325ac714265d9f8c749fbe094574e733f337666406bc7dab7836511e8aa611f6

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Oct-08 15:09:11
Detected languages English - United States
CompanyName Display Client
FileDescription Display Client
FileVersion 1.0.0.0
InternalName DisplayClient
OriginalFilename DisplayClient.exe
ProductName Display Client
ProductVersion 1.0.0.0

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentControlSet\Services
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegEnumKeyExA
  • RegQueryValueExW
  • RegEnumValueW
  • RegDeleteValueA
  • RegDeleteValueW
  • RegEnumValueA
  • RegGetValueW
  • RegOpenKeyExW
  • RegCloseKey
  • RegQueryValueExA
  • RegSetValueExW
  • RegSetValueExA
  • RegOpenKeyExA
Possibly launches other programs:
  • ShellExecuteA
Can create temporary files:
  • GetTempPathW
  • CreateFileW
  • CreateFileA
  • GetTempPathA
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
Memory manipulation functions often used by packers:
  • VirtualAllocEx
  • VirtualProtect
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
  • CheckTokenMembership
Enumerates local disk drives:
  • GetVolumeInformationW
Manipulates other processes:
  • OpenProcess
  • Process32NextW
  • Process32FirstW
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 0f0f147364c9dcb76feaba57089a65c6 🔍
SHA1 df1aa1dde338943f8be05bf2c3245d0756acab69 🔍
SHA256 325ac714265d9f8c749fbe094574e733f337666406bc7dab7836511e8aa611f6 🔍
SHA3 d5afeab1b6d3a2fb66df7ecb89e6f22c437978ace5291bf2e748b41dba345362 🔍
SSDeep 196608:ncJNHE27YBCF/AbEepRxoJua7BIDmg/Htumr3U/3qKySMkHG7FoXJm+kLS3/hys:c7MYobEkohIDmonw6KySJHGBoX4yPQs 🔍
Imports Hash 7e256579048a66670b7396979874230e 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x120

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Oct-08 15:09:11
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x1e1c00
SizeOfInitializedData 0x983800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000019FA00 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xb69000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 198e86f82d165d0f683cb47bbe497ca4 🔍
SHA1 17467165e0ca3f4755f6c0a3329f6ea80412f437 🔍
SHA256 4a313588e4d7b88294bed8828cc447af94fda69c3fc63e6604134b4bdbe20c7b 🔍
SHA3 db35f84c04c4a4f0a170a5c9d3b559da3f1d082469a747be8cf1ed6a2494dfd7 🔍
VirtualSize 0x1e1a8c
VirtualAddress 0x1000
SizeOfRawData 0x1e1c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.56913

.rdata

MD5 78378c3550de51f040eadddf10861c1c 🔍
SHA1 d09989ad6105477015700d918454e11f8485714f 🔍
SHA256 3ce899345b2429d2bbf51ae0556b0239edc1437d37d6419c6bae82ed1259d758 🔍
SHA3 dacf868f5a7f21c527b8ae0c7723c38ddc895b4363e7b52c54696cd0e9af69da 🔍
VirtualSize 0x94f400
VirtualAddress 0x1e3000
SizeOfRawData 0x94f400
PointerToRawData 0x1e2000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.52876

.data

MD5 7e3b66f6da6f3d520f64c92b80506724 🔍
SHA1 269a72d6f1981e97422ca33e29581ae678827a8c 🔍
SHA256 98d9b5e1210216c54c10f3373bc920b5bdf2f6564759db8e1910149eb4332e0f 🔍
SHA3 adeb9071cb7627e87699211f8521452c2bd334fadfc735ebe49bd7e568869d91 🔍
VirtualSize 0x5634
VirtualAddress 0xb33000
SizeOfRawData 0x2e00
PointerToRawData 0xb31400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.20029

.pdata

MD5 f350e56af717a5052f68de8f95492084 🔍
SHA1 9a3533fae757fae2ffa14a36ec0111331dc8d75e 🔍
SHA256 272b5fd61e11c14fccecb3900ea701e48cb8ef2da57e5254cf3502bfbc0eb89d 🔍
SHA3 d72ace754be11f488a6d304a7986b5f9ca603a1eaee348c994584d5ffab676c3 🔍
VirtualSize 0x123cc
VirtualAddress 0xb39000
SizeOfRawData 0x12400
PointerToRawData 0xb34200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.21616

.rsrc

MD5 8c362da590ed6c20a801e884a2dcb829 🔍
SHA1 3f11b2c6183a3fc50d465d3bdc91091cd6b39a78 🔍
SHA256 5241fd6641376ffd7509290084e8c2baa552f438f80213c756c2d293dc8ec367 🔍
SHA3 c3a17f02cc3c09f4afe8cba2b67dc04fbea5927c934e086934aa98f8df8e24da 🔍
VirtualSize 0x1ace8
VirtualAddress 0xb4c000
SizeOfRawData 0x1ae00
PointerToRawData 0xb46600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.72625

