| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Sep-05 13:20:07 |
| Detected languages |
English - United States
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA256 Uses constants related to SHA512 Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 22/70 (Scanned on 2026-09-06 16:22:06) |
APEX:
Malicious
AVG: Win64:MalwareX-gen [Cryp] AhnLab-V3: Trojan/Win.Generic.C5930659 Avast: Win64:MalwareX-gen [Cryp] Avira: TR/W64.MalwareX Bkav: W32.Malware.6AF96004 CrowdStrike: win/malicious_confidence_70% (D) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS ESET-NOD32: Win64/GenKryptik_AGen.BDP trojan Elastic: malicious (high confidence) F-Secure: Trojan.TR/W64.MalwareX Fortinet: W64/GenKryptik.WS!tr Google: Detected Malwarebytes: Malware.AI.3575263493 McAfeeD: ti!330B6FEF2450 Microsoft: Trojan:Win32/Sabsik.EN.A!ml Rising: Trojan.Kryptik@AI.94 (RDML:bZcm66mb2dZ+A1e2u3W4ig) Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Suspicious PE Symantec: ML.Attribute.HighConfidence |
| MD5 | 142884e1606742ec520e3f8b14ea5724 🔍 |
|---|---|
| SHA1 | 8ba108645b57f9168ff71288ff5b013e5157d3f7 🔍 |
| SHA256 | 330b6fef24500765145ecb0afece808f67d0ae12595598a391cbcaee50f02637 🔍 |
| SHA3 | bc885b08a17ae2a478d20db7129f79d525dc7398a7f6195cf1790f0b2a3d9e02 🔍 |
| SSDeep | 49152:3vslNqIqNhY07DxI/Wl3VwMf+NWNarsAn3bj:UjqIEfI/Wl3VwMf+NWNw 🔍 |
| Imports Hash | 1ab7f90e706300fd453fc0ea63d13545 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x128 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Sep-05 13:20:07 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x15bc00 |
| SizeOfInitializedData | 0x6d400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000001205A0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1ce000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 293a5ca513d6a5617018ade66f5efcc3 🔍 |
|---|---|
| SHA1 | 921bc91fa7c771cf2e68f61dfa1ba5b764aac90e 🔍 |
| SHA256 | 2424a5cbcb5e0b9ae94e00f31b1973afa01b9aa0c89e71b570ec3d35b3addeea 🔍 |
| SHA3 | 4c1cc829d9605156aee0a1fb948e079c28d7db857740c479e164f7373a711873 🔍 |
| VirtualSize | 0x15bb88 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x15bc00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.55717 |
| MD5 | db7b6bcd960405b6cf5c6958d852f8f0 🔍 |
|---|---|
| SHA1 | 090c8c8483bba4636e50b3f86273cc635e5d713a 🔍 |
| SHA256 | 071beb3aed5b1b42bfc53eaf23232eac6f006ba8b7c49a72283c300b3d5fe8d5 🔍 |
| SHA3 | acaaf4f92785a4a90be964b82fa368ed8a4da519ecaef3d396d2a59bbba9585a 🔍 |
| VirtualSize | 0x562f0 |
| VirtualAddress | 0x15d000 |
| SizeOfRawData | 0x56400 |
| PointerToRawData | 0x15c000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.26964 |
| MD5 | 5158f9515130226bae52eb1d331a1306 🔍 |
|---|---|
| SHA1 | 7032f5a213f11a30c51904f067c8153e54dd674c 🔍 |
| SHA256 | 5688c0c8e241582dc9e217c01814f85cbab6e8248547ad50e3289e0e1e49771e 🔍 |
| SHA3 | 6cc8cc454c6f1826c2f3bc6ea896e3c74cb9b8f247f2ede0b3d332295bfcf1fa 🔍 |
| VirtualSize | 0x6b04 |
| VirtualAddress | 0x1b4000 |
| SizeOfRawData | 0x3200 |
| PointerToRawData | 0x1b2400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 4.11911 |
| MD5 | a63ecafad04fa22bead11edeae3542ad 🔍 |
|---|---|
| SHA1 | 4b283ec76df703e3a3a57774f63c6221c4b7d03f 🔍 |
| SHA256 | 482e08cadd3bc5dda3eda13990fa3727b13525c9e811fb52e3a0cddd29eeeeca 🔍 |
| SHA3 | 0d8fe52d0500077f25897ba6dd8f532c1dbadffbee1db5e53bd35be86989d12f 🔍 |
| VirtualSize | 0xe7c0 |
| VirtualAddress | 0x1bb000 |
| SizeOfRawData | 0xe800 |
| PointerToRawData | 0x1b5600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.15433 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x100 |
