2e826510ef092f222f55250da6914b2ee7f43515261a21fb2d8bdd91e3989c52

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Feb-25 16:11:55

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious PEiD Signature: UPolyX V0.1 -> Delikon
Info Interesting strings found in the binary: Contains domain names:
  • Alarm.com
  • Amazon.com
  • AntTail.com
  • e-moola.com
  • github.com
  • google.com
  • https://github.com
  • https://nappgui.com
  • inkscape.org
  • moola.com
  • nappgui.com
  • vtracksystems.com
  • www.google.com
  • www.inkscape.org
  • www.vtracksystems.com
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryW
  • GetProcAddress
Uses functions commonly found in keyloggers:
  • MapVirtualKeyW
  • GetAsyncKeyState
Leverages the raw socket API to access the Internet:
  • recv
  • send
  • shutdown
  • WSAStartup
  • WSACleanup
  • WSAGetLastError
  • closesocket
Can take screenshots:
  • GetDC
  • CreateCompatibleDC
  • BitBlt
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 d3708db30ca1784cf72d6df6f03a497d
SHA1 a0072b0cca54a4a9e373f5b8777c8f49c4b0cb5d
SHA256 2e826510ef092f222f55250da6914b2ee7f43515261a21fb2d8bdd91e3989c52
SHA3 a3b53f01902d282c7364cae75d3e2ef69bef7ec22613a7ad2559c38154302df6
SSDeep 24576:w9ZkAWPx8yCBFsUHaf61Gs0+FJtMQCHdx/aa:WcIRGs0+FJtMdX/a
Imports Hash b8cd696c3d3f54645443230aa076f109

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x40

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2024-Feb-25 16:11:55
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x92c00
SizeOfInitializedData 0x82c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000060C48 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x11d000
SizeOfHeaders 0x400
Checksum 0x1199d0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 9e9c4a2564f65e087663f766e330811a
SHA1 815c10de144d0d33f0c0a5cbf2470cf6f8b9ab51
SHA256 50591778df4323a83a463e82db36be9609a8762950ad2d65bcb31e85548c85a5
SHA3 bb4fa334f05281bb0f81cc380f9eb7389627ed28417a652488012ad492c9d7ac
VirtualSize 0x93000
VirtualAddress 0x1000
SizeOfRawData 0x92c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.42715

.rdata

MD5 8dafce3667b84ed84b0f49869954910a
SHA1 a153d7e4adf83383c710769635c45d576091b184
SHA256 c1921ec546dc97d7a4b014f5fca58e1a2fa151a725575eff76f83ba21f381870
SHA3 7697f08864a7698fdb1989f584ba2dc131620fe8220fcc05c6b464926fa9a81c
VirtualSize 0x6e000
VirtualAddress 0x94000
SizeOfRawData 0x6d400
PointerToRawData 0x93000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.52094

.data

MD5 95628d309492cf0b83660f883a443f58
SHA1 4667b7e318f64777efe59bac617b49eab6536752
SHA256 a6970cdd3dde447fa0d6c8a51fcce53adc3fb24c699ad167a9544d5b226d2b93
SHA3 cf5746f3d57532ffd0f5339827547655808c4d2db0106016df116493c23ab531
VirtualSize 0xb000
VirtualAddress 0x102000
SizeOfRawData 0x8800
PointerToRawData 0x100400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.9294

.pdata

MD5 da4edbd0f79dee37bd2b260e4162a85d
SHA1 dbb70fcf4d7d1e04726ae47b295771a7fa3f88b3
SHA256 51c3faa6d54e0622b6888ea9400f83c1114cb9fdeeff1a45b812072d5554f34d
SHA3 95e9a36bcdd75d842962a78426ff185ae0f44bb1aeaf5b8e17f6a9fdd6bde75b
VirtualSize 0x9000
VirtualAddress 0x10d000
SizeOfRawData 0x8800
PointerToRawData 0x108c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.8393

_RDATA

MD5 d707bd5e604df0fc263f61b41eab30e8
SHA1 4097552dd7791423eeeab44944ba04c1fd7fb5f0
SHA256 f95a08de2a84dda5eec73d4cd07e0885ba8e5d6fcc76d41caf49d99748704ea5
SHA3 a19586a127ef7f2af075f37d3ad5d068aa8679bdb91a2b8d67ba566f5ffc7a93
VirtualSize 0x1000
VirtualAddress 0x116000
SizeOfRawData 0x200
PointerToRawData 0x111400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.19553

.rsrc

MD5 88cfc7058e0194ac083ad668a95d9300
SHA1 cca75c49f083ccfa516145167d2a5bb8b2e615bd
SHA256 d98a97a50925a1301cb5b432611e094c07dce460bb20d7743744b3ce2de67a8e
SHA3 157d322bafa94f46028b4df1e9ea837b30a0a74322f77e445ad2ac500b4cef01
VirtualSize 0x1000
VirtualAddress 0x117000
SizeOfRawData 0x400
PointerToRawData 0x111600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.25646

