1e237d7ada051761217ea05cd090521dc3fbd127c8c8970e9a1dec2dfb689817

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-20 13:55:25
Detected languages English - United States

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentControlSet\Services
Contains domain names:
  • curl.haxx.se
  • example.com
  • exljbris.com
  • github.com
  • http://www.exljbris.com
  • https://curl.haxx.se
  • https://curl.haxx.se/docs/http-cookies.html
  • https://github.com
  • www.exljbris.com
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Code injection capabilities:
  • WriteProcessMemory
  • OpenProcess
  • VirtualAllocEx
  • CreateRemoteThread
Can access the registry:
  • RegOpenKeyExA
  • RegQueryValueExA
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessA
  • ShellExecuteW
  • system
Uses Windows's Native API:
  • ntohs
  • ntohl
Uses Microsoft's cryptographic API:
  • CryptReleaseContext
  • CryptGetHashParam
  • CryptDestroyHash
  • CryptHashData
  • CryptCreateHash
  • CryptAcquireContextA
  • CryptEncrypt
  • CryptImportKey
  • CryptDestroyKey
  • CryptGenRandom
Leverages the raw socket API to access the Internet:
  • getsockname
  • WSASetLastError
  • getsockopt
  • closesocket
  • __WSAFDIsSet
  • htons
  • ntohs
  • setsockopt
  • WSAIoctl
  • bind
  • freeaddrinfo
  • send
  • accept
  • listen
  • recvfrom
  • sendto
  • ioctlsocket
  • gethostname
  • htonl
  • ntohl
  • select
  • recv
  • getaddrinfo
  • socket
  • connect
  • getpeername
  • WSAGetLastError
  • WSACleanup
  • WSAStartup
Interacts with services:
  • OpenServiceA
  • QueryServiceStatusEx
  • OpenSCManagerA
Manipulates other processes:
  • Process32First
  • WriteProcessMemory
  • OpenProcess
  • Process32Next
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 16/69 (Scanned on 2026-07-22 04:29:05) APEX: Malicious
CTX: exe.trojan.generic
CrowdStrike: win/malicious_confidence_70% (W)
Cylance: Unsafe
ESET-NOD32: Win32/GameHack_AGen.APZ potentially unsafe application
Elastic: malicious (high confidence)
Google: Detected
Malwarebytes: Malware.AI.4027825286
McAfeeD: Real Protect-LS!71F48003C053
Microsoft: Trojan:Win32/Kepavll!rfn
Paloalto: generic.ml
Sophos: Generic Reputation PUA (PUA)
Symantec: ML.Attribute.HighConfidence
Trapmine: malicious.high.ml.score
TrendMicro-HouseCall: Trojan.Win32.VSX.PE04CA5
Varist: W32/ABApplication.VRXR-7202

Hashes

MD5 71f48003c053ce1d7c7491315b37def7
SHA1 10c1556cc9ceba8e384a3a5d4392536924949c55
SHA256 1e237d7ada051761217ea05cd090521dc3fbd127c8c8970e9a1dec2dfb689817
SHA3 77253004ac4d9f36e2340ed2838972b9760ab0521c99d7d6f1b4f51ef40ba393
SSDeep 24576:jblVqEcoRHN/Rl5aRUDSWSBg0U3G+im3N3kIJ:j5VhRt/YLWSDXm3hZJ
Imports Hash 76c1234fc3f0dba908321bc920d1e362

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x120

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2026-Jul-20 13:55:25
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x90200
SizeOfInitializedData 0x39000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0008EFFA (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x92000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xcd000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e93a1a26491c57138b2a23974dbd8980
SHA1 477bcbbc855c433431d237f44d94a01d3429a1ad
SHA256 a11faf16885883b2616aad58ccb4e18326a2360129a3b881da7616a893f4000a
SHA3 03ee20e7d9a95af7c300052ace93d71c38d6ceaed1a056ad2f42de706e746fcb
VirtualSize 0x901e2
VirtualAddress 0x1000
SizeOfRawData 0x90200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.53781

