33c316676d2e69c8640a836bf006c30ade08a353f1803d281b885a4a4ed14520

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jun-28 11:42:49
TLS Callbacks 2 callback(s) detected.

Plugin Output

Suspicious PEiD Signature: HQR data file
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to internet browsers:
  • IEXPLORE.EXE
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • Bytecode.info
  • Logger.info
  • NullTranslations.info
  • activestate.com
  • bugs.python.org
  • cam.ac.uk
  • cl.cam.ac.uk
  • code.activestate.com
  • docs.python.org
  • eGenix.com
  • egenix.com
  • en.wikipedia.org
  • flags.ru
  • freedesktop.org
  • ftp.python.org
  • ftp://dkuug.dk
  • gmail.com
  • gustaebel.de
  • http://code.activestate.com
  • http://code.activestate.com/recipes/577452-a-memoize-decorator-for-instance-methods/
  • http://json.org
  • http://www.cl.cam.ac.uk
  • http://www.cl.cam.ac.uk/
  • http://www.iana.org
  • http://www.iana.org/time-zones/repository/tz-link.html
  • http://www.phys.uu.nl
  • http://www.phys.uu.nl/
  • http://www.w3.org
  • http://www.w3.org/TR/NOTE-datetime
  • http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd
  • http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
  • https://bugs.python.org
  • https://bugs.python.org/issue42195.
  • https://docs.python.org
  • https://docs.python.org/3.11/library/binascii.html#binascii.a2b_base64
  • https://en.wikipedia.org
  • https://en.wikipedia.org/wiki/Cache_replacement_policies#Least_recently_used_
  • https://importlib-resources.readthedocs.io
  • https://importlib-resources.readthedocs.io/en/latest/using.html#migrating-from-legacy
  • https://nuitka.net
  • https://packaging.python.org
  • https://packaging.python.org/specifications/entry-points/
  • https://peps.python.org
  • https://peps.python.org/pep-0205/
  • https://www.ibm.com
  • https://www.ibm.com/
  • https://www.python.org
  • https://www.python.org/download/releases/2.3/mro/.
  • lemburg.com
  • logger.info
  • logging.info
  • nuitka.net
  • packaging.python.org
  • peps.python.org
  • phys.uu.nl
  • pitrou.net
  • python.org
  • red-dove.com
  • redivi.com
  • samba.org
  • skippinet.com.au
  • sprymix.com
  • sweetapp.com
  • wikipedia.org
  • www.cl.cam.ac.uk
  • www.iana.org
  • www.ibm.com
  • www.phys.uu.nl
  • www.python.org
  • www.w3.org
  • zen.co.uk
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Malicious VirusTotal score: 22/70 (Scanned on 2026-08-15 13:51:03) AVG: Win64:MalwareX-gen [Misc]
Antiy-AVL: GrayWare/Win32.Wacapew
Avast: Win64:MalwareX-gen [Misc]
Avira: TR/W64.Agent
Cylance: Unsafe
Cynet: Malicious (score: 99)
ESET-NOD32: Python/Packed.Nuitka_AGen.LN suspicious application
F-Secure: Trojan.TR/W64.Agent
Fortinet: Riskware/Application
Google: Detected
K7AntiVirus: Adware ( 006d9bef1 )
K7GW: Adware ( 006d9bef1 )
MaxSecure: Trojan.Malware.8328611.susgen
McAfeeD: ti!33C316676D2E
Microsoft: Adware:Python/Multiverze!rfn
Sophos: Generic Reputation PUA (PUA)
Symantec: ML.Attribute.HighConfidence
TrellixENS: Artemis!1920F2817E8F
TrendMicro: Trojan.Win32.MULTIVERZE.USBLHA26
TrendMicro-HouseCall: Trojan.Win32.MULTIVERZE.USBLHA26
Varist: W64/ABRisk.NPSN-3340
alibabacloud: VirTool:Python/Packed.Nuitka_AGen.LT

