik@AI.83 (RDML:UroC+h1qPqWtzcc5gaGmcQ)
SentinelOne: Static AI - Suspicious PE
Skyhigh: BehavesLike.Win64.Dropper.hh
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
TrellixENS: Artemis!95B888C829E0
TrendMicro: Trojan.Win32.ZYX.USBLGE26
TrendMicro-HouseCall: Trojan.Win32.ZYX.USBLGE26
VIPRE: Gen:Variant.Adware.Yogi.2053
Varist: W64/ABApplication.MGLU-1836

Hashes

MD5 95b888c829e02b6d13298baf90a4240d 🔍
SHA1 b2222581e6fd68531e7414a942e5072b1e62549f 🔍
SHA256 f02c3e1ebf64945fc8c26b6e8893a151a38af266a37d5f6505dddce65abb9cc6 🔍
SHA3 021df229254b2a8a5b7249fe4a1f78b1a3b9f4c43ca9cfed9f405970248a165a 🔍
SSDeep 12288:xOKL2dooc9v2jTVg1Ofg2URs/5XyIiVnWvi:4YR9v2jRQUnU2X1iVnWvi 🔍
Imports Hash 20b243cd56f166e22b79b071d386954f 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jul-09 15:40:58
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x7a200
SizeOfInitializedData 0x20400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000079500 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x9f000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 f80761ce971b3e057326e725b8fcd6c8 🔍
SHA1 1307fe7ebf0c480b5054386ed6741c49c06f71d5 🔍
SHA256 5ae7bb6cb7df4ad5c7756d73c4b6e7832a8f3d94becedf2e730bd1536722d3df 🔍
SHA3 5770e586157ea29864229d6052ad87164617351d1d253b565b526fd8bce280ce 🔍
VirtualSize 0x7a115
VirtualAddress 0x1000
SizeOfRawData 0x7a200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.49849

.rdata

MD5 1e7fb32c80ebd840f16c1c76b3797405 🔍
SHA1 f97334d5fbee88f55c122d0a1ac72e656704945a 🔍
SHA256 5780a18b68116fdcae7d2a2aaafd050eb23641e23d90a41e0c981c50efe0d5b8 🔍
SHA3 e2cd6b8ba7666bd1cb360822633be2bc6956c9db98d0d512b325fb1acd523ee8 🔍
VirtualSize 0x1491c
VirtualAddress 0x7c000
SizeOfRawData 0x14a00
PointerToRawData 0x7a600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.99451

.data

MD5 52a9184b494866f87a09d4253f956750 🔍
SHA1 198b8664c3a4b0a40d33861d6a302581cd194b2a 🔍
SHA256 4ebf9091f7e405f3bac5905f54b00ab46861497095a263588495009ec083af92 🔍
SHA3 68f2bc2f7310e17e768e90eb22491452487bcd94a76ad9511b53db85ebd9854e 🔍
VirtualSize 0x65e8
VirtualAddress 0x91000
SizeOfRawData 0x800
PointerToRawData 0x8f000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.11344

.pdata

MD5 4e3309b4f40edbf4894050bb92b6077e 🔍
SHA1 6ba71e953d0f93b16b96bd4959820f0dba3caa98 🔍
SHA256 1c24114ecebd782ce75861b3ce9dd10a1c62d19f5330e3bee1c4d6e9de290e6c 🔍
SHA3 e1115f1c5e342053c557e0c1e666402411c7ac219c0acb160ab978e0799eced3 🔍
VirtualSize 0x4df4
VirtualAddress 0x98000
SizeOfRawData 0x4e00
PointerToRawData 0x8f800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.88502

.rsrc

MD5 912b76bed2c62eceb7d3360a1fa3f3df 🔍
SHA1 49def09fc45dac879753b07a9f5b11e8da5c7c26 🔍
SHA256 5bdf945476950a1f4145d23db9010f9e7ee240db23e21f0d7ad8636526cc37bd 🔍
SHA3 9eabd4836e586aa8dddb7b61e1ce07a58f93b8c6558a951ebbef87aa27351617 🔍
VirtualSize 0x1e0
VirtualAddress 0x9d000
SizeOfRawData 0x200
PointerToRawData 0x94600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.71377

.reloc

MD5 dfadcf1467c1d718af5c1aa41e22f9ff 🔍
SHA1 4179fa0e89f5d73c7b1585cfb4b09c265340fc36 🔍
SHA256 e649c87e53fcd35e1b54e0697997d1f6f139acc5d1509ea39240aa22a5158c3d 🔍
SHA3 cd728d6a5663b0937715a77ed70781c146aa6d33466be951005ffb9c3aeaf6ea 🔍
VirtualSize 0x2d0
VirtualAddress 0x9e000
SizeOfRawData 0x400
PointerToRawData 0x94800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.39316

