| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1970-Jan-01 00:00:00 |
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 |
| Suspicious | The PE is packed with UPX |
Unusual section name found: UPX0
Section UPX0 is both writable and executable. Unusual section name found: UPX1 Section UPX1 is both writable and executable. Unusual section name found: UPX2 The PE only has 4 import(s). |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 44/66 (Scanned on 2025-10-04 05:16:38) |
ALYac:
Trojan.MSIL.Stealer.gen
APEX: Malicious AhnLab-V3: Trojan/Win.Generic.R455890 Alibaba: Trojan:Win32/Redcap.e1c7a081 Arcabit: Trojan.Generic.D44FE667 Avira: HEUR/AGEN.1375015 BitDefender: Trojan.GenericKD.72345191 CAT-QuickHeal: Trojan.Ghanarava.172883654463fc6f CTX: exe.trojan.scar CrowdStrike: win/malicious_confidence_100% (W) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS DrWeb: Trojan.MulDrop19.3970 ESET-NOD32: a variant of WinGo/Agent.DG Elastic: malicious (moderate confidence) Emsisoft: Trojan.GenericKD.72345191 (B) Fortinet: W64/Agent.DG!tr GData: Trojan.GenericKD.72345191 Google: Detected Ikarus: Trojan.WinGo.Agent Jiangmin: Trojan.Scar.try K7AntiVirus: Trojan ( 0058abb41 ) K7GW: Trojan ( 0058abb41 ) Kaspersky: Trojan.Win32.Scar.tiut Lionic: Trojan.Win32.Scar.1n!c Malwarebytes: Generic.Malware/Suspicious McAfeeD: Real Protect-LS!618EA7B0E2A2 MicroWorld-eScan: Trojan.GenericKD.72345191 Microsoft: Trojan:Win32/Mamson.A!ac Paloalto: generic.ml Panda: Trj/CI.A Sangfor: Trojan.Win32.Agent.Vy47 SentinelOne: Static AI - Malicious PE Sophos: Mal/Generic-S Tencent: Malware.Win32.Gencirc.13b17019 VBA32: Trojan.Scar VIPRE: Trojan.GenericKD.72345191 Varist: W64/Trojan.HSE.gen!Eldorado Webroot: W32.Trojan.Gen Xcitium: Malware@#lpxsa0kx5653 ZoneAlarm: Troj/Agent-BILT alibabacloud: Trojan:Multi/Scar.tiut huorong: Backdoor/Kraken.b |
| MD5 | 618ea7b0e2a26f3c6db0a8664c63fc6f 🔍 |
|---|---|
| SHA1 | f2d41df1d55178b5f7de0512912159f2663296cd 🔍 |
| SHA256 | 3215decffc40b3257ebeb9b6e5c81c45e298a020f33ef90c9418c153c6071b36 🔍 |
| SHA3 | 7e58e97daf90bca4a3d6fce79fe1c9f116f7da1adbe8481ca8035167a6509cd2 🔍 |
| SSDeep | 49152:HAThssooIzoGVgz+GymgXdAa/9uZvvij0b/U:hbTrGymgNAaIv5/U 🔍 |
| Imports Hash | 6ed4f5f04d62b18d96b26d6db7c18840 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0x4 |
| e_cparhdr | 0 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0x8b |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 3 |
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| PointerToSymbolTable | 0x4ba000 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 3.0 |
| SizeOfCode | 0x1bc000 |
| SizeOfInitializedData | 0x1000 |
| SizeOfUninitializedData | 0x328000 |
| AddressOfEntryPoint | 0x00000000004E4790 (Section: UPX1) |
| BaseOfCode | 0x329000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.1 |
| ImageVersion | 1.0 |
| SubsystemVersion | 6.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x4e6000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | d41d8cd98f00b204e9800998ecf8427e 🔍 |
|---|---|
| SHA1 | da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍 |
| SHA256 | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍 |
| SHA3 | a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍 |
| VirtualSize | 0x328000 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0 |
| PointerToRawData | 0x200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| MD5 | 853f4d5e547928c6eafaa7fae312c83b 🔍 |
|---|---|
| SHA1 | ed4b7daebc7e7c9600f7b842dc146109af4e2063 🔍 |
| SHA256 | 8a56eeabf7cf0f7e3ec4bf5e38b0b92191e6ececcaad61ac5ffce2b71ba07731 🔍 |
| SHA3 | 135bbbbdeac72290be01a4d1a4b9a6c06c6ea63fde8cb05841979c169e7b8068 🔍 |
| VirtualSize | 0x1bc000 |
| VirtualAddress | 0x329000 |
| SizeOfRawData | 0x1bba00 |
| PointerToRawData | 0x200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 7.867 |
| MD5 | 8be4450c3eabb4eb1a9348c19a7ce871 🔍 |
|---|---|
| SHA1 | 649319d7a3b87f5e3570c4d61fff73f6973d4ee6 🔍 |
| SHA256 | a712d41773bc78b76a05e73040729000232280798a537120ab28a0269dbe554d 🔍 |
| SHA3 | db62af0bbdc5a1de9fa868cf64dd06f94675eae2b39225530eaa9e0785874a2a 🔍 |
| VirtualSize | 0x1000 |
| VirtualAddress | 0x4e5000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x1bbc00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 1.34486 |
| KERNEL32.DLL |
LoadLibraryA
ExitProcess GetProcAddress VirtualProtect |
|---|
No comments yet.