330b6fef24500765145ecb0afece808f67d0ae12595598a391cbcaee50f02637

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Sep-05 13:20:07
Detected languages English - United States

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • example.com
  • github.com
  • https://curl.se
  • https://github.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA256
Uses constants related to SHA512
Uses known Mersenne Twister constants
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryW
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegCreateKeyExA
  • RegDeleteKeyA
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteA
Uses Microsoft's cryptographic API:
  • CryptHashData
  • CryptAcquireContextW
  • CryptReleaseContext
  • CryptGetHashParam
  • CryptCreateHash
  • CryptEncrypt
  • CryptImportKey
  • CryptDestroyKey
  • CryptDestroyHash
  • CryptDecodeObjectEx
  • CryptQueryObject
  • CryptStringToBinaryW
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • MapVirtualKeyA
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Has Internet access capabilities:
  • URLDownloadToFileA
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Functions related to the privilege level:
  • OpenProcessToken
Interacts with services:
  • ControlService
  • CreateServiceW
  • DeleteService
  • OpenSCManagerA
  • OpenSCManagerW
  • OpenServiceW
  • QueryServiceStatusEx
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • Process32NextW
  • Process32FirstW
Changes object ACLs:
  • SetSecurityInfo
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertOpenStore
  • CertAddCertificateContextToStore
Malicious VirusTotal score: 22/70 (Scanned on 2026-09-06 16:22:06) APEX: Malicious
AVG: Win64:MalwareX-gen [Cryp]
AhnLab-V3: Trojan/Win.Generic.C5930659
Avast: Win64:MalwareX-gen [Cryp]
Avira: TR/W64.MalwareX
Bkav: W32.Malware.6AF96004
CrowdStrike: win/malicious_confidence_70% (D)
Cylance: Unsafe
Cynet: Malicious (score: 100)
DeepInstinct: MALICIOUS
ESET-NOD32: Win64/GenKryptik_AGen.BDP trojan
Elastic: malicious (high confidence)
F-Secure: Trojan.TR/W64.MalwareX
Fortinet: W64/GenKryptik.WS!tr
Google: Detected
Malwarebytes: Malware.AI.3575263493
McAfeeD: ti!330B6FEF2450
Microsoft: Trojan:Win32/Sabsik.EN.A!ml
Rising: Trojan.Kryptik@AI.94 (RDML:bZcm66mb2dZ+A1e2u3W4ig)
Sangfor: Trojan.Win32.Save.a
SentinelOne: Static AI - Suspicious PE
Symantec: ML.Attribute.HighConfidence

Hashes

MD5 142884e1606742ec520e3f8b14ea5724 🔍
SHA1 8ba108645b57f9168ff71288ff5b013e5157d3f7 🔍
SHA256 330b6fef24500765145ecb0afece808f67d0ae12595598a391cbcaee50f02637 🔍
SHA3 bc885b08a17ae2a478d20db7129f79d525dc7398a7f6195cf1790f0b2a3d9e02 🔍
SSDeep 49152:3vslNqIqNhY07DxI/Wl3VwMf+NWNarsAn3bj:UjqIEfI/Wl3VwMf+NWNw 🔍
Imports Hash 1ab7f90e706300fd453fc0ea63d13545 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x128

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Sep-05 13:20:07
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x15bc00
SizeOfInitializedData 0x6d400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000001205A0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1ce000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 293a5ca513d6a5617018ade66f5efcc3 🔍
SHA1 921bc91fa7c771cf2e68f61dfa1ba5b764aac90e 🔍
SHA256 2424a5cbcb5e0b9ae94e00f31b1973afa01b9aa0c89e71b570ec3d35b3addeea 🔍
SHA3 4c1cc829d9605156aee0a1fb948e079c28d7db857740c479e164f7373a711873 🔍
VirtualSize 0x15bb88
VirtualAddress 0x1000
SizeOfRawData 0x15bc00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.55717

.rdata

MD5 db7b6bcd960405b6cf5c6958d852f8f0 🔍
SHA1 090c8c8483bba4636e50b3f86273cc635e5d713a 🔍
SHA256 071beb3aed5b1b42bfc53eaf23232eac6f006ba8b7c49a72283c300b3d5fe8d5 🔍
SHA3 acaaf4f92785a4a90be964b82fa368ed8a4da519ecaef3d396d2a59bbba9585a 🔍
VirtualSize 0x562f0
VirtualAddress 0x15d000
SizeOfRawData 0x56400
PointerToRawData 0x15c000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.26964

.data

MD5 5158f9515130226bae52eb1d331a1306 🔍
SHA1 7032f5a213f11a30c51904f067c8153e54dd674c 🔍
SHA256 5688c0c8e241582dc9e217c01814f85cbab6e8248547ad50e3289e0e1e49771e 🔍
SHA3 6cc8cc454c6f1826c2f3bc6ea896e3c74cb9b8f247f2ede0b3d332295bfcf1fa 🔍
VirtualSize 0x6b04
VirtualAddress 0x1b4000
SizeOfRawData 0x3200
PointerToRawData 0x1b2400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.11911

