471a8508b1a58345b982fe1007ce490b00b62de8bd0f743cc151408cd329fe61

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Feb-02 11:00:45

Plugin Output

Info Cryptographic algorithms detected in the binary: Uses constants related to RC5 or RC6
Uses known Mersenne Twister constants
Suspicious The PE contains functions most legitimate programs don't use. Interacts with the certificate store:
  • CertSaveStore
  • CertAddCertificateContextToStore
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 ecceac7cd2cdb03bc33221cdb82fed46
SHA1 52144ac8e1677a056fe1ffb600e13b8da6b6b421
SHA256 471a8508b1a58345b982fe1007ce490b00b62de8bd0f743cc151408cd329fe61
SHA3 54707ef6f773bc969a25739ecd0275d605e66d0e1aa21c3e5fd50297ee7e8376
SSDeep 393216:nUijOpJLi1JpQHzW0Nq9QEI3nqC/z1y4h7O6Ys7iqsxjOp/O8il/IKNOiNV/F5:nbELspQTW0NfEg84h7G6VsxjmPil/II
Imports Hash db49ea7d9d142c5c40164bf0d3de444b

DOS Header

e_magic MZ
e_cblp 0x78
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x78

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 5
TimeDateStamp 2024-Feb-02 11:00:45
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x43200
SizeOfInitializedData 0x164ac00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000034D78 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x1891000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 f34e45670664632ec6c1c30970e259f5
SHA1 eced9c30bc17d02109aa072643ac8a4c078dfff8
SHA256 25a045bde5699c2014a13a80bfba8a6704f7b4d4de649b7e3811337f722f5923
SHA3 f59a1c8e654687eb108523bcab7667289b8694c05af04b2f05a9f701aa4edcf0
VirtualSize 0x430e1
VirtualAddress 0x1000
SizeOfRawData 0x43200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.40968

.rdata

MD5 d19738b2e615183bcf4ce6658c0b4705
SHA1 1e7b945719f9681970708e28e12b6b55a4030bf6
SHA256 c3035d1dd8f8012e01c67c38ff77f8fd905e2cb524de5f74d4155c1f6dcd406a
SHA3 8ecf8e6e81f006e215de762408b955a997951906835840ad7ee123c2f1a601f2
VirtualSize 0x2364
VirtualAddress 0x45000
SizeOfRawData 0x2400
PointerToRawData 0x43600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.35686

.data

MD5 e9237388f1ceea7e4455b8e62932e711
SHA1 bdfb6970fe9ad434bb78af92171a1c7ca985d726
SHA256 c231ee8afdeaf1b805dfec311b466187a5f1e7ad0d02f2076159955278cdf189
SHA3 a8ca770e068bbf8939f35abdc348fa370ba8951638a1d0d680c6fa146b81dcd0
VirtualSize 0x1845f84
VirtualAddress 0x48000
SizeOfRawData 0x1646000
PointerToRawData 0x45a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.99882

.pdata

MD5 53a675496fc80fe29ed6de3445f2b9eb
SHA1 fb78716e9b503b3f7a212601c84810dded0a906b
SHA256 3723a4f8b288893806279cb2b6546c3c073bba783eed471624cbc1484ed2f76a
SHA3 d568965d4844ee380c1663fcad2cd7d8e6155280e2ab223e72d164267d47dc65
VirtualSize 0x1d94
VirtualAddress 0x188e000
SizeOfRawData 0x1e00
PointerToRawData 0x168ba00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.27696

.reloc

MD5 0eb9ae04af87308df42abac837b6d600
SHA1 96b29248ed2f3190d6c92c4786c729db474cc6f8
SHA256 e544c88b694056cb3a498066359810529ca0309f201dd520515954a1ef2b3e6d
SHA3 feaad9ee7fc862fa2e8604697827baab6c60271eb0bd11444fe691502b306963
VirtualSize 0x910
VirtualAddress 0x1890000
SizeOfRawData 0xa00
PointerToRawData 0x168d800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.25432

Imports

api-ms-win-crt-runtime-l1-1-0.dll _cexit
_invoke_watson
_initterm_e
_register_thread_local_exe_atexit_callback
exit
_register_onexit_function
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_get_narrow_winmain_command_line
_c_exit
_exit
terminate
_initterm
_set_app_type
_seh_filter_exe
_crt_atexit
_seh_filter_exe
exit
KERNEL32.dll GetStartupInfoW
SetUnhandledExceptionFilter
GetSystemTimeAsFileTime
GetCurrentProcess
RtlLookupFunctionEntry
TerminateProcess
QueryPerformanceCounter
GetModuleHandleW
IsProcessorFeaturePresent
RtlVirtualUnwind
GetCurrentProcessId
GetCurrentThreadId
RtlCaptureContext
IsDebuggerPresent
UnhandledExceptionFilter
InitializeSListHead
GetModuleHandleW
TerminateProcess
MSVCP140.dll ?_Random_device@std@@YAIXZ
VCRUNTIME140.dll memset
__current_exception
_CxxThrowException
__std_exception_copy
__C_specific_handler
memmove
__std_exception_destroy
memcpy
__current_exception_context
__C_specific_handler
__current_exception_context
memcpy
__C_specific_handler
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
malloc
_callnewh
free
_callnewh
CRYPT32.dll CertControlStore
CertCloseStore
CertSaveStore
CertAddCertificateContextToStore
CertCreateCertificateContext
CertEnumCertificatesInStore
CertGetCertificateContextProperty
CertDuplicateCertificateContext
CertCreateCRLContext
CertFreeCRLContext
CertFindCRLInStore
CertFindCRLInStore
CertControlStore
CertFindCRLInStore
RPCRT4.dll UuidFromStringA
UuidEqual
api-ms-win-crt-stdio-l1-1-0.dll __p__commode
_set_fmode
_set_fmode
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
__setusermatherr
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
_configthreadlocale

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14168d780

RICH Header

Errors

Leave a comment

No comments yet.