0e1d635aa4332d12cc5d4264c97cf99ba8ca9fd1013ab49e28ccdd0a3aa8ebdd

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Jul-22 20:04:51

Plugin Output

Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA256
Uses constants related to AES
Uses constants related to Blowfish
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Manipulates other processes:
  • OpenProcess
Suspicious The PE is possibly a dropper. Resource 27 is possibly compressed or encrypted.
Resources amount for 98.8329% of the executable.
Malicious VirusTotal score: 41/70 (Scanned on 2026-09-20 05:26:19) ALYac: Gen:Variant.Application.Tedy.47351
APEX: Malicious
AVG: Win64:Malware-gen
AhnLab-V3: Malware/Win.Mikey.R762674
Alibaba: Packed:Win64/Nuitka.c1b8f13d
Arcabit: Trojan.Application.Tedy.DB8F7
Avast: Win64:Malware-gen
Avira: TR/W64.Malware
BitDefender: Gen:Variant.Application.Tedy.47351
CTX: exe.trojan.tedy
CrowdStrike: win/malicious_confidence_60% (W)
Cylance: Unsafe
Cynet: Malicious (score: 99)
DeepInstinct: MALICIOUS
ESET-NOD32: Python/Packed.Nuitka.AL suspicious application
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Application.Tedy.47351 (B)
F-Secure: Trojan.TR/W64.Malware
Fortinet: Riskware/Application
GData: Gen:Variant.Application.Tedy.47351
Google: Detected
Gridinsoft: Trojan.Win64.Packed.oa!s1
Ikarus: Trojan.Gensteal
K7AntiVirus: Unwanted-Program ( 006d84911 )
K7GW: Unwanted-Program ( 006d84911 )
Lionic: Trojan.Win32.Generic.4!c
Malwarebytes: Malware.AI.3693141856
MaxSecure: Trojan.Malware.300983.susgen
McAfeeD: ti!0E1D635AA433
MicroWorld-eScan: Gen:Variant.Application.Tedy.47351
Microsoft: Trojan:Win32/Kepavll!rfn
Paloalto: generic.ml
SentinelOne: Static AI - Suspicious PE
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
TrellixENS: Artemis!B737CD4CAFBC
TrendMicro: Trojan.Win64.WACATAC.USBLGQ26
TrendMicro-HouseCall: Trojan.Win64.WACATAC.USBLGQ26
VIPRE: Gen:Variant.Application.Tedy.47351
Varist: W64/ABApplication.EWYF-1053
Zillya: Trojan.Agent.Win32.4414007

Hashes

MD5 b737cd4cafbcfbff95655b342a411e56 🔍
SHA1 3d6d4098d996baefef902523e0fbf057edf97927 🔍
SHA256 0e1d635aa4332d12cc5d4264c97cf99ba8ca9fd1013ab49e28ccdd0a3aa8ebdd 🔍
SHA3 9a8c9552675e421a61d03bc32edb7fb80790bd8cc1a1150762d32c04d7f8896e 🔍
SSDeep 196608:9x+haUhgSqWHrt49R6/jvDE7gqdqFBMw+NRGmixkEfm:2aUVqWu9R6/jvohdqFBVSRGmnY 🔍
Imports Hash 214feaa67f2611f337c17bded7d257ac 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jul-22 20:04:51
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xc600
SizeOfInitializedData 0x645000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000000C9DC (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x67d000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 7e9c34c0fa7ab3412dc8635b05f5a244 🔍
SHA1 299bf25f47cd6a68e3dfe44f79a2a25d7e4d1358 🔍
SHA256 eef7d0e2a9d99a9c7a89e98ebe311c37d51d214a7eceea700e5063542579ddbb 🔍
SHA3 4f6b1853e8cf094b7f22be80eee943cb48f0db983691a22cebff8c6175da0b40 🔍
VirtualSize 0xc49c
VirtualAddress 0x1000
SizeOfRawData 0xc600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.38826

.rdata

MD5 e09d3d7cc2ca9f9065e98e8154602bbb 🔍
SHA1 c71e637d7ee8d6114fed28571104328373c76886 🔍
SHA256 44ae6d78c09728a041038054e431101050b61801ea303eb1e775b6d12a07e9b7 🔍
SHA3 cf924fd7ef4b41f32bbc0830ea0f8550dd657361fa3540fc69e36938524d5696 🔍
VirtualSize 0x5596
VirtualAddress 0xe000
SizeOfRawData 0x5600
PointerToRawData 0xca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.59499

.data

MD5 85c2aebd011c5c1b37c1009def59c2b6 🔍
SHA1 e6f88330c0bc7698e3f5d77202242a6e10f6e321 🔍
SHA256 ab4f194dcbbaf38d8dca700fa10eee22d80c5463d8256b36eb72ed5f7126ba69 🔍
SHA3 a5818bd143f172ebe95ef85b8e270e51e0d1ae2330fd892938463b36527155ea 🔍
VirtualSize 0x27718
VirtualAddress 0x14000
SizeOfRawData 0x200
PointerToRawData 0x12000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.53249

