| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jul-24 18:39:29 |
| Detected languages |
English - United States
|
| TLS Callbacks | 2 callback(s) detected. |
| CompanyName | Real |
| FileDescription | Real Setup |
| FileVersion | 1.0.0.0 |
| InternalName | RealSetup |
| OriginalFilename | RealSetup.exe |
| ProductName | Real |
| ProductVersion | 1.0.0.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish Uses known Diffie-Helman primes Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE is possibly a dropper. | Resource 101 detected as a PE Executable. |
| Malicious | VirusTotal score: 45/69 (Scanned on 2026-07-26 18:39:00) |
ALYac:
Gen:Variant.Cerbu.278886
AVG: Win64:MalwareX-gen [Trj] AhnLab-V3: Dropper/Win.MalwareX-gen.R782436 Antiy-AVL: Trojan/Win32.Sdum Arcabit: Trojan.Cerbu.D44166 Avast: Win64:MalwareX-gen [Trj] Avira: TR/W64.Agent BitDefender: Gen:Variant.Cerbu.278886 Bkav: W32.Malware.70A35EC7 CAT-QuickHeal: Trojan.Sdum CTX: exe.trojan.sdum CrowdStrike: win/malicious_confidence_100% (W) DrWeb: Trojan.Siggen33.3064 ESET-NOD32: Win64/GameTool_AGen.C potentially unsafe application Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Cerbu.278886 (B) F-Secure: Trojan.TR/W64.Agent Fortinet: Adware/GameTool_AGen GData: Gen:Variant.Cerbu.278886 Google: Detected Gridinsoft: Trojan.Win64.Kryptik.dd!n Ikarus: Trojan.W64.MalwareX K7AntiVirus: Unwanted-Program ( 006e231d1 ) K7GW: Unwanted-Program ( 006e231d1 ) Kaspersky: HEUR:Trojan.Win32.Sdum.gen Kingsoft: Win32.Trojan.Sdum.gen Lionic: Trojan.Win32.Sdum.4!c Malwarebytes: Trojan.Dropper McAfeeD: Trojan:Win/Wacatac.ENR MicroWorld-eScan: Gen:Variant.Cerbu.278886 Microsoft: Trojan:Win32/Egairtigado!rfn Paloalto: generic.ml Rising: Malware.Undefined!8.C (TFE:5:FtKAVutKhBM) Skyhigh: Artemis Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence Tencent: Malware.Win32.Gencirc.11e60d9a TrellixENS: Artemis!78425792AD72 TrendMicro: Trojan.Win32.SDUM.USBLGO26 TrendMicro-HouseCall: Trojan.Win32.SDUM.USBLGO26 VBA32: Trojan.Sdum VIPRE: Gen:Variant.Cerbu.278886 Varist: W64/ABTrojan.RURD-5069 Webroot: Win.Trojan.Gen Yandex: Backdoor.Agent!X516lEh0cw8 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x130 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Jul-24 18:39:29 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x478e00 |
| SizeOfInitializedData | 0xbd4600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000043F1E0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1053000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
OpenProcessToken
GetTokenInformation RegCloseKey RegCreateKeyExW RegDeleteKeyW RegDeleteValueW RegOpenKeyExW RegQueryValueExW RegSetValueExW RegDeleteTreeW SetEntriesInAclW SetNamedSecurityInfoW RegEnumKeyExW RegEnumValueW RegGetValueW CloseServiceHandle OpenSCManagerW OpenServiceW QueryServiceConfigW QueryServiceStatusEx CryptAcquireContextW CryptReleaseContext CryptGetHashParam CryptCreateHash CryptHashData CryptDestroyHash EventRegister EventSetInformation EventWriteTransfer EventUnregister CryptDestroyKey CryptGenRandom CryptSetHashParam ReportEventW CryptEnumProvidersW CryptSignHashW CryptDecrypt RegisterEventSourceW DeregisterEventSource CryptGetProvParam CryptGetUserKey CryptExportKey |
|---|---|
| bcrypt.dll |
BCryptDestroyHash
BCryptFinishHash BCryptHashData BCryptCreateHash BCryptCloseAlgorithmProvider BCryptGetProperty BCryptOpenAlgorithmProvider |
| CRYPT32.dll |
CertGetNameStringW
CryptQueryObject CertGetCertificateChain CertFreeCertificateChain CertVerifyCertificateChainPolicy CryptBinaryToStringA CertFreeCertificateContext CertGetEnhancedKeyUsage CertGetIntendedKeyUsage CertOpenSystemStoreA CryptMsgGetParam CryptMsgClose CertFindCertificateInStore CertOpenSystemStoreW CertEnumCertificatesInStore CertOpenStore CertGetCertificateContextProperty CertCloseStore CertDuplicateCertificateContext |