Hashes

MD5 1920f2817e8fef2140a3fa88fe592caa 🔍
SHA1 eeb542d569d0c2a6f542d274b955ff53a2b06121 🔍
SHA256 33c316676d2e69c8640a836bf006c30ade08a353f1803d281b885a4a4ed14520 🔍
SHA3 c064e04f512571d77ce8392e6e1ce8a0a280b7daa7aa01a6914c310324752664 🔍
SSDeep 98304:XOjKcZ4/76okLDQz2YQoxLFA+wFrkF4a21geu:WS76tLDQv 🔍
Imports Hash 156e34e84cd3125e1656da8b16d79697 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 12
TimeDateStamp 2026-Jun-28 11:42:49
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 2.0
SizeOfCode 0x88000
SizeOfInitializedData 0x4fcc00
SizeOfUninitializedData 0x3e00
AddressOfEntryPoint 0x00000000000012EF (Section: .text)
BaseOfCode 0x1000
ImageBase 0x2e9a30000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x590000
SizeOfHeaders 0x400
Checksum 0x58cf8a
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 4647f088c2e0b20d211130af15f6dd42 🔍
SHA1 ae03de0e948ea0280af1a67b79d7ba3aaec40209 🔍
SHA256 f3bf4b0f29186063e2f44690caec4f80f77e1500f8b579367e5557f68f4c9aeb 🔍
SHA3 3db0ee3cc3048b34fee0f4d4f76261335749bcec815b343721efb50e74549393 🔍
VirtualSize 0x87ee0
VirtualAddress 0x1000
SizeOfRawData 0x88000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.12506

.data

MD5 d42770417f7b04d18ed68ccc00529c2a 🔍
SHA1 9f4a46dc720251e8ee7f70924b32f9dc4055556b 🔍
SHA256 b0cb6cb9e90e5fecbc6ecac3ccd3c8d7a32350386765c3b768245584d58b73cd 🔍
SHA3 26dd7aa771e6d413b53b9e1dd32d6d1cf70f7aa87c2ad63ab9509027254f3527 🔍
VirtualSize 0x6370
VirtualAddress 0x89000
SizeOfRawData 0x6400
PointerToRawData 0x88400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.37506

.rdata

MD5 986903618d5fedc67d47df891bb505a4 🔍
SHA1 6f3104df67a97ed34c2bcb573c8e52ee66e78669 🔍
SHA256 ef3067df014bfebe2bb91879d885997bec50643b74f03f0ec7badb31e2a74649 🔍
SHA3 a8e35a12718cd2e3ef016a738a56db14abf2306182d9e896819ae4a4055ed077 🔍
VirtualSize 0x4eccd8
VirtualAddress 0x90000
SizeOfRawData 0x4ece00
PointerToRawData 0x8e800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.54083

.eh_fram

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x4
VirtualAddress 0x57d000
SizeOfRawData 0x200
PointerToRawData 0x57b600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.pdata

MD5 0ab9c424609ccccf585cb324e0026b78 🔍
SHA1 49199f132a7faa02474d0273315ef0a8af2abdb0 🔍
SHA256 0ab51035f317df8ad9bb5c87793d1ec09a4880d652753aa023f6079bf30eaffb 🔍
SHA3 6c2d97fb2f082e66d1498322e1c991378afd8a0648cbc2daafc6c144129a228e 🔍
VirtualSize 0x2280
VirtualAddress 0x57e000
SizeOfRawData 0x2400
PointerToRawData 0x57b800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.62007

.xdata

MD5 3105fcf0c5456a65e8997c993613bbf8 🔍
SHA1 4c7013e4319ddf5da40c79b4cb64b1381de2a5d8 🔍
SHA256 51e43c09cc42c9b499e6d273cadb73e74439580df3325d47674d1cdf6aea6b71 🔍
SHA3 fb07e3627903062f7281bb7783281524c454ff6b210bf80d22a7f238369823a8 🔍
VirtualSize 0x2484
VirtualAddress 0x581000
SizeOfRawData 0x2600
PointerToRawData 0x57dc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.42294

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍
VirtualSize 0x3ca0
VirtualAddress 0x584000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.edata

MD5 b514306b02c95b2136b9927e2fefaab3 🔍
SHA1 e737fd5c6432ceaea1ed3ae1ddb1f3829cfd4b1f 🔍
SHA256 f080a47205bc54aa0e53c29eab93aac918b02c617b693fc1edfa2bd1d06ac8fe 🔍
SHA3 cab4a8ffb09ef5e0afef30342c2c5521c8a642ba2663c92557f1974516c7cfd3 🔍
VirtualSize 0x4f
VirtualAddress 0x588000
SizeOfRawData 0x200
PointerToRawData 0x580200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.946945