.rdata

MD5 dece3c2f210205d70467bd63742a58ca
SHA1 3380e395bfcaf289f0dd661e2c5c283ffba285ec
SHA256 31c2bbbd832258d905caf2d63861f46f275b75db740760f5291ee84bc04fad02
SHA3 bd7c151d3db56e2809ba6b54901c64614d4a1bdf25c69dd251b7fc9676c3956c
VirtualSize 0x295be
VirtualAddress 0x92000
SizeOfRawData 0x29600
PointerToRawData 0x90600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.90414

.data

MD5 6a7de6a3a47a8076cc884da606e53f85
SHA1 787c725e35a5057ede7fecbc2ca5def42b0c69d3
SHA256 77702807deb27f18fb4012e8dd784531998c90f9c6bdfb7c505bff16ff702c40
SHA3 7abdd142e82064e433781f4f3f6b902d668de78d290336b414eea72a8a485621
VirtualSize 0x8c4
VirtualAddress 0xbc000
SizeOfRawData 0x200
PointerToRawData 0xb9c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.83808

.rsrc

MD5 af2f9efd2e96aa7a8125f28cdc885961
SHA1 81bf0bc4dbf03140fc67d9c4ea7798b9731df0e9
SHA256 3b338152e4ef2ce8b2e44d264a401aed8ec59de06133a7b2f073eb0fe66852af
SHA3 32460c3187b83853e02d103ad4a0a46154a8d029700b946740c99c2b0eaf3534
VirtualSize 0x9d48
VirtualAddress 0xbd000
SizeOfRawData 0x9e00
PointerToRawData 0xb9e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.9682

.reloc

MD5 91ed7ce8c250ea525491a21c2302c76c
SHA1 d5ec5f3f76d1fc8ce64562626d964611e9d97a4f
SHA256 98a3689c7a3d8519151374334035d3261863b1a0da86b5d0de562c0ba5a91e79
SHA3 b98783fe869f7353259545311c20c54998aea9007cbab3ac03e186179996356d
VirtualSize 0x5168
VirtualAddress 0xc7000
SizeOfRawData 0x5200
PointerToRawData 0xc3c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.72275