Imports

d3d11.dll D3D11CreateDevice
KERNEL32.dll QueryPerformanceFrequency
GetProcAddress
FreeLibrary
QueryPerformanceCounter
ReadFile
Sleep
CreateFileA
WaitForSingleObjectEx
CloseHandle
GetFileSize
GetModuleHandleW
CreateDirectoryA
GetTickCount
DeleteFileA
GetModuleFileNameA
GetCurrentProcess
GetCurrentProcessId
FindFirstFileA
FindNextFileA
FindClose
GlobalLock
GetLocaleInfoA
FindFirstFileW
CreateFile2
GetLocaleInfoEx
FormatMessageA
AreFileApisANSI
GetLastError
LocalFree
InitializeSListHead
GetFileInformationByHandleEx
GetSystemTimeAsFileTime
GetCurrentThreadId
SetUnhandledExceptionFilter
GlobalFree
GlobalAlloc
SleepConditionVariableSRW
WakeAllConditionVariable
AcquireSRWLockExclusive
LoadLibraryA
GetModuleHandleA
GlobalUnlock
WideCharToMultiByte
MultiByteToWideChar
ReleaseSRWLockExclusive
GetFileAttributesExW
USER32.dll CloseClipboard
GetAsyncKeyState
PostQuitMessage
FindWindowW
SetLayeredWindowAttributes
GetClipboardData
SetClipboardData
MoveWindow
ShowWindow
RegisterClassExW
CreateWindowExW
DefWindowProcW
GetWindowLongW
EmptyClipboard
DispatchMessageW
PeekMessageW
OpenClipboard
GetCursorPos
SetCursorPos
ReleaseCapture
IsWindowUnicode
GetClientRect
SetWindowDisplayAffinity
SetCursor
SetCapture
LoadCursorW
GetForegroundWindow
GetKeyboardLayout
TrackMouseEvent
ClientToScreen
GetCapture
TranslateMessage
mouse_event
SetWindowLongW
GetKeyState
GetMessageExtraInfo
ScreenToClient
SHELL32.dll ShellExecuteW
IMM32.dll ImmSetCandidateWindow
ImmReleaseContext
ImmGetContext
ImmSetCompositionWindow
dwmapi.dll DwmExtendFrameIntoClientArea
D3DCOMPILER_47.dll D3DCompile
WINMM.dll timeEndPeriod
timeBeginPeriod
MSVCP140.dll ?_Syserror_map@std@@YAPEBDH@Z
?_Winerror_map@std@@YAHH@Z
_Thrd_yield
_Query_perf_counter
?_Xlength_error@std@@YAXPEBD@Z
_Query_perf_frequency
dcomp.dll DCompositionCreateDevice
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll memcpy
memchr
memset
memcmp
__current_exception_context
__current_exception
__C_specific_handler
strrchr
strstr
__std_exception_copy
__std_exception_destroy
strchr
__std_terminate
memmove
_CxxThrowException
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
__p__commode
_set_fmode
ftell
fflush
fopen_s
fclose
fgets
fseek
__stdio_common_vsprintf_s
__stdio_common_vsscanf
fread
__stdio_common_vsprintf
_wfopen
fwrite
__stdio_common_vfprintf
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-heap-l1-1-0.dll free
_callnewh
_set_new_mode
malloc
api-ms-win-crt-convert-l1-1-0.dll atoi
atof
strtoull
api-ms-win-crt-time-l1-1-0.dll _localtime64_s
_time64
api-ms-win-crt-math-l1-1-0.dll pow
fmodf
fmaxf
sinf
sqrtf
logf
__setusermatherr
fminf
acosf
atan2f
log
ceilf
cosf
floorf
powf
api-ms-win-crt-string-l1-1-0.dll strcpy_s
_wcsicmp
wcslen
_wcsnicmp
strcmp
strlen
strncmp
strncpy
strncpy_s
api-ms-win-crt-runtime-l1-1-0.dll _configure_narrow_argv
abort
_initialize_narrow_environment
terminate
_initialize_onexit_table
_register_thread_local_exe_atexit_callback
_c_exit
__p___argv
__p___argc
_register_onexit_function
_exit
exit
_initterm_e
_initterm
_get_initial_narrow_environment
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
api-ms-win-crt-locale-l1-1-0.dll ___lc_codepage_func
_configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jul-09 15:40:58
Version 0.0
SizeofData 80
AddressOfRawData 0x86ef4
PointerToRawData 0x854f4
Referenced File C:\Users\shipi\source\repos\Laura\x64\Release\Laura.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jul-09 15:40:58
Version 0.0
SizeofData 20
AddressOfRawData 0x86f44
PointerToRawData 0x85544

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-09 15:40:58
Version 0.0
SizeofData 892
AddressOfRawData 0x86f58
PointerToRawData 0x85558

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jul-09 15:40:58
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1400872f8
EndAddressOfRawData 0x140087300
AddressOfIndex 0x1400916d8
AddressOfCallbacks 0x14007c708
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140091040

RICH Header

XOR Key 0xcb8a95a2
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 18
Imports (35721) 6
ASM objects (35721) 4
C objects (35721) 10
C++ objects (35721) 34
Imports (33145) 21
Total imports 230
C++ objects (LTCG) (36248) 15
ASM objects (36244) 1
Resource objects (36248) 1
Linker (36248) 1

Errors

Leave a comment

No comments yet.