.idata

MD5 2cb88d72a727cfe6daa1e7f1c6867ab0 🔍
SHA1 39cecdd7b202075534a2aa709f16321b700b97ab 🔍
SHA256 d5b2e493319c331f0b966cee2d84373c9f2ccd3986b114d27fd102a79441d1b5 🔍
SHA3 b67a87c495cae38c720852889869bfdf61b08a549cae8a3d8d5cc61f1587fc08 🔍
VirtualSize 0x3888
VirtualAddress 0x589000
SizeOfRawData 0x3a00
PointerToRawData 0x580400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.73254

.tls

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x10
VirtualAddress 0x58d000
SizeOfRawData 0x200
PointerToRawData 0x583e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 a2b90b59cc49bb647b196ae9eebaaf68 🔍
SHA1 9b0c610fca02e1958f367fa03262e5e4a1f5c1fb 🔍
SHA256 f88cceaa21ba672864f115045ebda121675de54ae2546a28e175580ba42a613c 🔍
SHA3 17c83aa9dd78611e296546d5ea45fb56b8b9e87badda4f7f772ff2c32659f46a 🔍
VirtualSize 0x54c
VirtualAddress 0x58e000
SizeOfRawData 0x600
PointerToRawData 0x584000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.53314

.reloc

MD5 f04fd42a8655c43839121b56d02ede2f 🔍
SHA1 7b1a5ef57a36fc4bc5c559fbf6895e2a166ebdeb 🔍
SHA256 be80336978f4825d80d571f5b4639befc2ba47a78b3315396e38960fc199c7bf 🔍
SHA3 60c92065f55badbd070d01e51428fe623e6c2035c64360643765217b42d9bde7 🔍
VirtualSize 0x8c8
VirtualAddress 0x58f000
SizeOfRawData 0xa00
PointerToRawData 0x584600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.00142