.reloc

MD5 fb1e5c0fb28e0db805355e611119665d
SHA1 e3aee2a22cced8d2ceaaad57c66be8144143b621
SHA256 3f2b72225214967301418ed1df66858d4c34ec22480c42f0134866331154a220
SHA3 61e2d3bb10e1f991b31f3d2c2b84db1c6748e6965ae4f834010af39893f46854
VirtualSize 0x5000
VirtualAddress 0x118000
SizeOfRawData 0x4200
PointerToRawData 0x111a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.38837

Imports

KERNEL32.dll TerminateProcess
VerSetConditionMask
VerifyVersionInfoW
GetStdHandle
IsDebuggerPresent
DebugBreak
OutputDebugStringW
WriteConsoleW
GetCurrentThreadId
CreateThread
Sleep
GetLocalTime
SetEvent
CreateEventW
FormatMessageW
GetProcessHeap
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineA
GetOEMCP
GetACP
IsValidCodePage
FindFirstFileExW
GetSystemTimeAsFileTime
SetFilePointerEx
GetConsoleMode
GetConsoleOutputCP
FlushFileBuffers
EnumSystemLocalesW
GetUserDefaultLCID
IsValidLocale
GetLocaleInfoW
LCMapStringW
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
HeapQueryInformation
HeapSize
HeapReAlloc
HeapAlloc
HeapFree
SetStdHandle
GetModuleHandleExW
LoadLibraryExW
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
SetLastError
InterlockedPushEntrySList
RtlUnwindEx
RaiseException
RtlPcToFileHeader
FileTimeToSystemTime
GetModuleFileNameW
WriteFile
SetFilePointer
ReadFile
GetFileType
GetFileSizeEx
GetFileAttributesExW
FindNextFileW
FindClose
GetExitCodeThread
FileTimeToLocalFileTime
CreateFileW
CreateDirectoryW
CreateMutexW
WaitForSingleObject
ReleaseMutex
CloseHandle
GetLastError
LoadLibraryW
GetProcAddress
GetModuleHandleW
FreeLibrary
LocalFree
ExitProcess
GetCommandLineW
USER32.dll ScrollWindowEx
GetIconInfo
CreateIconIndirect
DestroyIcon
SetParent
EnableWindow
DestroyWindow
CreateWindowExW
DrawFrameControl
DrawFocusRect
DrawTextW
GetScrollPos
SetWindowTextW
wsprintfW
SetMenuItemInfoW
InsertMenuItemW
RemoveMenu
EndMenu
TrackPopupMenu
GetMenuItemCount
DestroyMenu
CreatePopupMenu
CreateMenu
DrawMenuBar
ShowScrollBar
SetScrollPos
SystemParametersInfoW
MapVirtualKeyW
GetDoubleClickTime
GetScrollInfo
DestroyCursor
GetClassLongPtrW
EqualRect
IntersectRect
FrameRect
PostQuitMessage
SetTimer
KillTimer
DefWindowProcW
UnregisterClassW
RegisterClassExW
GetFocus
GetAsyncKeyState
GetCapture
IsWindowEnabled
CreateAcceleratorTableW
DestroyAcceleratorTable
GetDC
GetWindowDC
ReleaseDC
GetWindowRect
GetCursorPos
ScreenToClient
WindowFromPoint
ChildWindowFromPointEx
FillRect
InflateRect
PtInRect
GetDesktopWindow
LoadCursorW
LoadIconW
TranslateMessage
DispatchMessageW
PeekMessageW
SendMessageW
WaitMessage
CallWindowProcW
ShowWindow
SetWindowPos
IsWindowVisible
SetFocus
GetActiveWindow
TranslateAcceleratorW
GetMenu
SetMenu
GetMenuItemInfoW
SetActiveWindow
GetSysColorBrush
GetClientRect
AdjustWindowRectEx
SetCursor
ClientToScreen
SetRectEmpty
GetWindowLongPtrW
SetWindowLongPtrW
GetParent
EnumChildWindows
GetAncestor
TrackMouseEvent
InvalidateRect
GetKeyState
GetSystemMetrics
BeginPaint
EndPaint
MapWindowPoints
ReleaseCapture
SetCapture
GetSysColor
RedrawWindow
GetDialogBaseUnits
SetWindowLongW
GetWindowLongW
SetScrollInfo
GDI32.dll CreateFontW
GetTextMetricsW
GetObjectW
SetBkMode
SetTextAlign
MoveToEx
SetWindowOrgEx
LineTo
Rectangle
SetBkColor
GetStockObject
CreateSolidBrush
SelectObject
DeleteDC
CreateCompatibleDC
CreateCompatibleBitmap
CreatePen
CreateBitmap
SetTextColor
BitBlt
GetTextExtentPoint32W
GetDeviceCaps
ExcludeClipRect
DeleteObject
CreatePatternBrush
SHELL32.dll SHGetFolderPathW
SHBrowseForFolderW
SHGetPathFromIDListW
CommandLineToArgvW
COMDLG32.dll ChooseColorW
GetOpenFileNameW
GetSaveFileNameW
gdiplus.dll GdipGetWorldTransform
GdipGetImagePalette
GdipGetImagePaletteSize
GdipGetImagePixelFormat
GdipTranslateWorldTransform
