| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Jul-22 20:04:51 |
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA256 Uses constants related to AES Uses constants related to Blowfish |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The PE is possibly a dropper. |
Resource 27 is possibly compressed or encrypted.
Resources amount for 98.8329% of the executable. |
| Malicious | VirusTotal score: 41/70 (Scanned on 2026-09-20 05:26:19) |
ALYac:
Gen:Variant.Application.Tedy.47351
APEX: Malicious AVG: Win64:Malware-gen AhnLab-V3: Malware/Win.Mikey.R762674 Alibaba: Packed:Win64/Nuitka.c1b8f13d Arcabit: Trojan.Application.Tedy.DB8F7 Avast: Win64:Malware-gen Avira: TR/W64.Malware BitDefender: Gen:Variant.Application.Tedy.47351 CTX: exe.trojan.tedy CrowdStrike: win/malicious_confidence_60% (W) Cylance: Unsafe Cynet: Malicious (score: 99) DeepInstinct: MALICIOUS ESET-NOD32: Python/Packed.Nuitka.AL suspicious application Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Application.Tedy.47351 (B) F-Secure: Trojan.TR/W64.Malware Fortinet: Riskware/Application GData: Gen:Variant.Application.Tedy.47351 Google: Detected Gridinsoft: Trojan.Win64.Packed.oa!s1 Ikarus: Trojan.Gensteal K7AntiVirus: Unwanted-Program ( 006d84911 ) K7GW: Unwanted-Program ( 006d84911 ) Lionic: Trojan.Win32.Generic.4!c Malwarebytes: Malware.AI.3693141856 MaxSecure: Trojan.Malware.300983.susgen McAfeeD: ti!0E1D635AA433 MicroWorld-eScan: Gen:Variant.Application.Tedy.47351 Microsoft: Trojan:Win32/Kepavll!rfn Paloalto: generic.ml SentinelOne: Static AI - Suspicious PE Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence TrellixENS: Artemis!B737CD4CAFBC TrendMicro: Trojan.Win64.WACATAC.USBLGQ26 TrendMicro-HouseCall: Trojan.Win64.WACATAC.USBLGQ26 VIPRE: Gen:Variant.Application.Tedy.47351 Varist: W64/ABApplication.EWYF-1053 Zillya: Trojan.Agent.Win32.4414007 |
| MD5 | b737cd4cafbcfbff95655b342a411e56 🔍 |
|---|---|
| SHA1 | 3d6d4098d996baefef902523e0fbf057edf97927 🔍 |
| SHA256 | 0e1d635aa4332d12cc5d4264c97cf99ba8ca9fd1013ab49e28ccdd0a3aa8ebdd 🔍 |
| SHA3 | 9a8c9552675e421a61d03bc32edb7fb80790bd8cc1a1150762d32c04d7f8896e 🔍 |
| SSDeep | 196608:9x+haUhgSqWHrt49R6/jvDE7gqdqFBMw+NRGmixkEfm:2aUVqWu9R6/jvohdqFBVSRGmnY 🔍 |
| Imports Hash | 214feaa67f2611f337c17bded7d257ac 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Jul-22 20:04:51 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xc600 |
| SizeOfInitializedData | 0x645000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000000C9DC (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x67d000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 7e9c34c0fa7ab3412dc8635b05f5a244 🔍 |
|---|---|
| SHA1 | 299bf25f47cd6a68e3dfe44f79a2a25d7e4d1358 🔍 |
| SHA256 | eef7d0e2a9d99a9c7a89e98ebe311c37d51d214a7eceea700e5063542579ddbb 🔍 |
| SHA3 | 4f6b1853e8cf094b7f22be80eee943cb48f0db983691a22cebff8c6175da0b40 🔍 |
| VirtualSize | 0xc49c |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0xc600 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.38826 |
| MD5 | e09d3d7cc2ca9f9065e98e8154602bbb 🔍 |
|---|---|
| SHA1 | c71e637d7ee8d6114fed28571104328373c76886 🔍 |
| SHA256 | 44ae6d78c09728a041038054e431101050b61801ea303eb1e775b6d12a07e9b7 🔍 |
| SHA3 | cf924fd7ef4b41f32bbc0830ea0f8550dd657361fa3540fc69e36938524d5696 🔍 |
| VirtualSize | 0x5596 |
| VirtualAddress | 0xe000 |
| SizeOfRawData | 0x5600 |
| PointerToRawData | 0xca00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.59499 |
| MD5 | 85c2aebd011c5c1b37c1009def59c2b6 🔍 |
|---|---|
| SHA1 | e6f88330c0bc7698e3f5d77202242a6e10f6e321 🔍 |
| SHA256 | ab4f194dcbbaf38d8dca700fa10eee22d80c5463d8256b36eb72ed5f7126ba69 🔍 |
| SHA3 | a5818bd143f172ebe95ef85b8e270e51e0d1ae2330fd892938463b36527155ea 🔍 |
| VirtualSize | 0x27718 |
| VirtualAddress | 0x14000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x12000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0.53249 |
| MD5 | 9023cb890056d37ac83dc417db8424f3 🔍 |
|---|---|
| SHA1 | 50f0de0e991648267fb79700ef24566c62a39531 🔍 |
| SHA256 | bad48c7df9877001295657436b3b42b6b52b7c9b894a2a2589249db17340ebbc 🔍 |
| SHA3 | 08838764c064983dfbf18eaa6dfe2cd600d6d0fbb7ac45cae0e7bfdd0a453f54 🔍 |
