| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Mar-23 15:37:49 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA1 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .fptable
Unusual section name found: .rcd7cb Section .rcd7cb is both writable and executable. |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE's resources present abnormal characteristics. | Resource 1 is possibly compressed or encrypted. |
| Malicious | VirusTotal score: 55/70 (Scanned on 2026-06-28 05:43:21) |
ALYac:
Gen:Variant.Lazy.715626
APEX: Malicious AVG: Win64:MalwareX-gen [Misc] AhnLab-V3: Trojan/Win.Lazy.R720011 Alibaba: TrojanDropper:Win64/ToolX.8832e31a Antiy-AVL: Trojan/Win32.Phonzy Arcabit: Trojan.Lazy.DAEB6A Avast: Win64:MalwareX-gen [Misc] Avira: TR/Patched.Gen BitDefender: Gen:Variant.Lazy.715626 Bkav: W32.Malware.B5462192 CTX: exe.trojan.generic ClamAV: Win.Tool.Zusy-10033075-0 CrowdStrike: win/malicious_confidence_100% (W) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS DrWeb: Trojan.DownLoader49.35384 ESET-NOD32: Win64/TrojanDropper.Agent.DO trojan Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Lazy.715626 (B) F-Secure: Trojan.TR/Patched.Gen Fortinet: W64/Agent.BPJ!tr GData: Win64.Virus.Fidxinf.A Google: Detected Gridinsoft: Trojan.Heur!.03012023 Jiangmin: Trojan.Generic.hssry K7AntiVirus: Trojan-Downloader ( 006dab321 ) K7GW: Trojan-Downloader ( 006d9c241 ) Kaspersky: Trojan.Win64.Patched.t Kingsoft: Win64.Trojan.Generic.a Malwarebytes: Generic.Trojan.Dropper.DDS MaxSecure: Trojan.Malware.121218.susgen McAfeeD: Real Protect-LS!9242AD20DB1F MicroWorld-eScan: Gen:Variant.Lazy.715626 Microsoft: Trojan:Win32/Kepavll!rfn Paloalto: generic.ml Panda: Trj/CI.A Rising: Trojan.Midie!8.12D29 (TFE:1:WvQqQDUantJ) Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Malicious PE Skyhigh: BehavesLike.Win64.Dropper.wc Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence Tencent: Trojan-DL.Win64.Agent.cbd Trapmine: malicious.high.ml.score TrellixENS: Artemis!9242AD20DB1F TrendMicro: Trojan.Win32.ZYX.USBLFC26 TrendMicro-HouseCall: Trojan.Win32.ZYX.USBLFC26 VBA32: TrojanDownloader.Win64.Agent VIPRE: Gen:Variant.Lazy.715626 Varist: W64/Agent.LXR.gen!Eldorado Zoner: Probably Heur.ExeHeaderL alibabacloud: Trojan[dropper]:Win/Zusy.Gen huorong: HackTool/Injector.f |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 8 |
| TimeDateStamp | 2026-Mar-23 15:37:49 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x33000 |
| SizeOfInitializedData | 0x37b400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000003B2000 (Section: .rcd7cb) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x3ce000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
DeviceIoControl
CreateFileW CloseHandle ReadFile VirtualFree GetCurrentProcess WriteFile VirtualAlloc LoadLibraryExA CreateToolhelp32Snapshot Sleep GetLastError Process32NextW LoadLibraryA DeleteFileW Process32FirstW LoadLibraryW GetWindowsDirectoryW GetProcAddress GetFileSize FreeLibrary WriteConsoleW HeapSize SetStdHandle GetProcessHeap SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetOEMCP GetACP IsValidCodePage FindNextFileW FindFirstFileExW FindClose WideCharToMultiByte EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection EncodePointer DecodePointer MultiByteToWideChar LCMapStringEx GetStringTypeW GetCPInfo ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW GetModuleHandleW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead RtlUnwindEx RtlPcToFileHeader RaiseException SetLastError InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree LoadLibraryExW ExitProcess GetModuleHandleExW GetModuleFileNameW GetStdHandle GetCommandLineA GetCommandLineW HeapAlloc HeapFree FlsAlloc FlsGetValue FlsSetValue FlsFree VirtualProtect CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetFileType WaitForSingleObject GetExitCodeProcess CreateProcessW GetFileAttributesExW FlushFileBuffers GetConsoleOutputCP GetConsoleMode GetFileSizeEx SetFilePointerEx ReadConsoleW HeapReAlloc RtlUnwind |
|---|---|
| USER32.dll |
SetWindowsHookExA
UnhookWindowsHookEx EnumWindows PostThreadMessageA GetWindowThreadProcessId IsWindowVisible |
| SHELL32.dll |
ShellExecuteW
|
| ntdll.dll |
RtlCaptureContext
RtlLookupFunctionEntry RtlVirtualUnwind RtlImageNtHeader |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-23 15:37:49 |
| Version | 0.0 |
| SizeofData | 1032 |
| AddressOfRawData | 0x43164 |
| PointerToRawData | 0x42564 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-23 15:37:49 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1400435b8 |
|---|---|
| EndAddressOfRawData | 0x1400435c0 |
| AddressOfIndex | 0x14020ea20 |
| AddressOfCallbacks | 0x140034498 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140048040 |
| XOR Key | 0xe872142e |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 178 |
| C objects (33145) | 17 |
| ASM objects (33145) | 8 |
| ASM objects (35207) | 10 |
| C objects (35207) | 17 |
| C++ objects (35207) | 82 |
| Imports (33145) | 9 |
| Total imports | 133 |
| C++ objects (LTCG) (35225) | 2 |
| Resource objects (35225) | 1 |
| 151 | 1 |
| Linker (35225) | 1 |
No comments yet.