Imports

ADVAPI32.dll CryptReleaseContext
OpenServiceA
QueryServiceStatusEx
CryptGetHashParam
RegOpenKeyExA
CryptDestroyHash
CryptHashData
CryptCreateHash
OpenSCManagerA
RegQueryValueExA
CloseServiceHandle
RegCloseKey
CryptAcquireContextA
CryptEncrypt
CryptImportKey
CryptDestroyKey
CryptGenRandom
WS2_32.dll getsockname
WSASetLastError
getsockopt
closesocket
__WSAFDIsSet
htons
ntohs
setsockopt
WSAIoctl
bind
freeaddrinfo
send
accept
listen
recvfrom
sendto
ioctlsocket
gethostname
htonl
ntohl
select
recv
getaddrinfo
socket
connect
getpeername
WSAGetLastError
WSACleanup
WSAStartup
CRYPT32.dll CertFreeCertificateContext
WLDAP32.dll #50
#60
#211
#46
#143
#301
#200
#30
#79
#35
#41
#33
#32
#27
#26
#22
Normaliz.dll IdnToAscii
d3d9.dll Direct3DCreate9
KERNEL32.dll IsProcessorFeaturePresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
ExpandEnvironmentStringsA
IsDebuggerPresent
AcquireSRWLockExclusive
ReadFile
GetStartupInfoW
GetModuleHandleW
GetFileType
GetStdHandle
WaitForSingleObjectEx
FormatMessageA
VerifyVersionInfoA
GetSystemDirectoryA
SleepEx
DeleteCriticalSection
ReleaseSRWLockExclusive
WakeAllConditionVariable
PeekNamedPipe
SleepConditionVariableSRW
InitializeCriticalSectionEx
LeaveCriticalSection
EnterCriticalSection
SetLastError
GetLastError
GetTickCount64
QueryPerformanceCounter
FreeLibrary
VerSetConditionMask
IsDBCSLeadByte
QueryPerformanceFrequency
GetCurrentProcessId
GetCurrentThreadId
InitializeSListHead
LoadLibraryA
WaitForMultipleObjects
OutputDebugStringA
GetLocaleInfoA
GlobalUnlock
WideCharToMultiByte
GlobalLock
GlobalFree
GetSystemFirmwareTable
GetModuleFileNameA
Process32First
GetFileAttributesExA
WriteProcessMemory
GetCurrentProcess
TerminateProcess
GetEnvironmentVariableA
WaitForSingleObject
GetModuleHandleA
OpenProcess
CreateToolhelp32Snapshot
MultiByteToWideChar
GetExitCodeThread
Sleep
GetTempPathA
DeleteFileA
Process32Next
CloseHandle
GetProcAddress
VirtualAllocEx
CreateRemoteThread
CreateProcessA
GetSystemTimeAsFileTime
CreateDirectoryA
VirtualFreeEx
GetTickCount
GlobalAlloc
USER32.dll GetKeyState
GetMessageExtraInfo
TrackMouseEvent
ClientToScreen
GetCapture
GetKeyboardLayout
GetForegroundWindow
SetCursor
SetProcessDPIAware
GetDC
IsWindowUnicode
LoadCursorA
ReleaseCapture
SetCapture
UpdateWindow
PostQuitMessage
PeekMessageA
GetClientRect
LoadIconA
TranslateMessage
SetLayeredWindowAttributes
MessageBoxA
ShowWindow
GetActiveWindow
RegisterClassExW
UnregisterClassW
GetSystemMetrics
ScreenToClient
CreateWindowExW
PostMessageA
SetWindowPos
DestroyWindow
GetWindowRect
DispatchMessageA
MonitorFromPoint
DefWindowProcW
SetClipboardData
GetClipboardData
EmptyClipboard
CloseClipboard
OpenClipboard
GetCursorPos
ReleaseDC
SetCursorPos
GDI32.dll GetDeviceCaps
SHELL32.dll ShellExecuteW
MSVCP140.dll _Mtx_unlock
_Thrd_join
_Thrd_detach
_Thrd_id
_Cnd_do_broadcast_at_thread_exit
_Mtx_lock
?_Xlength_error@std@@YAXPBD@Z
?_Xout_of_range@std@@YAXPBD@Z
?_Throw_Cpp_error@std@@YAXH@Z
IMM32.dll ImmSetCompositionWindow
ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow
VCRUNTIME140.dll _except_handler4_common
__current_exception_context
__current_exception
_CxxThrowException
memchr
strstr
memmove
memcpy
memset
strrchr
__std_terminate
_set_se_translator
__std_exception_copy
strchr
__std_exception_destroy
__CxxFrameHandler3
api-ms-win-crt-stdio-l1-1-0.dll __stdio_common_vfprintf
fwrite
ferror
feof
__stdio_common_vsprintf
__stdio_common_vfscanf
_lseeki64
fputc
fread
__acrt_iob_func
fflush
_set_fmode
_wfopen
__stdio_common_vsscanf
fclose
fgets
__p__commode
fopen
fputs
ftell
_read
_write
_close
_open
fseek
api-ms-win-crt-runtime-l1-1-0.dll _controlfp_s
_invoke_watson
_register_thread_local_exe_atexit_callback
_c_exit
_exit
exit
_initterm_e
_initterm
strerror
__sys_nerr
_getpid
_get_narrow_winmain_command_line
_beginthreadex
_set_app_type
_seh_filter_exe
_cexit
_errno
terminate
system
_crt_atexit
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
api-ms-win-crt-string-l1-1-0.dll tolower
_strdup
wcscat_s
isgraph
_stricmp
isprint
islower
isupper
isalnum
strncpy
isspace
isdigit
strpbrk
isxdigit
isalpha
strncmp
api-ms-win-crt-convert-l1-1-0.dll atol
strtoll
strtoul
strtol
atoi
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-heap-l1-1-0.dll realloc
_callnewh
free
calloc
_set_new_mode
malloc
api-ms-win-crt-time-l1-1-0.dll _gmtime64
_time64
api-ms-win-crt-filesystem-l1-1-0.dll _stat64
_fstat64
api-ms-win-crt-environment-l1-1-0.dll getenv
api-ms-win-crt-math-l1-1-0.dll ceil
_libm_sse2_cos_precise
_libm_sse2_sin_precise
_CIfmod
__setusermatherr
_libm_sse2_sqrt_precise
_libm_sse2_acos_precise
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x320
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.72359
Detected Filetype PNG graphic file
MD5 4b5022652f957389424e5624dd6cac50
SHA1 7cf74dc8435e565713c679eb3cac83bb116bba64
SHA256 0198f83a400532a8bbc4177ba90245fcaad6868662b9e05ff65a3dc975832807
SHA3 c3c91bdfd12325ea15b4bd648e1e9a46bc28617161cc363da2623e8b001e16c6