.pdata

MD5 9023cb890056d37ac83dc417db8424f3 🔍
SHA1 50f0de0e991648267fb79700ef24566c62a39531 🔍
SHA256 bad48c7df9877001295657436b3b42b6b52b7c9b894a2a2589249db17340ebbc 🔍
SHA3 08838764c064983dfbf18eaa6dfe2cd600d6d0fbb7ac45cae0e7bfdd0a453f54 🔍
VirtualSize 0x708
VirtualAddress 0x3c000
SizeOfRawData 0x800
PointerToRawData 0x12200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.35065

.rsrc

MD5 df20c4f4d21528938db88270a18b2722 🔍
SHA1 867a358cbff992e6c215d5c3babceec6b76cc0d9 🔍
SHA256 aae6299b2dd941e69520d6a21f7329730c5d317f3ef227bb5615c82d12c33300 🔍
SHA3 a612f3d225f603b75b1170062f187fcdd344f49a98e013f5944950cede113f43 🔍
VirtualSize 0x63ec8c
VirtualAddress 0x3d000
SizeOfRawData 0x63ee00
PointerToRawData 0x12a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.99923

.reloc

MD5 4e46d31f380fd344cd961b0d8e5ff4ae 🔍
SHA1 f9d443bd137ac4c18ea181d36ac7de740801141e 🔍
SHA256 cf617826cc0587c1558b084329303a913cf684289e421073bccc72c852181adf 🔍
SHA3 ede1fafaf0c844797cda631dd95874e6ba10867555bcb0694450b6bdada31476 🔍
VirtualSize 0x3c
VirtualAddress 0x67c000
SizeOfRawData 0x200
PointerToRawData 0x651800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.770308

Imports

SHELL32.dll SHFileOperationW
SHGetFolderPathW
CommandLineToArgvW
KERNEL32.dll LockResource
GetModuleHandleW
IsDebuggerPresent
CreateDirectoryW
SizeofResource
SetConsoleCtrlHandler
AddDllDirectory
GetCommandLineW
GetStdHandle
WriteFile
GetShortPathNameW
TerminateProcess
GetModuleFileNameW
SetEnvironmentVariableW
K32GetModuleFileNameExW
GetEnvironmentVariableW
GetTempPathW
FindResourceA
WaitForSingleObject
CreateFileW
GetFileAttributesW
GetModuleHandleA
OpenProcess
Sleep
GetLastError
GetCurrentThreadId
CloseHandle
LoadResource
GetProcAddress
GetCurrentProcessId
CreateProcessW
GetSystemTimeAsFileTime
FormatMessageA
LoadLibraryExW
GetExitCodeProcess
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
InitializeSListHead
VCRUNTIME140.dll wcschr
__C_specific_handler
__current_exception
__current_exception_context
memset
memcpy
memmove
api-ms-win-crt-runtime-l1-1-0.dll terminate
abort
_seh_filter_exe
_set_app_type
__p___wargv
_errno
_initialize_wide_environment
_get_initial_wide_environment
_initterm
_initterm_e
_exit
exit
__p___argc
_cexit
_c_exit
_register_thread_local_exe_atexit_callback
_configure_wide_argv
_crt_atexit
_initialize_onexit_table
_register_onexit_function
api-ms-win-crt-heap-l1-1-0.dll free
malloc
_set_new_mode
api-ms-win-crt-convert-l1-1-0.dll mbstowcs
wcstoul
api-ms-win-crt-stdio-l1-1-0.dll puts
__stdio_common_vsprintf
__stdio_common_vfprintf
_set_fmode
__acrt_iob_func
__p__commode
__stdio_common_vswprintf
api-ms-win-crt-string-l1-1-0.dll _wcsdup
iswctype
wcsncmp
_wcsicmp
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

27

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x63e6f0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99923
MD5 6b904fbc23f87453b4082e2e8f44fa99 🔍
SHA1 d06272ecfd4d77d6bef0499a9f7984f65bb58186 🔍
SHA256 4ccc311e5b1a0ebd0b8a8f33169b084e3ce2e758c7e3db72b3c84de678efbfbf 🔍
SHA3 58e0ef924586b699ce3b0fd55148a564491b47a842da5416b40c28beb1522edf 🔍

1

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4fc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.27037
MD5 4ca7ed0b93a26e63b06e883828f8dc35 🔍
SHA1 0d31369d919517f6fcafb97dc92c2539b6ccb4ba 🔍
SHA256 4a6a1dce6b90dcdec54f805a36e6834624b5e33691d5a9c33c1d243c6e5efdc4 🔍
SHA3 c2f10f57c37bd3f42aae14a0a0a01f9ac16d4d8819c0d8173d3cd098ac49a1ed 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-22 20:04:51
Version 0.0
SizeofData 604
AddressOfRawData 0x11dec
PointerToRawData 0x107ec

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140014000

RICH Header

XOR Key 0x9b319320
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 16
Imports (35207) 2
253 (35207) 2
ASM objects (35207) 4
C objects (35207) 10
C++ objects (35207) 19
Imports (33145) 5
Total imports 114
C objects (LTCG) (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.