Imports

KERNEL32.dll CloseHandle
CopyFileW
CreateFileMappingW
CreateFileW
DeleteCriticalSection
DeleteFileW
EnterCriticalSection
FormatMessageA
FreeLibrary
GetCurrentProcessId
GetEnvironmentVariableW
GetFileSize
GetLastError
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleExA
GetProcAddress
GetShortPathNameW
GetSystemTimeAsFileTime
GetTempPathW
InitializeCriticalSection
IsDBCSLeadByteEx
LeaveCriticalSection
LoadLibraryA
LoadLibraryExW
MapViewOfFile
MultiByteToWideChar
QueryPerformanceCounter
ReadFile
SetConsoleCtrlHandler
SetDllDirectoryW
SetEnvironmentVariableW
SetErrorMode
Sleep
TlsGetValue
UnmapViewOfFile
VirtualProtect
VirtualQuery
WideCharToMultiByte
WriteFile
msvcrt.dll ___lc_codepage_func
___mb_cur_max_func
__argc
__iob_func
__setusermatherr
__wargv
_amsg_exit
_errno
_initterm
_lock
_unlock
_wcsicmp
_wcsdup
_wcstoi64
_wcstoui64
_wrename
_wtoi
abort
calloc
exit
fflush
fgetwc
fprintf
fputc
fputwc
free
fwprintf
iswctype
ldexp
localeconv
malloc
mbstowcs
memcmp
memcpy
memset
puts
raise
realloc
signal
strchr
strcmp
strerror
strlen
strncmp
strncpy
strrchr
towlower
ungetwc
vfprintf
wcscmp
wcslen
wcsncmp
wcstol
wcstoul
SHELL32.dll SHGetFolderPathW
USER32.dll CallWindowProcA
CreateWindowExW
DefWindowProcW
DestroyWindow
DispatchMessageW
GetDesktopWindow
GetMessageW
GetParent
GetWindowLongPtrW
GetWindowRect
GetWindowTextW
LoadCursorA
PostMessageA
PostQuitMessage
RegisterClassW
SetFocus
SetWindowLongPtrW
TranslateMessage
UnregisterClassW
python311.dll PyObject_GC_Del
_PyObject_GC_Resize
_PyObject_GC_NewVar
PyIter_Send
PyIter_Next
PyObject_GetIter
PyObject_IsSubclass
PyObject_IsInstance
PyMapping_Check
PySequence_Contains
PySequence_List
PySequence_Tuple
PySequence_InPlaceConcat
PySequence_Check
PyNumber_ToBase
PyNumber_Float
PyNumber_Long
PyNumber_AsSsize_t
PyNumber_Invert
PyNumber_Negative
PyNumber_InPlaceAdd
PyNumber_InPlaceLshift
PyNumber_InPlaceOr
PyNumber_FloorDivide
PyNumber_Add
PyNumber_Subtract
PyBuffer_Release
PyObject_GetBuffer
PyObject_DelItem
PyObject_SetItem
PyObject_LengthHint
PyBool_Type
_Py_FalseStruct
_Py_TrueStruct
_PyByteArray_empty_string
PyByteArray_Type
PyByteArray_FromStringAndSize
PyByteArray_FromObject
PyBytes_Type
_PyBytes_Resize
PyBytes_FromString
PyObject_CallFunctionObjArgs
PyObject_CallMethodObjArgs
PyObject_CallFunction
PyObject_Call
PyCapsule_New
PyMethod_Type
PyCode_Type
PyCode_Addr2Line
PyCode_NewWithPosOnlyArgs
PyComplex_Type
PyComplex_FromDoubles
PyDictItems_Type
PyDictKeys_Type
PyDictValues_Type
PyDict_Type
PyDict_DelItemString
PyDict_SetItemString
PyDict_GetItemString
PyDict_Merge
PyDict_MergeFromSeq2
PyDict_Clear
PyDict_DelItem
PyDict_SetItem
PyDict_GetItem
_PyDict_NewPresized
_PyDict_MaybeUntrack
PyDict_New
PyExc_ImportWarning
PyExc_Exception
PyExc_KeyError
PyExc_RuntimeError
PyExc_UnboundLocalError
PyExc_KeyboardInterrupt
PyExc_AttributeError
PyExc_ZeroDivisionError
PyExc_ValueError
PyExc_BaseException
PyExc_OverflowError
PyExc_FileExistsError
PyExc_StopIteration
PyExc_StopAsyncIteration
PyExc_TypeError
PyExc_NameError
PyExc_IndexError
PyExc_ImportError
PyExc_SystemError
PyExc_GeneratorExit
PyExc_FileNotFoundError
PyFloat_Type
PyFloat_FromString
PyFloat_FromDouble
PyFrame_Type
PyFunction_Type
Py_GenericAliasType
Py_GenericAlias
_PyAsyncGenWrappedValue_Type
PyCoro_Type
PyGen_Type
PyAsyncGen_Type
PySeqIter_Type
PyCallIter_Type
PyList_Type
PyList_Sort
PyList_Append
PyList_New
PyLong_Type
PyLong_FromUnicodeObject
PyLong_FromString
PyLong_FromSsize_t
PyLong_AsSsize_t
PyLong_AsLong
PyLong_AsLongAndOverflow
_PyLong_Copy
_PyLong_New