.pdata

MD5 a63ecafad04fa22bead11edeae3542ad 🔍
SHA1 4b283ec76df703e3a3a57774f63c6221c4b7d03f 🔍
SHA256 482e08cadd3bc5dda3eda13990fa3727b13525c9e811fb52e3a0cddd29eeeeca 🔍
SHA3 0d8fe52d0500077f25897ba6dd8f532c1dbadffbee1db5e53bd35be86989d12f 🔍
VirtualSize 0xe7c0
VirtualAddress 0x1bb000
SizeOfRawData 0xe800
PointerToRawData 0x1b5600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.15433

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x1ca000
SizeOfRawData 0x200
PointerToRawData 0x1c3e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 11b6ccd5b2b416f1a2c7ee24217c8dbc 🔍
SHA1 c7dd58ff1d81ad99fe698a544c1fadd469c59943 🔍
SHA256 aeae31fc3f21424f731e4568a8e9f44e8304ebc72f844fa58081959c9b120482 🔍
SHA3 1f4ffbe279e3c0ef368cd919e25b42c9c957971b4b2ebf052d44357fda46b1d0 🔍
VirtualSize 0x1e8
VirtualAddress 0x1cb000
SizeOfRawData 0x200
PointerToRawData 0x1c4000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.77204

.reloc

MD5 e63cd1d2e3d1390e76e69696d7e8ab05 🔍
SHA1 a35a81d4cbfa91fc3870441746bb14bab9fb99a1 🔍
SHA256 b0d6758079fb03d9dd6330a389eb374f809d6861d7cb58aa5956214f41cc9947 🔍
SHA3 fa464ecf2fea3c6e2cb82b3db3a2e0efbade52d4dfcd6d0f4bbf7a4a04917cf5 🔍
VirtualSize 0x179c
VirtualAddress 0x1cc000
SizeOfRawData 0x1800
PointerToRawData 0x1c4200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.4259