| VirtualAddress | 0x1ca000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x1c3e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 11b6ccd5b2b416f1a2c7ee24217c8dbc 🔍 |
|---|---|
| SHA1 | c7dd58ff1d81ad99fe698a544c1fadd469c59943 🔍 |
| SHA256 | aeae31fc3f21424f731e4568a8e9f44e8304ebc72f844fa58081959c9b120482 🔍 |
| SHA3 | 1f4ffbe279e3c0ef368cd919e25b42c9c957971b4b2ebf052d44357fda46b1d0 🔍 |
| VirtualSize | 0x1e8 |
| VirtualAddress | 0x1cb000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x1c4000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.77204 |
| MD5 | e63cd1d2e3d1390e76e69696d7e8ab05 🔍 |
|---|---|
| SHA1 | a35a81d4cbfa91fc3870441746bb14bab9fb99a1 🔍 |
| SHA256 | b0d6758079fb03d9dd6330a389eb374f809d6861d7cb58aa5956214f41cc9947 🔍 |
| SHA3 | fa464ecf2fea3c6e2cb82b3db3a2e0efbade52d4dfcd6d0f4bbf7a4a04917cf5 🔍 |
| VirtualSize | 0x179c |
| VirtualAddress | 0x1cc000 |
| SizeOfRawData | 0x1800 |
| PointerToRawData | 0x1c4200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.4259 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| KERNEL32.dll |
GetEnvironmentVariableA
GetStdHandle GetFileType ReadFile PeekNamedPipe WaitForMultipleObjects GetCurrentProcessId VerifyVersionInfoW GetFileSizeEx SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetOEMCP GetACP IsValidCodePage SetEndOfFile SetStdHandle GetTimeZoneInformation CreatePipe FlushFileBuffers EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW GetTimeFormatW GetDateFormatW FlsFree FlsSetValue FlsGetValue FlsAlloc GetExitCodeProcess WaitForSingleObject GetConsoleOutputCP ReadConsoleW GetConsoleMode GetCommandLineW GetCommandLineA WriteFile SetFilePointerEx FileTimeToSystemTime SystemTimeToTzSpecificLocalTime GetDriveTypeW VirtualQuery CreateProcessW DuplicateHandle WaitForSingleObjectEx ExitThread GetModuleHandleExW VirtualAlloc LoadLibraryExW TlsFree TlsSetValue GetSystemInfo LoadLibraryW GetSystemDirectoryW LocalFree LeaveCriticalSection EnterCriticalSection InitializeCriticalSection AcquireSRWLockExclusive ReleaseSRWLockExclusive FormatMessageW SetLastError QueryFullProcessImageNameW GetModuleFileNameW UnmapViewOfFile MapViewOfFile CreateFileMappingW VirtualProtect CreateThread GetCurrentProcess DeleteCriticalSection InitializeCriticalSectionEx GetProcessHeap HeapSize HeapFree HeapReAlloc HeapAlloc HeapDestroy AddVectoredExceptionHandler DecodePointer GetLocaleInfoA LoadLibraryA GetProcAddress GetModuleHandleA FreeLibrary QueryPerformanceFrequency QueryPerformanceCounter VerSetConditionMask MultiByteToWideChar TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount GetTickCount FreeLibraryAndExitThread GlobalFree GlobalLock RtlUnwindEx RtlPcToFileHeader RaiseException OutputDebugStringW GlobalUnlock GlobalAlloc Process32NextW Process32FirstW CreateToolhelp32Snapshot RtlUnwind SetConsoleTitleA SetConsoleCtrlHandler WideCharToMultiByte MoveFileExW lstrcmpiW GetModuleHandleW GetModuleFileNameA GetWindowsDirectoryW Sleep SleepEx InitializeSListHead GetStartupInfoW IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext GetCPInfo GetStringTypeW LCMapStringEx EncodePointer WakeAllConditionVariable GetSystemTimeAsFileTime GetFileInformationByHandleEx AreFileApisANSI SetFileInformationByHandle DeviceIoControl GetLastError CloseHandle RemoveDirectoryW DeleteFileW CreateFileW WriteConsoleW ExitProcess GetFullPathNameW GetFileInformationByHandle GetFileAttributesExW FormatMessageA GetLocaleInfoEx GetCurrentThreadId TryAcquireSRWLockExclusive SleepConditionVariableSRW GetCurrentDirectoryW CreateDirectoryW FindClose FindFirstFileW FindFirstFileExW FindNextFileW |
| USER32.dll |
