| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jul-20 23:02:14 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
pluto.pdb
|
| CompanyName | vrad |
| FileDescription | pluto |
| FileVersion | 0.1.0 |
| ProductName | pluto |
| ProductVersion | 0.1.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA256
Uses constants related to SHA512 Uses constants related to RC5 or RC6 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 3/70 (Scanned on 2026-07-21 08:39:14) |
AVG:
MalwareX-gen [Drp]
Avast: MalwareX-gen [Drp] Avira: DR/W64.MalwareX |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Jul-20 23:02:14 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x7e5000 |
| SizeOfInitializedData | 0x7da800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000007BD7FC (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xfc3000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| bcryptprimitives.dll |
ProcessPrng
|
|---|---|
| advapi32.dll |
RegOpenKeyExW
RegQueryValueExW RegCloseKey RegGetValueW |
| ntdll.dll |
NtCancelIoFileEx
RtlGetVersion NtDeviceIoControlFile RtlNtStatusToDosError NtReadFile NtOpenFile NtWriteFile NtCreateNamedPipeFile NtCreateFile |
| kernel32.dll |
GetSystemTimeAsFileTime
FlsGetValue SleepConditionVariableSRW WakeAllConditionVariable lstrlenW AcquireSRWLockExclusive ReleaseSRWLockExclusive FindNextFileW RtlLookupFunctionEntry LoadLibraryA GetSystemInfo QueryPerformanceCounter GetSystemTimePreciseAsFileTime WriteFileEx CreateProcessW GetWindowsDirectoryW GetSystemDirectoryW CompareStringOrdinal FreeEnvironmentStringsW CreateThread SetWaitableTimer CreateWaitableTimerExW LoadLibraryW FlsAlloc GetConsoleOutputCP GetStdHandle WriteConsoleW MultiByteToWideChar QueryPerformanceFrequency SleepEx ReadFileEx ExitProcess GetTempPathW SetEnvironmentVariableW FlsSetValue FindClose FindFirstFileExW RtlPcToFileHeader DeleteFileW SwitchToThread GetFileInformationByHandleEx DeviceIoControl CreateDirectoryW MoveFileExW GetCommandLineW GetEnvironmentStringsW GetCurrentDirectoryW SetLastError GetCurrentThread SetThreadStackGuarantee AddVectoredExceptionHandler WaitForSingleObject DuplicateHandle GetModuleHandleW GetUserDefaultUILanguage SetHandleInformation SetFileCompletionNotificationModes SetFileInformationByHandle GetFileAttributesW OutputDebugStringA OutputDebugStringW GetModuleFileNameW GetLastError GetProcessHeap HeapFree LoadLibraryExW FlsFree EncodePointer InitializeSListHead FreeLibrary ReleaseMutex CreateMutexA GetCurrentProcessId SetUnhandledExceptionFilter WaitForSingleObjectEx LCIDToLocaleName GetFullPathNameW WideCharToMultiByte GetCurrentProcess HeapReAlloc GetEnvironmentVariableW RtlVirtualUnwind RtlUnwindEx GetCurrentThreadId RaiseException GetModuleHandleA LoadLibraryExA Sleep HeapAlloc GetProcAddress CloseHandle InitializeCriticalSectionEx FormatMessageW GetFinalPathNameByHandleW RtlCaptureContext CreateFileW SetNamedPipeHandleState GetConsoleMode GetFileInformationByHandle GetQueuedCompletionStatusEx CreateIoCompletionPort CancelIoEx WriteFile ReadFile PostQueuedCompletionStatus GetOverlappedResult DeleteCriticalSection |
| user32.dll |
GetTouchInputInfo
RedrawWindow VkKeyScanW DrawTextW GetWindowDC OffsetRect GetMenuBarInfo TrackMouseEvent DestroyMenu DrawIconEx CheckMenuItem GetMenuItemInfoW RemoveMenu CreatePopupMenu CreateMenu SetMenu DrawMenuBar SetMenuItemInfoW SendMessageW TranslateMessage AppendMenuW InsertMenuW TrackPopupMenu PostQuitMessage CreateAcceleratorTableW DestroyAcceleratorTable CreateIcon ToUnicodeEx GetKeyState SystemParametersInfoW GetAsyncKeyState GetKeyboardState MapVirtualKeyExW GetMenu GetUpdateRect FillRect SetPropW SetWindowLongW EnableMenuItem DispatchMessageW LoadCursorW PostMessageW GetSystemMenu ClipCursor GetClipCursor ShowCursor MonitorFromRect GetRawInputData ClientToScreen EnumDisplayMonitors MonitorFromPoint GetKeyboardLayout SetWindowTextW GetWindowTextW GetWindowTextLengthW SetWindowDisplayAffinity SendInput SetForegroundWindow DestroyIcon PeekMessageW RegisterRawInputDevices ReleaseCapture SetCapture MsgWaitForMultipleObjectsEx GetSystemMetrics CloseTouchInputHandle RegisterWindowMessageA SetParent MapWindowPoints GetWindow