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
KERNEL32.dll GetEnvironmentVariableA
GetStdHandle
GetFileType
ReadFile
PeekNamedPipe
WaitForMultipleObjects
GetCurrentProcessId
VerifyVersionInfoW
GetFileSizeEx
SetEnvironmentVariableW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetOEMCP
GetACP
IsValidCodePage
SetEndOfFile
SetStdHandle
GetTimeZoneInformation
CreatePipe
FlushFileBuffers
EnumSystemLocalesW
GetUserDefaultLCID
IsValidLocale
GetLocaleInfoW
LCMapStringW
CompareStringW
GetTimeFormatW
GetDateFormatW
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetExitCodeProcess
WaitForSingleObject
GetConsoleOutputCP
ReadConsoleW
GetConsoleMode
GetCommandLineW
GetCommandLineA
WriteFile
SetFilePointerEx
FileTimeToSystemTime
SystemTimeToTzSpecificLocalTime
GetDriveTypeW
VirtualQuery
CreateProcessW
DuplicateHandle
WaitForSingleObjectEx
ExitThread
GetModuleHandleExW
VirtualAlloc
LoadLibraryExW
TlsFree
TlsSetValue
GetSystemInfo
LoadLibraryW
GetSystemDirectoryW
LocalFree
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
FormatMessageW
SetLastError
QueryFullProcessImageNameW
GetModuleFileNameW
UnmapViewOfFile
MapViewOfFile
CreateFileMappingW
VirtualProtect
CreateThread
GetCurrentProcess
DeleteCriticalSection
InitializeCriticalSectionEx
GetProcessHeap
HeapSize
HeapFree
HeapReAlloc
HeapAlloc
HeapDestroy
AddVectoredExceptionHandler
DecodePointer
GetLocaleInfoA
LoadLibraryA
GetProcAddress
GetModuleHandleA
FreeLibrary
QueryPerformanceFrequency
QueryPerformanceCounter
VerSetConditionMask
MultiByteToWideChar
TlsGetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
GetTickCount
FreeLibraryAndExitThread
GlobalFree
GlobalLock
RtlUnwindEx
RtlPcToFileHeader
RaiseException
OutputDebugStringW
GlobalUnlock
GlobalAlloc
Process32NextW
Process32FirstW
CreateToolhelp32Snapshot
RtlUnwind
SetConsoleTitleA
SetConsoleCtrlHandler
WideCharToMultiByte
MoveFileExW
lstrcmpiW
GetModuleHandleW
GetModuleFileNameA
GetWindowsDirectoryW
Sleep
SleepEx
InitializeSListHead
GetStartupInfoW
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
GetCPInfo
GetStringTypeW
LCMapStringEx
EncodePointer
WakeAllConditionVariable
GetSystemTimeAsFileTime
GetFileInformationByHandleEx
AreFileApisANSI
SetFileInformationByHandle
DeviceIoControl
GetLastError
CloseHandle
RemoveDirectoryW
DeleteFileW
CreateFileW
WriteConsoleW
ExitProcess
GetFullPathNameW
GetFileInformationByHandle
GetFileAttributesExW
FormatMessageA
GetLocaleInfoEx
GetCurrentThreadId
TryAcquireSRWLockExclusive
SleepConditionVariableSRW
GetCurrentDirectoryW
CreateDirectoryW
FindClose
FindFirstFileW
FindFirstFileExW
FindNextFileW
USER32.dll DestroyWindow
ShowWindow
SetLayeredWindowAttributes
GetAsyncKeyState
GetKeyNameTextA
MapVirtualKeyA
GetSystemMetrics
UpdateWindow
GetClientRect
GetCursorPos
ScreenToClient
GetDesktopWindow
MonitorFromPoint
BlockInput
OpenClipboard
CloseClipboard
CreateWindowExW
GetClipboardData
EmptyClipboard
GetKeyboardLayout
TrackMouseEvent
GetMessageExtraInfo
GetKeyState
GetCapture
SetCapture
ReleaseCapture
IsWindowUnicode
GetForegroundWindow
GetDC
ReleaseDC
SetCursorPos
SetCursor
ClientToScreen
LoadCursorW
SetProcessDPIAware
MessageBoxA
RegisterClassExW
SetClipboardData
TranslateMessage
UnregisterClassW
PeekMessageW
DefWindowProcW
PostQuitMessage
DispatchMessageW
GDI32.dll GetDeviceCaps
ADVAPI32.dll CryptHashData
CloseServiceHandle
ControlService
CreateServiceW
DeleteService
OpenSCManagerA
OpenSCManagerW
OpenProcessToken
AddAccessAllowedAce
GetLengthSid
GetTokenInformation
InitializeAcl
IsValidSid
RegCreateKeyExA
RegDeleteKeyA
SetSecurityInfo
CopySid
ConvertSidToStringSidA
CryptAcquireContextW
CryptReleaseContext
CryptGetHashParam
OpenServiceW
QueryServiceStatusEx
CryptCreateHash
CryptEncrypt
CryptImportKey
CryptDestroyKey
SystemFunction036
CryptDestroyHash
StartServiceW
SHELL32.dll ShellExecuteA
urlmon.dll URLDownloadToFileA
IMM32.dll ImmSetCompositionWindow
ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow
D3DCOMPILER_47.dll D3DCompile
dwmapi.dll DwmExtendFrameIntoClientArea
CRYPT32.dll CertOpenStore
CertCloseStore
CertEnumCertificatesInStore
CertFindCertificateInStore
CertFreeCertificateContext
PFXImportCertStore
CryptDecodeObjectEx
CertAddCertificateContextToStore
CertFindExtension
CertGetNameStringW
CryptQueryObject
CertCreateCertificateChainEngine
CertFreeCertificateChainEngine
CertGetCertificateChain
CertFreeCertificateChain
CryptStringToBinaryW
WS2_32.dll send
WSACloseEvent
WSACreateEvent
WSAEnumNetworkEvents
WSAEventSelect
WSAResetEvent
WSAWaitForMultipleEvents
getsockopt
WSAGetLastError
inet_pton
ntohs
WSASetLastError
inet_ntop
WSAStartup
WSACleanup
bind
connect
getpeername
closesocket
htons
recv
setsockopt
socket
WSAIoctl
__WSAFDIsSet
select
accept
htonl
listen
getaddrinfo
freeaddrinfo
recvfrom
sendto
ioctlsocket
gethostname
getsockname
SHLWAPI.dll PathFindFileNameW
PSAPI.DLL GetModuleInformation
USERENV.dll UnloadUserProfile
bcrypt.dll BCryptGenRandom

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b 🔍
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Sep-05 13:20:07
Version 0.0
SizeofData 1052
AddressOfRawData 0x19bed0
PointerToRawData 0x19aed0

TLS Callbacks

StartAddressOfRawData 0x14019c338
EndAddressOfRawData 0x14019c340
AddressOfIndex 0x1401b9910
AddressOfCallbacks 0x14015dc50
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1401b5600

RICH Header

XOR Key 0xa6d44855
Unmarked objects 0
C++ objects (33145) 209
C objects (33145) 38
ASM objects (33145) 24
253 (35207) 7
ASM objects (35207) 10
C objects (35207) 18
C++ objects (35207) 102
C objects (33523) 43
C objects (VS2022 Update 6 (17.6.4) compiler 32535) 129
C++ objects (35221) 5
Imports (33145) 35
Total imports 362
C++ objects (35228) 10
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.