DestroyWindow
ShowWindow SetLayeredWindowAttributes GetAsyncKeyState GetKeyNameTextA MapVirtualKeyA GetSystemMetrics UpdateWindow GetClientRect GetCursorPos ScreenToClient GetDesktopWindow MonitorFromPoint BlockInput OpenClipboard CloseClipboard CreateWindowExW GetClipboardData EmptyClipboard GetKeyboardLayout TrackMouseEvent GetMessageExtraInfo GetKeyState GetCapture SetCapture ReleaseCapture IsWindowUnicode GetForegroundWindow GetDC ReleaseDC SetCursorPos SetCursor ClientToScreen LoadCursorW SetProcessDPIAware MessageBoxA RegisterClassExW SetClipboardData TranslateMessage UnregisterClassW PeekMessageW DefWindowProcW PostQuitMessage DispatchMessageW |
| GDI32.dll |
GetDeviceCaps
|
| ADVAPI32.dll |
CryptHashData
CloseServiceHandle ControlService CreateServiceW DeleteService OpenSCManagerA OpenSCManagerW OpenProcessToken AddAccessAllowedAce GetLengthSid GetTokenInformation InitializeAcl IsValidSid RegCreateKeyExA RegDeleteKeyA SetSecurityInfo CopySid ConvertSidToStringSidA CryptAcquireContextW CryptReleaseContext CryptGetHashParam OpenServiceW QueryServiceStatusEx CryptCreateHash CryptEncrypt CryptImportKey CryptDestroyKey SystemFunction036 CryptDestroyHash StartServiceW |
| SHELL32.dll |
ShellExecuteA
|
| urlmon.dll |
URLDownloadToFileA
|
| IMM32.dll |
ImmSetCompositionWindow
ImmReleaseContext ImmGetContext ImmSetCandidateWindow |
| D3DCOMPILER_47.dll |
D3DCompile
|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| CRYPT32.dll |
CertOpenStore
CertCloseStore CertEnumCertificatesInStore CertFindCertificateInStore CertFreeCertificateContext PFXImportCertStore CryptDecodeObjectEx CertAddCertificateContextToStore CertFindExtension CertGetNameStringW CryptQueryObject CertCreateCertificateChainEngine CertFreeCertificateChainEngine CertGetCertificateChain CertFreeCertificateChain CryptStringToBinaryW |
| WS2_32.dll |
send
WSACloseEvent WSACreateEvent WSAEnumNetworkEvents WSAEventSelect WSAResetEvent WSAWaitForMultipleEvents getsockopt WSAGetLastError inet_pton ntohs WSASetLastError inet_ntop WSAStartup WSACleanup bind connect getpeername closesocket htons recv setsockopt socket WSAIoctl __WSAFDIsSet select accept htonl listen getaddrinfo freeaddrinfo recvfrom sendto ioctlsocket gethostname getsockname |
| SHLWAPI.dll |
PathFindFileNameW
|
| PSAPI.DLL |
GetModuleInformation
|
| USERENV.dll |
UnloadUserProfile
|
| bcrypt.dll |
BCryptGenRandom
|
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x188 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.89623 |
| MD5 | b8e76ddb52d0eb41e972599ff3ca431b 🔍 |
| SHA1 | fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍 |
| SHA256 | 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍 |
| SHA3 | 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Sep-05 13:20:07 |
| Version | 0.0 |
| SizeofData | 1052 |
| AddressOfRawData | 0x19bed0 |
| PointerToRawData | 0x19aed0 |
| StartAddressOfRawData | 0x14019c338 |
|---|---|
| EndAddressOfRawData | 0x14019c340 |
| AddressOfIndex | 0x1401b9910 |
| AddressOfCallbacks | 0x14015dc50 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1401b5600 |
| XOR Key | 0xa6d44855 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 209 |
| C objects (33145) | 38 |
| ASM objects (33145) | 24 |
| 253 (35207) | 7 |
| ASM objects (35207) | 10 |
| C objects (35207) | 18 |
| C++ objects (35207) | 102 |
| C objects (33523) | 43 |
| C objects (VS2022 Update 6 (17.6.4) compiler 32535) | 129 |
| C++ objects (35221) | 5 |
| Imports (33145) | 35 |
| Total imports | 362 |
| C++ objects (35228) | 10 |
| Resource objects (35228) | 1 |
| Linker (35228) | 1 |
No comments yet.