SetFocus ShowWindow ReleaseDC SetWindowPos GetClientRect IsProcessDPIAware GetDC GetWindowRect SetWindowLongPtrW GetParent GetWindowLongPtrW FindWindowExW SetWindowRgn EnableWindow IsWindowEnabled GetWindowLongW SetCursor GetCursorPos PostThreadMessageW ScreenToClient ValidateRect GetMonitorInfoW IsWindowVisible RegisterTouchWindow IsWindow AdjustWindowRectEx GetWindowPlacement SetWindowPlacement ChangeDisplaySettingsExW FlashWindowEx DefWindowProcW GetMessageW MapVirtualKeyW TranslateAcceleratorW MonitorFromWindow GetForegroundWindow GetActiveWindow UpdateWindow InvalidateRect SetCursorPos InvalidateRgn DestroyWindow IsIconic EnumChildWindows DispatchMessageA GetMessageA CreateWindowExW RegisterClassExW SystemParametersInfoA AdjustWindowRect |
| shell32.dll |
DragFinish
SHGetKnownFolderPath ILFree SHAppBarMessage DragQueryFileW SHOpenFolderAndSelectItems ShellExecuteExW ILCreateFromPathW ShellExecuteW |
| api-ms-win-core-synch-l1-2-0.dll |
WakeByAddressAll
WakeByAddressSingle WaitOnAddress |
| ole32.dll |
CoUninitialize
CoInitializeEx RevokeDragDrop CoInitialize RegisterDragDrop CoTaskMemAlloc CoCreateInstance OleInitialize CoTaskMemFree CoCreateFreeThreadedMarshaler |
| comctl32.dll |
TaskDialogIndirect
SetWindowSubclass RemoveWindowSubclass DefSubclassProc |
| gdi32.dll |
CreateRectRgn
SetBkMode DeleteDC SelectObject CreateDIBSection GetDeviceCaps BitBlt CreateCompatibleDC CombineRgn CreateSolidBrush SetTextColor DeleteObject |
| shlwapi.dll |
SHCreateMemStream
|
| dwmapi.dll |
DwmGetWindowAttribute
DwmSetWindowAttribute DwmEnableBlurBehindWindow |
| oleaut32.dll |
SetErrorInfo
SysStringLen GetErrorInfo SysFreeString |
| ws2_32.dll |
freeaddrinfo
WSAStartup WSACleanup getaddrinfo closesocket getpeername getsockopt WSAGetLastError getsockname recv WSASend send setsockopt ioctlsocket connect shutdown bind WSASocketW WSAIoctl |
| bcrypt.dll |
BCryptGenRandom
|
| ADVAPI32.dll |
EventSetInformation
SystemFunction036 EventWriteTransfer EventUnregister EventRegister |
| api-ms-win-crt-math-l1-1-0.dll |
trunc
round roundf pow floor __setusermatherr |
| api-ms-win-crt-string-l1-1-0.dll |
wcscmp
strcpy_s wcslen _wcsicmp |
| api-ms-win-crt-convert-l1-1-0.dll |
_wtoi
wcstol _ultow_s |
| api-ms-win-crt-runtime-l1-1-0.dll |
_initialize_narrow_environment
_cexit _configure_narrow_argv _c_exit _register_thread_local_exe_atexit_callback __p___argv _initterm abort __p___argc _exit _initterm_e exit terminate _seh_filter_exe _set_app_type _crt_atexit _register_onexit_function _initialize_onexit_table _get_initial_narrow_environment |
| api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
_set_fmode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-heap-l1-1-0.dll |
calloc
_set_new_mode free _callnewh malloc |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.1.0.0 |
| ProductVersion | 0.1.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | vrad |
| FileDescription | pluto |
| FileVersion (#2) | 0.1.0 |
| ProductName | pluto |
| ProductVersion (#2) | 0.1.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-20 23:02:14 |
| Version | 0.0 |
| SizeofData | 34 |
| AddressOfRawData | 0xd737cc |
| PointerToRawData | 0xd72bcc |
| Referenced File | pluto.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-20 23:02:14 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xd737f0 |
| PointerToRawData | 0xd72bf0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-20 23:02:14 |
| Version | 0.0 |
| SizeofData | 1048 |
| AddressOfRawData | 0xd73804 |
| PointerToRawData | 0xd72c04 |
| StartAddressOfRawData | 0x140d73c68 |
|---|---|
| EndAddressOfRawData | 0x140d73e6c |
| AddressOfIndex | 0x140f35620 |
| AddressOfCallbacks | 0x1407e6c40 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x000000014077A670
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140f33080 |
| XOR Key | 0xd62ef7f4 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 14 |
| ASM objects (35403) | 9 |
| C objects (35403) | 13 |
| C++ objects (35403) | 46 |
| Imports (33145) | 5 |
| Total imports | 427 |
| C objects (35719) | 12 |
| Unmarked objects (#2) | 669 |
| Resource objects (35719) | 1 |
| Linker (35719) | 1 |
No comments yet.