PyCFunction_Type
PyCMethod_New
PyModule_Type
PyModuleDef_Type
PyModule_GetState
PyModule_GetDef
PyModule_GetFilenameObject
PyModule_GetName
PyModule_GetDict
PyModule_ExecDef
PyModule_FromDefAndSpec2
PyModule_NewObject
_Py_NoneStruct
_Py_NotImplementedStruct
_Py_Dealloc
PyCallable_Check
PyObject_IsTrue
PyObject_GenericSetAttr
PyObject_SelfIter
PyObject_SetAttr
PyObject_GetAttr
PyObject_SetAttrString
PyObject_GetAttrString
PyObject_RichCompareBool
PyObject_RichCompare
PyObject_Str
PyObject_Repr
_PyObject_New
PyObject_InitVar
PyObject_Free
PyObject_Realloc
PyMem_Free
PyMem_Malloc
PyMem_GetAllocator
PyRange_Type
PyFrozenSet_Type
PySet_Type
_PySet_NextEntry
PySet_Add
PySet_Contains
PyFrozenSet_New
PySet_New
PySlice_Type
_Py_EllipsisObject
PyEllipsis_Type
PyStructSequence_InitType
PyStructSequence_New
PyTuple_Type
_PyTuple_MaybeUntrack
PyTuple_New
PyBaseObject_Type
PyType_Type
PyType_Ready
_PyType_Lookup
PyType_IsSubtype
PyUnicode_Type
PyUnicode_InternInPlace
PyUnicode_Format
PyUnicode_RPartition
PyUnicode_Partition
PyUnicode_Substring
PyUnicode_Concat
PyUnicode_RichCompare
PyUnicode_Join
PyUnicode_FindChar
PyUnicode_Find
PyUnicode_DecodeUTF8
PyUnicode_GetLength
PyUnicode_AsUTF8
PyUnicode_FromEncodedObject
PyUnicode_FromOrdinal
PyUnicode_AsWideCharString
PyUnicode_FromFormat
PyUnicode_FromString
PyUnicode_FromStringAndSize
PyUnicode_FromWideChar
_PyUnicode_Ready
PyUnicode_New
_PyWeakref_CallableProxyType
_PyWeakref_ProxyType
_PyWeakref_RefType
PyObject_ClearWeakRefs
_PyWeakref_ClearRef
_PyWarnings_Init
PyErr_WarnEx
PyEval_GetFuncName
PyEval_EvalCodeEx
_PyEval_EvalFrameDefault
Py_MakePendingCalls
PyEval_RestoreThread
PyEval_SaveThread
PyEval_AcquireThread
PyErr_WriteUnraisable
_PyErr_WriteUnraisableMsg
PyErr_Format
_PyErr_Format
PyErr_SetFromErrno
PyErr_NoMemory
PyErr_BadArgument
_PyErr_FormatFromCause
_PyErr_ChainStackItem
_PyErr_NormalizeException
PyErr_ExceptionMatches
PyErr_SetNone
PyImport_FrozenModules
_PyArg_NoKeywords
PyArg_UnpackTuple
PyArg_ParseTupleAndKeywords
PyArg_ParseTuple
PyImport_ImportModule
PyImport_ImportFrozenModule
PyImport_ExecCodeModuleEx
PyImport_ExecCodeModule
_PyImport_FixupExtensionObject
PyImport_GetModuleDict
Py_NoSiteFlag
Py_NoUserSiteDirectory
Py_DontWriteBytecodeFlag
Py_DebugFlag
Py_BytesWarningFlag
Py_VerboseFlag
Py_OptimizeFlag
Py_UTF8Mode
Py_InteractiveFlag
Py_InspectFlag
Py_IgnoreEnvironmentFlag
Py_FrozenFlag
PyConfig_SetArgv
PyConfig_SetString
_PyConfig_InitCompatConfig
PyWideStringList_Append
PyStatus_Exception
PyMarshal_ReadObjectFromString
_Py_PackageContext
Py_BuildValue
PyOS_snprintf
Py_SetProgramName
_PyRuntime
Py_Exit
Py_ExitStatusException
Py_InitializeFromConfig
_PyRuntime_Initialize
Py_CompileStringExFlags
PyErr_Print
PyErr_PrintEx
PySys_SetArgv
PySys_SetObject
PySys_GetObject
PyTraceBack_Type

Delayed Imports

run_code

Ordinal 1
Address 0x711c0

1

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4f1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.27584
MD5 9175a1fabff80fec23018fdfc1dc274b 🔍
SHA1 be8f32edef4e9f4aa514fa34f36ca9ee0204139b 🔍
SHA256 94b146eac0a80f5089ac9e57303515ddf9087d9d88fd4d47f27df8f3cf14cbb4 🔍
SHA3 934768e038a5727d347f31840aaab3de69c96e1d4bca3c9e726bae6be020edf3 🔍

Version Info

TLS Callbacks

StartAddressOfRawData 0x2e9fbd000
EndAddressOfRawData 0x2e9fbd008
AddressOfIndex 0x2e9fb71e0
AddressOfCallbacks 0x2e9faccb0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks 0x00000002E9AA3980
0x00000002E9AA3A39

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0!
Leave a comment

No comments yet.