| IPHLPAPI.DLL |
GetAdaptersAddresses
if_nametoindex |
| ncrypt.dll |
NCryptFinalizeKey
NCryptCreatePersistedKey NCryptOpenStorageProvider NCryptDeleteKey NCryptFreeObject |
| WINTRUST.dll |
WinVerifyTrust
|
| COMCTL32.dll |
InitCommonControlsEx
|
| SHELL32.dll |
SHGetFolderPathW
ShellExecuteExW ShellExecuteW SHGetPathFromIDListW SHBrowseForFolderW |
| ole32.dll |
CoCreateInstance
PropVariantClear CoInitializeEx CoTaskMemFree CoInitialize CreateStreamOnHGlobal StringFromGUID2 CoUninitialize CoCreateGuid CoSetProxyBlanket CoTaskMemAlloc |
| gdiplus.dll |
GdipGetImageWidth
GdipDisposeImage GdipCloneImage GdipSetPenLineJoin GdipSetPenEndCap GdipSetPenStartCap GdipDeletePen GdipCreatePen1 GdipCreateLineBrushI GdipCreateSolidFill GdipDeleteBrush GdipCloneBrush GdipDeleteRegion GdipCreateRegionPath GdipScaleMatrix GdipGetImageHeight GdipDeleteMatrix GdipCreateMatrix GdipTransformPath GdipAddPathRectangle GdipAddPathBezier GdipAddPathArc GdipAddPathLine GdipClosePathFigure GdipStartPathFigure GdipDeletePath GdipCreatePath GdiplusShutdown GdiplusStartup GdipFree GdipAlloc GdipCreateImageAttributes GdipCreateBitmapFromStream GdipDisposeImageAttributes GdipSetImageAttributesColorMatrix GdipCreateFromHDC GdipDeleteGraphics GdipSetSmoothingMode GdipSetPixelOffsetMode GdipSetTextRenderingHint GdipTranslateMatrix GdipSetInterpolationMode GdipDrawLine GdipDrawEllipse GdipDrawPath GdipFillRectangleI GdipFillEllipse GdipFillPath GdipDrawImageRectRect GdipSetClipRegion GdipResetClip |
| dwmapi.dll |
DwmSetWindowAttribute
|
| WS2_32.dll |
recv
WSAWaitForMultipleEvents WSAGetLastError ntohs WSAStartup WSACleanup accept bind closesocket getpeername getsockname WSAResetEvent WSAEventSelect WSAEnumNetworkEvents WSACreateEvent WSACloseEvent send getsockopt GetNameInfoW ioctlsocket htonl freeaddrinfo setsockopt htons connect getaddrinfo select listen WSASocketA recvfrom sendto inet_addr inet_ntoa gethostbyaddr gethostbyname getservbyport getservbyname shutdown __WSAFDIsSet WSAIoctl WSASetLastError socket |
| Secur32.dll |
InitSecurityInterfaceW
|
| KERNEL32.dll |
IsDebuggerPresent
SetConsoleCtrlHandler SetStdHandle FileTimeToSystemTime SystemTimeToTzSpecificLocalTime PeekNamedPipe GetFileInformationByHandle GetDriveTypeW FreeLibraryAndExitThread ExitThread FlsFree FlsSetValue FlsGetValue FlsAlloc RtlUnwindEx RtlLookupFunctionEntry RaiseException RtlPcToFileHeader InitializeSListHead GetStartupInfoW SetUnhandledExceptionFilter GetCPInfo LCMapStringEx DecodePointer EncodePointer SleepConditionVariableSRW WakeAllConditionVariable ExitProcess GetFileInformationByHandleEx CopyFile2 AreFileApisANSI CreateFile2 SetFileInformationByHandle GetFinalPathNameByHandleW GetFileAttributesExW FindFirstFileExW GetCurrentDirectoryW GetLocaleInfoEx UnhandledExceptionFilter HeapAlloc GetDateFormatW GetTimeFormatW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW FlushFileBuffers HeapReAlloc SetEndOfFile GetConsoleOutputCP IsProcessorFeaturePresent GetStringTypeW RtlCaptureContext IsValidCodePage GetOEMCP GetTimeZoneInformation GetCommandLineA GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW WriteConsoleW HeapSize SetFilePointerEx RtlVirtualUnwind ConvertThreadToFiberEx ConvertFiberToThread GetACP CreateSemaphoreA GetExitCodeThread ReleaseSemaphore InitializeCriticalSection LoadLibraryA GetSystemDirectoryA GetModuleHandleExW FindNextFileW FindFirstFileW GetCommandLineW CreateFileW GetFileSizeEx ReadFile WriteFile CloseHandle GetLastError ReleaseMutex WaitForSingleObject CreateMutexW Sleep GetCurrentProcess GetCurrentProcessId TerminateProcess GetExitCodeProcess