.reloc

MD5 63a3901a58f22b0b46ca4ea2cd31cb5b 🔍
SHA1 dc50acff08136e8b0c98f6c8cf89b39a0d15d0fb 🔍
SHA256 34ff649e952fbf45686aa8978ff8af0400b67520ce48619850907d8f00432ea2 🔍
SHA3 eff519f806ea0dedeeef09508f45ee726d6d2fd3810616f5a4667a4fd4ab23b2 🔍
VirtualSize 0x18e0
VirtualAddress 0xb67000
SizeOfRawData 0x1a00
PointerToRawData 0xb61400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.33914

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
D3DCOMPILER_43.dll D3DCompile
KERNEL32.dll GetTempPathW
FindClose
CreateFileW
GetFileAttributesW
SetFileAttributesW
Sleep
GetTickCount64
GetLastError
GetFileAttributesA
MoveFileExA
CreateFileA
DeleteFileW
CloseHandle
Beep
LocalFree
ExitProcess
GetSystemTimeAsFileTime
MoveFileW
GetFileTime
GetModuleHandleW
OpenProcess
CreateToolhelp32Snapshot
Process32NextW
Process32FirstW
K32GetModuleBaseNameA
K32GetModuleInformation
Module32FirstW
Module32NextW
K32EnumProcessModules
VirtualAllocEx
GetCurrentProcessId
VirtualFreeEx
VirtualQueryEx
GetStartupInfoW
LoadLibraryW
ReadFile
HeapAlloc
HeapReAlloc
HeapFree
GetProcessHeap
MapViewOfFile
UnmapViewOfFile
CreateFileMappingA
GetEnvironmentStringsW
GetCommandLineA
GetOEMCP
GetACP
IsValidCodePage
GetTimeZoneInformation
ReadConsoleW
EnumSystemLocalesW
GetUserDefaultLCID
IsValidLocale
GetLocaleInfoW
LCMapStringW
CompareStringW
LoadLibraryExW
VirtualProtect
GetConsoleMode
GetConsoleOutputCP
FlushFileBuffers
SetFilePointerEx
SetEndOfFile
UnhandledExceptionFilter
IsDebuggerPresent
RtlVirtualUnwind
RtlCaptureContext
WriteFile
GetStdHandle
TerminateProcess
IsProcessorFeaturePresent
GetModuleHandleExW
FreeLibraryAndExitThread
ExitThread
CreateThread
RtlUnwind
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
SetLastError
RaiseException
RtlPcToFileHeader
RtlUnwindEx
RtlLookupFunctionEntry
SetFilePointer
FindNextFileA
GetModuleFileNameW
SetFileTime
GetCurrentProcess
FindNextFileW
GetCommandLineW
FindFirstFileA
GetFileSizeEx
MoveFileA
FindFirstFileW
GetVolumeInformationW
QueryDosDeviceW
GlobalUnlock
WideCharToMultiByte
GlobalLock
GlobalFree
GlobalAlloc
QueryPerformanceCounter
FreeLibrary
GetProcAddress
QueryPerformanceFrequency
LoadLibraryA
MultiByteToWideChar
WriteConsoleW
GetLocaleInfoA
GetModuleHandleA
GetLocalTime
GetTempPathA
FreeEnvironmentStringsW
InitializeSListHead
SetUnhandledExceptionFilter
GetCPInfo
WakeAllConditionVariable
LCMapStringEx
DecodePointer
EncodePointer
DeleteCriticalSection
InitializeCriticalSectionEx
LeaveCriticalSection
EnterCriticalSection
GetStringTypeW
SleepConditionVariableSRW
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
GetExitCodeThread
WaitForSingleObjectEx
GetCurrentThreadId
GetSystemTimePreciseAsFileTime
GetFileInformationByHandleEx
AreFileApisANSI
CreateFile2
SetFileInformationByHandle
GetFileAttributesExW
FindFirstFileExW
SetEnvironmentVariableW
SetStdHandle
HeapSize
GetFileType
FormatMessageA
GetLocaleInfoEx
CreateDirectoryW
USER32.dll LoadCursorW
GetForegroundWindow
GetKeyboardLayout
TrackMouseEvent
ClientToScreen
GetCapture
ScreenToClient
GetMessageExtraInfo
GetKeyState
SetClipboardData
GetClipboardData
EmptyClipboard
CloseClipboard
SetCursor
SendInput
GetSystemMetrics
TranslateMessage
PeekMessageW
DispatchMessageW
mouse_event
GetWindowTextW
EnumWindows
GetWindowTextLengthW
GetWindowThreadProcessId
SetForegroundWindow
GetClientRect
GetAsyncKeyState
GetCursorPos
SetCursorPos
SetCapture
IsWindowUnicode
OpenClipboard
ShowWindow
UpdateWindow
DefWindowProcW
CreateWindowExW
RegisterClassExW
SetWindowLongW
MapWindowPoints
MoveWindow
SetLayeredWindowAttributes
ReleaseCapture
ADVAPI32.dll RegEnumKeyExA
RegQueryValueExW
RegEnumValueW
RegDeleteValueA
RegDeleteValueW
RegEnumValueA
RegGetValueW
RegOpenKeyExW
LookupPrivilegeValueW
AdjustTokenPrivileges
RegCloseKey
RegQueryValueExA
AllocateAndInitializeSid
RegSetValueExW
RegSetValueExA
OpenProcessToken
FreeSid
CheckTokenMembership
RegOpenKeyExA
SHELL32.dll SHGetFolderPathA
CommandLineToArgvW
SHGetKnownFolderPath
ShellExecuteA
ole32.dll CoTaskMemFree
d3dx11_43.dll D3DX11CreateShaderResourceViewFromMemory
dwmapi.dll DwmExtendFrameIntoClientArea
WS2_32.dll setsockopt
htons
inet_ntop
htonl
recv
connect
socket
send
getsockname
WSAStartup
inet_pton
listen
select
closesocket
bind
accept
WSACleanup
bcrypt.dll BCryptEncrypt
BCryptDestroyKey
BCryptDecrypt
BCryptOpenAlgorithmProvider
BCryptFinishHash
BCryptCloseAlgorithmProvider
BCryptDestroyHash
BCryptHashData
BCryptSetProperty
BCryptGenerateSymmetricKey
IMM32.dll ImmGetContext
ImmSetCandidateWindow
ImmReleaseContext
ImmSetCompositionWindow

