004e4c12ebdb62fbbd004b31d2c5cf9520e4c9d00ddfd03b7b6cfcbd460c334f

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Mar-28 14:40:34
Detected languages English - United States

Plugin Output

Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Suspicious The PE is possibly packed. Unusual section name found: .fptable
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 30c42fd01b1803bf5b12fc60c4783a91
SHA1 6144f9e21673129887dbee2ceb87811a0c4e167b
SHA256 004e4c12ebdb62fbbd004b31d2c5cf9520e4c9d00ddfd03b7b6cfcbd460c334f
SHA3 0e456c06d754bcfda101ad8f42f4a54864ce55a52528d37f123e56c4bf7bfa7c
SSDeep 6144:5HOWcMFEApCNBwY1T62fEbHcCHmj0eHYLP3sca5/:1O4q1QgzR4r3
Imports Hash 31eab0c54b955498aa165c451949cca4

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Mar-28 14:40:34
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x57200
SizeOfInitializedData 0x1ea00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000034FB0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x7b000
SizeOfHeaders 0x400
Checksum 0x784ba
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 0e559e1610b0bf1f29b3886e6992746c
SHA1 c8af74196453522a52a8fe5ede157497dc962cd6
SHA256 e187da3de96fe63c5c0516b4304bb334728fbb394a6f6302bc99cba0c7eeaa33
SHA3 586e579b2c7512b1e8d290f8a5f8b187f6b61ff87cb3f61ff4d7a9b30d8eba9e
VirtualSize 0x5710c
VirtualAddress 0x1000
SizeOfRawData 0x57200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.57242

.rdata

MD5 e010928979d5eea2e43325b04ca017bd
SHA1 3723b46d23de6809d4d39e640931bdae4a4b5208
SHA256 82807985570149605c7d2d935ef03b9308006d612e81c205f28d22a0a80f50b0
SHA3 e879b375e61c76cac62d2e837d54357eb83466527463841375e09fb3c1f54459
VirtualSize 0x16134
VirtualAddress 0x59000
SizeOfRawData 0x16200
PointerToRawData 0x57600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.29099

.data

MD5 206560e037889e23b6280af98df136b8
SHA1 15097091cfa351c4806dbbce08a0f8148b5ab404
SHA256 bffe2b5c193e8302ae2bc3a611ea01532437d613a7e1244558ed5fb5435a3317
SHA3 0ddfc7381ead9736e68b1944764f550155de6f62af7d4cf10541449da6cfb7b4
VirtualSize 0x3bb4
VirtualAddress 0x70000
SizeOfRawData 0x2200
PointerToRawData 0x6d800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.67932

.pdata

MD5 a3fdbb26eea26b65103e01405db1d993
SHA1 f0158c4f8db6ab736240ac365685a20596599579
SHA256 08d1feb042d277c78b882412d03c699325f2355327793393f4601bee06b74fb2
SHA3 2fd6500445b26415f229f79f6cc98f7c4b192444bbc23f8272a74019ac799e74
VirtualSize 0x3a44
VirtualAddress 0x74000
SizeOfRawData 0x3c00
PointerToRawData 0x6fa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.65601

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x100
VirtualAddress 0x78000
SizeOfRawData 0x200
PointerToRawData 0x73600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 3f4cf7d643e727e2d63b88bebc0e9560
SHA1 14e8f41ce38782d863b941c063b08228dfbfea59
SHA256 b7abbce17a41a24762bcddd0951d773484aacdf21c65aaf985884ec81a46813c
SHA3 690b91d6cf1381a7c6004589b537ac9361d98d697b0766b4d116c2e383522822
VirtualSize 0x1e8
VirtualAddress 0x79000
SizeOfRawData 0x200
PointerToRawData 0x73800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.77204

.reloc

MD5 4692948d2f5095b0e54dac7abb57ef5f
SHA1 6b41178ae9afaf0518c1b47b67f9260d03528988
SHA256 5356bf07aced284770016357ad6a02a22945976d4be46520ba75e5e620e1ce25
SHA3 f2fcfd3206e08974b890eeabf7030b1806aab5dcfde45d8ecbaf705c7af644fe
VirtualSize 0xa0c
VirtualAddress 0x7a000
SizeOfRawData 0xc00
PointerToRawData 0x73a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.03379

Imports

KERNEL32.dll GetConsoleScreenBufferInfo
SetConsoleTextAttribute
GetStdHandle
Sleep
GetTickCount64
FillConsoleOutputCharacterW
FillConsoleOutputAttribute
GetCurrentProcessId
SetConsoleCursorPosition
QueryPerformanceCounter
WriteConsoleW
LocalFree
FormatMessageA
GetLocaleInfoEx
CreateFileW
FindClose
FindFirstFileW
FindFirstFileExW
FindNextFileW
GetFileAttributesExW
SetFileInformationByHandle
AreFileApisANSI
CloseHandle
GetLastError
GetModuleHandleW
GetProcAddress
GetFileInformationByHandleEx
MultiByteToWideChar
WideCharToMultiByte
GetCurrentThreadId
EncodePointer
DecodePointer
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
LCMapStringEx
GetSystemTimeAsFileTime
GetStringTypeW
GetCPInfo
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
InitializeSListHead
RtlUnwindEx
RtlPcToFileHeader
RaiseException
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
CreateThread
ExitThread
FreeLibraryAndExitThread
GetModuleHandleExW
GetConsoleCP
ExitProcess
GetModuleFileNameW
WriteFile
GetCommandLineA
GetCommandLineW
HeapAlloc
HeapFree
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
VirtualProtect
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetConsoleMode
SetConsoleMode
GetNumberOfConsoleInputEvents
ReadConsoleInputW
PeekConsoleInputA
ReadConsoleW
GetFileType
FlushFileBuffers
GetConsoleOutputCP
ReadFile
GetFileSizeEx
SetFilePointerEx
HeapReAlloc
IsValidCodePage
GetACP
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
GetProcessHeap
SetStdHandle
HeapSize
RtlUnwind

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Mar-28 14:40:34
Version 0.0
SizeofData 1032
AddressOfRawData 0x69230
PointerToRawData 0x67830

UNKNOWN

Characteristics 0
TimeDateStamp 2026-Mar-28 14:40:34
Version 0.0
SizeofData 4
AddressOfRawData 0x69660
PointerToRawData 0x67c60

TLS Callbacks

StartAddressOfRawData 0x140069688
EndAddressOfRawData 0x140069690
AddressOfIndex 0x140072f18
AddressOfCallbacks 0x140059478
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140070080

RICH Header

XOR Key 0xc86280f9
Unmarked objects 0
C++ objects (33145) 173
C objects (33145) 18
ASM objects (33145) 8
ASM objects (35207) 10
C objects (35207) 17
C++ objects (35207) 91
Imports (33145) 3
Total imports 160
C++ objects (LTCG) (35225) 5
Resource objects (35225) 1
Linker (35225) 1

Errors

Leave a comment

No comments yet.