| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Feb-05 14:12:47 |
| Info | Matching compiler(s): | MASM/TASM - sig2(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Malicious | The PE contains functions mostly used by malware. |
Uses functions commonly found in keyloggers:
|
| Info | The PE is digitally signed. |
Signer: Guangzhou Kingteller Technology Co.
Issuer: VeriSign Class 3 Code Signing 2010 CA |
| Malicious | VirusTotal score: 9/63 (Scanned on 2026-02-06 10:00:22) |
Bkav:
W64.AIDetectMalware
Cylance: Unsafe ESET-NOD32: Win64/GenKryptik_AGen.CBW trojan Elastic: malicious (moderate confidence) GData: Win64.Trojan.Agent.KBA0V5 McAfeeD: ti!EE42F0CFED07 Microsoft: PUA:Win32/ClickAthlete Sophos: Generic Reputation PUA (PUA) TrellixENS: Artemis!F82BF0042BCF |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 5 |
| TimeDateStamp | 2026-Feb-05 14:12:47 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xf9400 |
| SizeOfInitializedData | 0x53a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000C4610 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x151000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x14136f |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
VirtualProtect
GetCurrentProcess VirtualAlloc GetModuleHandleA Sleep GetTickCount64 DisableThreadLibraryCalls K32GetModuleInformation CreateThread Beep CreateDirectoryA GetTickCount VirtualQuery GetProcAddress ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW SetUnhandledExceptionFilter GetStartupInfoW GetModuleHandleW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetLastError CreateDirectoryExW CopyFile2 CloseHandle MoveFileExW CreateHardLinkW GetFileInformationByHandleEx AreFileApisANSI CreateSymbolicLinkW CreateFile2 MultiByteToWideChar GetTempPathW WideCharToMultiByte SetFileTime SetFileInformationByHandle SetFileAttributesW GetFullPathNameW GetFinalPathNameByHandleW GetFileAttributesExW GetFileAttributesW GetDiskFreeSpaceExW FindNextFileW FindFirstFileExW FindFirstFileW FindClose CreateDirectoryW GetCurrentDirectoryW SetCurrentDirectoryW GetLocaleInfoEx FormatMessageA LocalFree InitializeSListHead GetSystemTimeAsFileTime DeviceIoControl |
|---|---|
| USER32.dll |
CallNextHookEx
GetCursorPos keybd_event MapVirtualKeyA MessageBoxA SendInput GetSystemMetrics GetAsyncKeyState GetKeyNameTextA |
| MSVCP140.dll |
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Gnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Pnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@M@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?width@ios_base@std@@QEAA_J_J@Z ?width@ios_base@std@@QEBA_JXZ ?flags@ios_base@std@@QEBAHXZ ?good@ios_base@std@@QEBA_NXZ ?_Getcat@?$ctype@_W@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?narrow@?$ctype@_W@std@@QEBAPEB_WPEB_W0DPEAD@Z ?always_noconv@codecvt_base@std@@QEBA_NXZ ?_W_Getmonths@_Locinfo@std@@QEBAPEBGXZ ?_W_Getdays@_Locinfo@std@@QEBAPEBGXZ ?_Getcvt@_Locinfo@std@@QEBA?AU_Cvtvec@@XZ ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD0@Z ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ ?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ _Query_perf_counter ?_Syserror_map@std@@YAPEBDH@Z ?_Xlength_error@std@@YAXPEBD@Z ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Xbad_function_call@std@@YAXXZ ?_Winerror_map@std@@YAHH@Z ?_Xout_of_range@std@@YAXPEBD@Z ?_Id_cnt@id@locale@std@@0HA ?_Xinvalid_argument@std@@YAXPEBD@Z ?id@?$ctype@_W@std@@2V0locale@2@A ?_Xbad_alloc@std@@YAXXZ ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?uncaught_exceptions@std@@YAHXZ ??0_Lockit@std@@QEAA@H@Z ??1_Lockit@std@@QEAA@XZ _Query_perf_frequency ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z |
| WINMM.dll |
PlaySoundW
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
memmove
__std_exception_destroy memcmp memchr __std_type_info_destroy_list memset _CxxThrowException __C_specific_handler __current_exception_context __current_exception __std_terminate __std_exception_copy memcpy _purecall |
| api-ms-win-crt-stdio-l1-1-0.dll |
fgetc
__stdio_common_vsprintf_s fread fclose fflush __stdio_common_vswprintf fwrite __acrt_iob_func fgetpos __stdio_common_vswprintf_s fputc setvbuf ungetc _get_stream_buffer_pointers fsetpos _fseeki64 __stdio_common_vfprintf __stdio_common_vsprintf |
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
malloc free calloc |
| api-ms-win-crt-convert-l1-1-0.dll |
strtol
strtof mbstowcs strtod strtoll strtoull |
| api-ms-win-crt-string-l1-1-0.dll |
wcslen
isdigit strlen towlower |
| api-ms-win-crt-math-l1-1-0.dll |
cos
fmodf ceilf atanf sqrtf cosf atan2f atan2 atan asin acosf _dclass _dsign sin truncf sinf pow sqrt fmaxf fminf |
| api-ms-win-crt-utility-l1-1-0.dll |
rand
|
| api-ms-win-crt-filesystem-l1-1-0.dll |
_unlock_file
_lock_file |
| api-ms-win-crt-locale-l1-1-0.dll |
localeconv
___lc_codepage_func |
| api-ms-win-crt-runtime-l1-1-0.dll |
_initialize_onexit_table
_initterm _cexit _crt_at_quick_exit _crt_atexit terminate _seh_filter_dll _execute_onexit_table abort _register_onexit_function _errno _initterm_e _initialize_narrow_environment _configure_narrow_argv |
| api-ms-win-crt-time-l1-1-0.dll |
_localtime64
_time64 |
| api-ms-win-crt-environment-l1-1-0.dll |
getenv
|
| Ordinal | 1 |
|---|---|
| Address | 0x760a0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Feb-05 14:12:47 |
| Version | 0.0 |
| SizeofData | 900 |
| AddressOfRawData | 0x1156c4 |
| PointerToRawData | 0x113ec4 |
| StartAddressOfRawData | 0x180115a68 |
|---|---|
| EndAddressOfRawData | 0x180115a70 |
| AddressOfIndex | 0x18012ee9c |
| AddressOfCallbacks | 0x1800fb9d8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x18012e140 |
| XOR Key | 0xc0c22a9b |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 22 |
| Imports (35403) | 6 |
| ASM objects (35403) | 3 |
| C objects (35403) | 8 |
| C++ objects (35403) | 27 |
| Imports (33145) | 7 |
| Total imports | 240 |
| C++ objects (LTCG) (35723) | 3 |
| ASM objects (35723) | 2 |
| Exports (35723) | 1 |
| Linker (35723) | 1 |