GdipMultiplyWorldTransform
GdipGetPropertyItemSize
GdipCreateMatrix
GdipCreateMatrix2
GdipDeleteMatrix
GdipInvertMatrix
GdipGetMatrixElements
GdipImageGetFrameDimensionsList
GdipGetImageEncoders
GdipDeleteBrush
GdipCreateSolidFill
GdipGetPropertyItem
GdipCreateBitmapFromStreamICM
GdipCreateLineBrushFromRectWithAngle
GdipSetLineTransform
GdipBitmapLockBits
GdipSaveImageToStream
GdipMultiplyLineTransform
GdipBitmapUnlockBits
GdipTranslateLineTransform
GdipScaleLineTransform
GdipRotateLineTransform
GdipDeletePen
GdipGetImageGraphicsContext
GdipScaleWorldTransform
GdipSetSmoothingMode
GdipDrawImageRectI
GdipCloneBrush
GdipGetImageEncodersSize
GdiplusStartup
GdipSetTextRenderingHint
GdipImageGetFrameCount
GdipResetWorldTransform
GdipDeleteFont
GdipCreateFont
GdipDeleteFontFamily
GdipCreateFontFamilyFromName
GdipGetImageHeight
GdipSetPenDashArray
GdipSetPenDashStyle
GdipSetPenBrushFill
GdipSetPenColor
GdipSetPenLineJoin
GdipSetPenLineCap197819
GdipSetPenWidth
GdipCreatePen1
GdipSetLineWrapMode
GdipSetLinePresetBlend
GdipSetSolidFillColor
GdipSetMatrixElements
GdipDrawImageRectRect
GdipDrawImageRect
GdipSetImageAttributesColorMatrix
GdipDisposeImageAttributes
GdipCreateImageAttributes
GdipCreateHICONFromBitmap
GdipCreateHBITMAPFromBitmap
GdipCreateBitmapFromScan0
GdipImageSelectActiveFrame
GdipDisposeImage
GdipCloneImage
GdipGraphicsClear
GdipDeleteGraphics
GdiplusShutdown
GdipAlloc
GdipFree
GdipCreateFromHDC
GdipGetImageWidth
SHLWAPI.dll #12
COMCTL32.dll ImageList_Replace
ImageList_Add
ImageList_GetImageCount
ImageList_Destroy
ImageList_Create
InitCommonControlsEx
UxTheme.dll GetThemePartSize
GetThemeFont
WS2_32.dll recv
send
shutdown
WSAStartup
WSACleanup
WSAGetLastError
closesocket
api-ms-win-core-winrt-l1-1-0.dll RoUninitialize
RoInitialize
api-ms-win-core-rtlsupport-l1-1-0.dll RtlLookupFunctionEntry
RtlCaptureContext
RtlVirtualUnwind
api-ms-win-core-errorhandling-l1-1-0.dll SetUnhandledExceptionFilter
UnhandledExceptionFilter
api-ms-win-core-processthreads-l1-1-0.dll GetStartupInfoW
GetCurrentProcess
GetCurrentProcessId
api-ms-win-core-processthreads-l1-1-1.dll IsProcessorFeaturePresent
api-ms-win-core-synch-l1-1-0.dll AcquireSRWLockExclusive
EnterCriticalSection
TryAcquireSRWLockExclusive
DeleteCriticalSection
ReleaseSRWLockExclusive
LeaveCriticalSection
InitializeCriticalSectionEx
api-ms-win-core-synch-l1-2-0.dll WakeAllConditionVariable
SleepConditionVariableSRW
api-ms-win-core-profile-l1-1-0.dll QueryPerformanceFrequency
QueryPerformanceCounter
api-ms-win-core-interlocked-l1-1-0.dll InitializeSListHead
api-ms-win-core-string-l1-1-0.dll MultiByteToWideChar
WideCharToMultiByte
GetStringTypeW
api-ms-win-core-localization-l1-2-0.dll GetCPInfo
LCMapStringEx
api-ms-win-core-util-l1-1-0.dll DecodePointer
EncodePointer
ole32.dll CoCreateFreeThreadedMarshaler
CoGetApartmentType
OLEAUT32.dll SysAllocString
SysFreeString
SysStringLen
GetErrorInfo
SetErrorInfo

Delayed Imports

1

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x282
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.0672
MD5 a4eb0c2758b7db705dae29ba5c636a0b
SHA1 885d569362df0efbbf4fce272ca6d9306e8bf302
SHA256 662d1c0a4ddb1b36682ca3a67d93b4fe41cb89b8039465921e8132d130a084cf
SHA3 a2fdc307e5705e942fbd50beec09c9ae3848b0f2ff8aba4f3b0b9748bfa6430a

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2024-Feb-25 16:11:55
Version 0.0
SizeofData 1048
AddressOfRawData 0xf3894
PointerToRawData 0xf2894

TLS Callbacks

StartAddressOfRawData 0x1400f3d08
EndAddressOfRawData 0x1400f3d10
AddressOfIndex 0x14010b898
AddressOfCallbacks 0x140094c50
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140102980

RICH Header

Errors

Leave a comment

No comments yet.