| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Oct-07 13:59:36 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
src_win.pdb
|
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 3/70 (Scanned on 2026-05-23 10:54:48) |
MaxSecure:
Trojan.Malware.300983.susgen
Skyhigh: BehavesLike.Win64.Dropper.dh TrellixENS: Artemis!AE36D2ABC77A |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2025-Oct-07 13:59:36 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x25400 |
| SizeOfInitializedData | 0x1b400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000024200 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x44000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| user32.dll |
DefWindowProcW
GetDC RegisterWindowMessageA IsProcessDPIAware MonitorFromWindow TrackPopupMenu ClientToScreen GetCursorPos GetWindowDC OffsetRect GetWindowRect MapWindowPoints GetMenuBarInfo ReleaseDC GetClientRect SetWindowPos DefWindowProcA GetMenuItemInfoW CreateWindowExA SystemParametersInfoA CreateAcceleratorTableW DestroyAcceleratorTable SendMessageW CheckMenuItem DestroyIcon DestroyMenu RemoveMenu SetMenu MessageBoxW DispatchMessageA TranslateMessage GetMessageA SetForegroundWindow ShowWindow SetWindowLongPtrA GetWindowLongPtrA RegisterClassA CreateWindowExW RegisterClassW LoadImageW DrawMenuBar SetMenuItemInfoW DrawIconEx AppendMenuW CreatePopupMenu CreateMenu PostQuitMessage SendInput DestroyWindow |
|---|---|
| gdi32.dll |
CreateSolidBrush
GetTextExtentPoint32A DeleteDC SelectObject CreateDIBSection CreateCompatibleDC GetDeviceCaps GetStockObject SetBkMode |
| shell32.dll |
Shell_NotifyIconW
ShellExecuteW Shell_NotifyIconGetRect |
| kernel32.dll |
GetProcAddress
LoadLibraryA LoadLibraryW GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetModuleFileNameW QueryPerformanceFrequency GetLastError GetCurrentThreadId GetModuleHandleW GetEnvironmentVariableW RtlVirtualUnwind WideCharToMultiByte ReleaseMutex lstrlenW GetCurrentProcess LoadLibraryExA WaitForSingleObjectEx QueryPerformanceCounter CreateMutexA GetCurrentProcessId GetModuleHandleA RtlLookupFunctionEntry RtlCaptureContext GetCurrentDirectoryW IsProcessorFeaturePresent HeapFree HeapAlloc FormatMessageW SetLastError UnhandledExceptionFilter CloseHandle SetUnhandledExceptionFilter GetProcessHeap SwitchToThread GetCommandLineW AddVectoredExceptionHandler SetThreadStackGuarantee GetCurrentThread HeapReAlloc CreateThread GetStdHandle GetConsoleMode GetConsoleOutputCP WriteConsoleW WaitForSingleObject MultiByteToWideChar |
| comctl32.dll |
DefSubclassProc
RemoveWindowSubclass SetWindowSubclass |
| uxtheme.dll |
CloseThemeData
DrawThemeText DrawThemeBackground OpenThemeData |
| ntdll.dll |
RtlNtStatusToDosError
NtWriteFile |
| oleaut32.dll |
SysFreeString
SysStringLen |
| api-ms-win-core-synch-l1-2-0.dll |
WakeByAddressAll
WaitOnAddress WakeByAddressSingle |
| bcryptprimitives.dll |
ProcessPrng
|
| VCRUNTIME140.dll |
__current_exception_context
__current_exception __C_specific_handler memmove memset memcpy __CxxFrameHandler3 memcmp |
| api-ms-win-crt-math-l1-1-0.dll |
round
__setusermatherr |
| api-ms-win-crt-runtime-l1-1-0.dll |
_seh_filter_exe
_get_initial_narrow_environment terminate _crt_atexit _set_app_type _exit _configure_narrow_argv _register_onexit_function _initialize_onexit_table __p___argc exit _initterm _register_thread_local_exe_atexit_callback _c_exit _cexit _initialize_narrow_environment __p___argv _initterm_e |
| api-ms-win-crt-stdio-l1-1-0.dll |
_set_fmode
__p__commode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-heap-l1-1-0.dll |
free
_set_new_mode |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Oct-07 13:59:36 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0x30ef4 |
| PointerToRawData | 0x2f6f4 |
| Referenced File | src_win.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Oct-07 13:59:36 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x30f18 |
| PointerToRawData | 0x2f718 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Oct-07 13:59:36 |
| Version | 0.0 |
| SizeofData | 856 |
| AddressOfRawData | 0x30f2c |
| PointerToRawData | 0x2f72c |
| StartAddressOfRawData | 0x1400312a8 |
|---|---|
| EndAddressOfRawData | 0x140031338 |
| AddressOfIndex | 0x140038598 |
| AddressOfCallbacks | 0x1400275e0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x000000014001C8C0
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140036200 |
| XOR Key | 0xb6f3a79d |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 10 |
| Imports (35207) | 3 |
| ASM objects (35207) | 3 |
| C objects (35207) | 9 |
| C++ objects (35207) | 23 |
| Total imports | 162 |
| Unmarked objects (#2) | 31 |
| Resource objects (35217) | 1 |
| Linker (35217) | 1 |
No comments yet.