| VirtualSize | 0x708 |
| VirtualAddress | 0x3c000 |
| SizeOfRawData | 0x800 |
| PointerToRawData | 0x12200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.35065 |
| MD5 | df20c4f4d21528938db88270a18b2722 🔍 |
|---|---|
| SHA1 | 867a358cbff992e6c215d5c3babceec6b76cc0d9 🔍 |
| SHA256 | aae6299b2dd941e69520d6a21f7329730c5d317f3ef227bb5615c82d12c33300 🔍 |
| SHA3 | a612f3d225f603b75b1170062f187fcdd344f49a98e013f5944950cede113f43 🔍 |
| VirtualSize | 0x63ec8c |
| VirtualAddress | 0x3d000 |
| SizeOfRawData | 0x63ee00 |
| PointerToRawData | 0x12a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 7.99923 |
| MD5 | 4e46d31f380fd344cd961b0d8e5ff4ae 🔍 |
|---|---|
| SHA1 | f9d443bd137ac4c18ea181d36ac7de740801141e 🔍 |
| SHA256 | cf617826cc0587c1558b084329303a913cf684289e421073bccc72c852181adf 🔍 |
| SHA3 | ede1fafaf0c844797cda631dd95874e6ba10867555bcb0694450b6bdada31476 🔍 |
| VirtualSize | 0x3c |
| VirtualAddress | 0x67c000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x651800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 0.770308 |
| SHELL32.dll |
SHFileOperationW
SHGetFolderPathW CommandLineToArgvW |
|---|---|
| KERNEL32.dll |
LockResource
GetModuleHandleW IsDebuggerPresent CreateDirectoryW SizeofResource SetConsoleCtrlHandler AddDllDirectory GetCommandLineW GetStdHandle WriteFile GetShortPathNameW TerminateProcess GetModuleFileNameW SetEnvironmentVariableW K32GetModuleFileNameExW GetEnvironmentVariableW GetTempPathW FindResourceA WaitForSingleObject CreateFileW GetFileAttributesW GetModuleHandleA OpenProcess Sleep GetLastError GetCurrentThreadId CloseHandle LoadResource GetProcAddress GetCurrentProcessId CreateProcessW GetSystemTimeAsFileTime FormatMessageA LoadLibraryExW GetExitCodeProcess RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess IsProcessorFeaturePresent QueryPerformanceCounter InitializeSListHead |
| VCRUNTIME140.dll |
wcschr
__C_specific_handler __current_exception __current_exception_context memset memcpy memmove |
| api-ms-win-crt-runtime-l1-1-0.dll |
terminate
abort _seh_filter_exe _set_app_type __p___wargv _errno _initialize_wide_environment _get_initial_wide_environment _initterm _initterm_e _exit exit __p___argc _cexit _c_exit _register_thread_local_exe_atexit_callback _configure_wide_argv _crt_atexit _initialize_onexit_table _register_onexit_function |
| api-ms-win-crt-heap-l1-1-0.dll |
free
malloc _set_new_mode |
| api-ms-win-crt-convert-l1-1-0.dll |
mbstowcs
wcstoul |
| api-ms-win-crt-stdio-l1-1-0.dll |
puts
__stdio_common_vsprintf __stdio_common_vfprintf _set_fmode __acrt_iob_func __p__commode __stdio_common_vswprintf |
| api-ms-win-crt-string-l1-1-0.dll |
_wcsdup
iswctype wcsncmp _wcsicmp |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Type |
RT_RCDATA
|
|---|---|
| Language | UNKNOWN |
| Codepage | Latin 1 / Western European |
| Size | 0x63e6f0 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 7.99923 |
| MD5 | 6b904fbc23f87453b4082e2e8f44fa99 🔍 |
| SHA1 | d06272ecfd4d77d6bef0499a9f7984f65bb58186 🔍 |
| SHA256 | 4ccc311e5b1a0ebd0b8a8f33169b084e3ce2e758c7e3db72b3c84de678efbfbf 🔍 |
| SHA3 | 58e0ef924586b699ce3b0fd55148a564491b47a842da5416b40c28beb1522edf 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | UNKNOWN |
| Codepage | Latin 1 / Western European |
| Size | 0x4fc |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.27037 |
| MD5 | 4ca7ed0b93a26e63b06e883828f8dc35 🔍 |
| SHA1 | 0d31369d919517f6fcafb97dc92c2539b6ccb4ba 🔍 |
| SHA256 | 4a6a1dce6b90dcdec54f805a36e6834624b5e33691d5a9c33c1d243c6e5efdc4 🔍 |
| SHA3 | c2f10f57c37bd3f42aae14a0a0a01f9ac16d4d8819c0d8173d3cd098ac49a1ed 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-22 20:04:51 |
| Version | 0.0 |
| SizeofData | 604 |
| AddressOfRawData | 0x11dec |
| PointerToRawData | 0x107ec |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140014000 |
| XOR Key | 0x9b319320 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 16 |
| Imports (35207) | 2 |
| 253 (35207) | 2 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 19 |
| Imports (33145) | 5 |
| Total imports | 114 |
| C objects (LTCG) (35228) | 1 |
| Linker (35228) | 1 |
No comments yet.