| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2023-Aug-12 12:18:31 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\missy\source\repos\mappy\x64\Release\kdmapper.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA1 |
| Suspicious | The PE contains functions most legitimate programs don't use. |
Functions which can be used for anti-debugging purposes:
|
| Malicious | VirusTotal score: 47/69 (Scanned on 2026-07-14 19:57:32) |
ALYac:
Gen:Variant.Tedy.446160
APEX: Malicious AVG: FileRepMalware [Misc] AhnLab-V3: Trojan/Win.Generic.C4769590 Alibaba: HackTool:Win64/Krypt.b52e1aa7 Antiy-AVL: HackTool/Win64.Gamehack Arcabit: Trojan.Tedy.D6CED0 Avast: FileRepMalware [Misc] BitDefender: Gen:Variant.Tedy.446160 Bkav: W32.Malware.9FEEA710 CTX: exe.hacktool.generic ClamAV: Win.Malware.Genkryptik-10034801-0 CrowdStrike: win/malicious_confidence_100% (W) Cylance: Unsafe DrWeb: Tool.VulnDriver.22 ESET-NOD32: Win64/HackTool.GameHack.Q trojan Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Tedy.446160 (B) Fortinet: W64/GameHack.Q!tr GData: Gen:Variant.Tedy.446160 Google: Detected K7AntiVirus: Hacktool ( 005c5c791 ) K7GW: Hacktool ( 005c5c791 ) Lionic: Hacktool.Win32.GameHack.3!c Malwarebytes: Malware.AI.1382527231 MaxSecure: Trojan.Malware.220162201.susgen McAfeeD: Trojan:Win/Driverloader.EAA MicroWorld-eScan: Gen:Variant.Tedy.446160 Microsoft: HackTool:Win32/GameHack Paloalto: generic.ml Rising: Hacktool.GameHack!8.59E (CLOUD) Sangfor: Suspicious.Win32.Save.a SentinelOne: Static AI - Malicious PE Skyhigh: BehavesLike.Win64.Rootkit.ch Sophos: ATK/Kdmapper-A Symantec: ML.Attribute.HighConfidence TrellixENS: Artemis!D94FCFD73566 TrendMicro: HackTool.Win64.Gamehack.AU TrendMicro-HouseCall: HackTool.Win64.Gamehack.AU VIPRE: Gen:Variant.Tedy.446160 Varist: W64/GameHack.EK.gen!Eldorado VirIT: Trojan.Win32.Genus.VIJ Xcitium: Malware@#1lt3jgkisqlj8 Yandex: Riskware.GameHack!6nD4Nmg3sPg Zillya: Tool.GameHack.Win64.1625 ZoneAlarm: ATK/Kdmapper-A huorong: HackTool/DriverLoader.b |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2023-Aug-12 12:18:31 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xfc00 |
| SizeOfInitializedData | 0x12400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000000F840 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x26000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetCurrentThreadId
GetModuleHandleA GetLastError CloseHandle CreateFileW GetProcAddress DeleteCriticalSection GetCurrentProcessId SetUnhandledExceptionFilter GetTempPathW FormatMessageA InitializeCriticalSectionEx VirtualAlloc DeviceIoControl VirtualFree FindClose FindFirstFileExW GetFileAttributesExW GetFileInformationByHandle AreFileApisANSI SetLastError GetModuleHandleW WideCharToMultiByte IsDebuggerPresent OutputDebugStringW EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionAndSpinCount SetEvent ResetEvent WaitForSingleObjectEx CreateEventW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetSystemTimeAsFileTime InitializeSListHead LocalFree |
|---|---|
| ADVAPI32.dll |
RegCloseKey
RegDeleteTreeW RegCreateKeyW RegOpenKeyW RegSetKeyValueW |
| MSVCP140.dll |
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@_K@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@PEBX@Z ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ ?_Getcat@?$ctype@_W@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?widen@?$ctype@_W@std@@QEBA_WD@Z ?always_noconv@codecvt_base@std@@QEBA_NXZ ??Bid@locale@std@@QEAA_KXZ ?_Winerror_map@std@@YAHH@Z ?_Syserror_map@std@@YAPEBDH@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@K@Z ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@J@Z ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z ??1_Lockit@std@@QEAA@XZ ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ??0_Lockit@std@@QEAA@H@Z ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?uncaught_exception@std@@YA_NXZ ?wcout@std@@3V?$basic_ostream@_WU?$char_traits@_W@std@@@1@A ?id@?$ctype@_W@std@@2V0locale@2@A ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ ?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z ?put@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@_W@Z ?widen@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEBA_WD@Z ?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAA_JPEB_W_J@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?_Xlength_error@std@@YAXPEBD@Z |
| ntdll.dll |
NtQuerySystemInformation
RtlInitUnicodeString |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__current_exception
__C_specific_handler memset _CxxThrowException __std_terminate __std_exception_copy memcpy memcmp __current_exception_context memmove __std_exception_destroy |
| api-ms-win-crt-stdio-l1-1-0.dll |
_fseeki64
fread fsetpos ungetc _set_fmode __p__commode fputc setvbuf fgetpos fwrite _get_stream_buffer_pointers fflush fgetc fclose |
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
_set_new_mode _callnewh free |
| api-ms-win-crt-utility-l1-1-0.dll |
rand
srand |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_lock_file
_unlock_file _wremove |
| api-ms-win-crt-string-l1-1-0.dll |
_stricmp
_wcsicmp |
| api-ms-win-crt-time-l1-1-0.dll |
_time64
|
| api-ms-win-crt-runtime-l1-1-0.dll |
__p___wargv
_exit exit _configure_wide_argv _c_exit __p___argc _set_app_type _seh_filter_exe _register_thread_local_exe_atexit_callback _crt_atexit _register_onexit_function _initialize_onexit_table _get_initial_wide_environment _initterm_e _cexit _initterm terminate _initialize_wide_environment _invalid_parameter_noinfo_noreturn |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
___lc_codepage_func |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Aug-12 12:18:31 |
| Version | 0.0 |
| SizeofData | 83 |
| AddressOfRawData | 0x1d594 |
| PointerToRawData | 0x1c594 |
| Referenced File | C:\Users\missy\source\repos\mappy\x64\Release\kdmapper.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Aug-12 12:18:31 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x1d5e8 |
| PointerToRawData | 0x1c5e8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Aug-12 12:18:31 |
| Version | 0.0 |
| SizeofData | 888 |
| AddressOfRawData | 0x1d5fc |
| PointerToRawData | 0x1c5fc |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Aug-12 12:18:31 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x14001d998 |
|---|---|
| EndAddressOfRawData | 0x14001d9a0 |
| AddressOfIndex | 0x140022bac |
| AddressOfCallbacks | 0x140011640 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x138 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140022010 |
| XOR Key | 0x1629a3b8 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 18 |
| C objects (VS 2015/2017/2019 runtime 29118) | 10 |
| ASM objects (VS 2015/2017/2019 runtime 29118) | 4 |
| C++ objects (VS 2015/2017/2019 runtime 29118) | 33 |
| Imports (VS 2015/2017/2019 runtime 29118) | 6 |
| Imports (30795) | 9 |
| Total imports | 243 |
| C++ objects (LTCG) (VS2019 Update 8 (16.8.4) compiler 29336) | 6 |
| Resource objects (VS2019 Update 8 (16.8.4) compiler 29336) | 1 |
| Linker (VS2019 Update 8 (16.8.4) compiler 29336) | 1 |
No comments yet.