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x934
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.89008
Detected Filetype PNG graphic file
MD5 766efd66bf84d93158c59aed0f3685fd
SHA1 889be05e602f871ac3a91c9fdba2771c03ebeade
SHA256 5a12ab812ba97c4b3f60f6ea2fd85e32b896db3b9ff7b8be8c55dcc6566852de
SHA3 591526860f2cb24d5eab21f2207876b9bc44688e8c02c69eeb2bb634af0c4ffd

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1201
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.94977
Detected Filetype PNG graphic file
MD5 e50fbaf75fd4b4375df15a5c63998b9b
SHA1 5e0b6def4fe10b9a8a35321316c94dab6a0d176b
SHA256 d9e959c5017b81df91302ee57143cf0b883de42708f9d0e948d9eb89be0b35a5
SHA3 8efacee01633b4b0ebfd86757a58089fa7939d0a31a8c17301b872348cfbfae7

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1d55
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.96583
Detected Filetype PNG graphic file
MD5 2e9d49e4ce1b04352f6938cb6d24b9a3
SHA1 ed64def610f9cbbcd9f2ac8f35ca3af95ece0dab
SHA256 481303b1c990b39afac1e5024d7ed22102321cb3d80cd9e1d5e45b0adfc06a54
SHA3 756226fe93cf41495b0b7b74efe3c15df7147d297c3cabeffafbfbef62b29f80

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5e02
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.98897
Detected Filetype PNG graphic file
MD5 1d2d56d43e3f1378c69d3fa949e4c0ed
SHA1 68260b6f71141b542c483cdb2ba2be6768f75a8e
SHA256 d5de167ae4510e1768877cb34536407fc0991834e46b9e796a37eeb1c1714ba2
SHA3 e83e23d8c2686abb74b6030189f68ae07b4a34034ead4b8a45595855069501ad

101

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.71989
Detected Filetype Icon file
MD5 145f8fc6000ecd97bb09f6de6bb7e2e8
SHA1 3c13fd426b76929b503182971936f00ad1ac1922
SHA256 f34b1ebd94215a645be9fb9d8c05e583ea73ecb32772e12946add2e773f1639a
SHA3 87a17e62b9d4553c2d91314535352a97e400a6ec6be4be621fa2d66442d41f6c

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-20 13:55:25
Version 0.0
SizeofData 864
AddressOfRawData 0xb8a68
PointerToRawData 0xb7068

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jul-20 13:55:25
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x4b8dd8
EndAddressOfRawData 0x4b8de0
AddressOfIndex 0x4bc6c8
AddressOfCallbacks 0x492564
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0xc0
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x4bc080
SEHandlerTable 0x4b8944
SEHandlerCount 44

RICH Header

XOR Key 0x1fbcdbb1
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 22
253 (35207) 5
ASM objects (35207) 9
C objects (35207) 12
C++ objects (35207) 30
Imports (35207) 4
Imports (33145) 14
Total imports 315
Imports (VS2015 v14.0.? compiler 24610) 11
C objects (VS2017 v15.2 compiler 25019) 93
C++ objects (LTCG) (35228) 7
Resource objects (35228) 1
151 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.