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1a580
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.60756
MD5 12a60110aae42fc412c1f3624f0ff2ac 🔍
SHA1 d55f611c7f6033fed1eb611500f577feb8e9683d 🔍
SHA256 ff9aba29bbea45a07c75e51b47f8dad6fac39c210600b2ec616fda5886325364 🔍
SHA3 cb22310e81d7f066bfadd6ab320031e5ba091730aff95bf9c5ed879daa1443cf 🔍

1 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.21498
Detected Filetype Icon file
MD5 4ca7aa52f03df5004cecdb4ff34719a1 🔍
SHA1 cc98c7620826b46e2aad03ecc6da4a10fc2b3a62 🔍
SHA256 343efad8f85cecc9a3f1a169f3fd81ea39152bca6a9d5a3f18d01ef4046fd86d 🔍
SHA3 8221845ef3590337c7177a7c4495a27f1b6220f4650146c14e15ae61165a60f9 🔍

1 (#3)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x290
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.21807
MD5 fe26a44214256aeadc3578252629a9aa 🔍
SHA1 39bb05225abb2b297c0732cbf0c2f9851df5d10b 🔍
SHA256 8579b0d52c27313e6708fe340ce2ef2161c7da9999942369b228cb73e8277826 🔍
SHA3 81fd812139a6689a8ade297487542482117763d052c5fd00ac9be28830051aa7 🔍

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x38c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.28392
MD5 e0b0b8c2b9f9be559c466fb27ed9b1d1 🔍
SHA1 7c7f1ecc31cc4bbc63956c03d3cec77d14f7f5d6 🔍
SHA256 e701c8729fd800e081b7f92417ba2daf3088f0d379055721b98b05056b7b38c3 🔍
SHA3 8de74658456ca05202de298b10fcf782ce3238f04994b0ffa1a266881fd2a0ab 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Display Client
FileDescription Display Client
FileVersion (#2) 1.0.0.0
InternalName DisplayClient
OriginalFilename DisplayClient.exe
ProductName Display Client
ProductVersion (#2) 1.0.0.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Oct-08 15:09:11
Version 0.0
SizeofData 1068
AddressOfRawData 0xb109c8
PointerToRawData 0xb0f9c8

TLS Callbacks

StartAddressOfRawData 0x140b10e40
EndAddressOfRawData 0x140b10e48
AddressOfIndex 0x140b36510
AddressOfCallbacks 0x1401e3a48
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140b33180

RICH Header

XOR Key 0x60ccdce0
Unmarked objects 0
C++ objects (35222) 185
C objects (35222) 30
ASM objects (35222) 28
253 (35721) 1
ASM objects (35721) 17
C objects (35721) 18
C++ objects (35721) 97
C objects (CVTCIL) (35222) 1
Imports (35222) 22
C objects (VS2022 Update 1 (17.1.6) compiler 31107) 26
Imports (21202) 7
Total imports 301
C++ objects (LTCG) (36252) 56
Resource objects (36252) 1
151 1
Linker (36252) 1

Errors

Leave a comment

No comments yet.