CreateProcessW OpenProcess GetTickCount64 FreeLibrary GetModuleFileNameW GetProcAddress LoadLibraryExW LoadResource LockResource SizeofResource FindResourceW LocalFree QueryFullProcessImageNameW MoveFileExW MultiByteToWideChar CreateToolhelp32Snapshot Process32FirstW Process32NextW GetTickCount GlobalAlloc GlobalUnlock GlobalLock GlobalFree MulDiv GetSystemDirectoryW GetTempPathW CreateDirectoryW DeleteFileW GetLocalTime GetModuleHandleW WideCharToMultiByte GetDiskFreeSpaceExW GetEnvironmentVariableW ReleaseSRWLockExclusive AcquireSRWLockExclusive SetLastError FormatMessageA SleepEx EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection QueryPerformanceCounter QueryPerformanceFrequency InitializeConditionVariable GetFullPathNameW GetEnvironmentVariableA CompareFileTime GetSystemTimeAsFileTime VerSetConditionMask VerifyVersionInfoW WakeConditionVariable SleepConditionVariableCS WaitForSingleObjectEx CreateThread GetFileAttributesW OutputDebugStringA OutputDebugStringW GetProcessHeap HeapFree LoadLibraryW GetFileType GetStdHandle GetConsoleMode SetConsoleMode ReadConsoleA ReadConsoleW InitializeSRWLock ReleaseSRWLockShared AcquireSRWLockShared GetCurrentThreadId TlsAlloc TlsGetValue TlsSetValue TlsFree VirtualProtect VirtualFree SwitchToFiber DeleteFiber CreateFiberEx GetSystemTime SystemTimeToFileTime FindClose RtlUnwind |
| USER32.dll |
SetForegroundWindow
MessageBoxW EnumWindows GetClassNameW GetMessageW TranslateMessage DispatchMessageW PeekMessageW SendMessageW DefWindowProcW PostQuitMessage RegisterClassExW CreateWindowExW IsWindow DestroyWindow BringWindowToTop SetCapture ReleaseCapture SetTimer KillTimer GetSystemMetrics DrawTextW UpdateWindow GetDC ReleaseDC BeginPaint EndPaint InvalidateRect SetWindowTextW GetClientRect ScreenToClient PtInRect LoadCursorW LoadIconW GetWindowLongPtrW SetWindowLongPtrW EnumChildWindows GetProcessWindowStation GetUserObjectInformationW PostMessageW ShowWindow IsWindowVisible IsIconic |
| GDI32.dll |
SetBkMode
SetTextColor SelectObject EnumFontFamiliesExW DeleteObject DeleteDC CreateSolidBrush CreateFontW CreateCompatibleDC CreateCompatibleBitmap GetDeviceCaps BitBlt |
| OLEAUT32.dll |
SysFreeString
VariantInit VariantClear SysAllocString |
| WINHTTP.dll |
WinHttpReceiveResponse
WinHttpSendRequest WinHttpOpenRequest WinHttpSetTimeouts WinHttpSetOption WinHttpQueryDataAvailable WinHttpReadData WinHttpCrackUrl WinHttpCloseHandle WinHttpQueryHeaders WinHttpSetStatusCallback WinHttpOpen WinHttpConnect |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Real |
| FileDescription | Real Setup |
| FileVersion (#2) | 1.0.0.0 |
| InternalName | RealSetup |
| OriginalFilename | RealSetup.exe |
| ProductName | Real |
| ProductVersion (#2) | 1.0.0.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-24 18:39:29 |
| Version | 0.0 |
| SizeofData | 1264 |
| AddressOfRawData | 0x5ebab4 |
| PointerToRawData | 0x5eacb4 |
| StartAddressOfRawData | 0x1405ebff0 |
|---|---|
| EndAddressOfRawData | 0x1405ec198 |
| AddressOfIndex | 0x140633f28 |
| AddressOfCallbacks | 0x14047af90 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks |
0x000000014043EF00
0x000000014043EDD0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14062da00 |
| XOR Key | 0xf6c68c8f |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 197 |
| ASM objects (33145) | 16 |
| ASM objects (35721) | 10 |
| C objects (35721) | 19 |
| C++ objects (35721) | 101 |
| C objects (33145) | 25 |
| C objects (CVTCIL) (33145) | 1 |
| Imports (33145) | 37 |
| Total imports | 465 |
| Unmarked objects (#2) | 48 |
| C objects (36307) | 1054 |
| C++ objects (36231) | 14 |
| C objects (36231) | 2 |
| Resource objects (36231) | 1 |
| 151 | 1 |
| Linker (36231) | 1 |
No comments yet.