| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Dec-14 19:00:54 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/65 (Scanned on 2026-08-09 04:16:43) |
APEX:
Malicious
tehtris: Generic.Malware |
| MD5 | f45c3869a0c859050a0ba1db15ea6c47 🔍 |
|---|---|
| SHA1 | 3b0c4561d822943f13d5012edda5852127ef618c 🔍 |
| SHA256 | 4ca75131274cd879ea411104e8e34619fb69b31117692f0fca3a4ffd4e040b0e 🔍 |
| SHA3 | b6c7d53ab9988a3bbbfc51a98c6901d925d47bdc44d748dd6112254d56ef3c6d 🔍 |
| SSDeep | 24576:LvoUqWtuY4bYhrMfjc0l59vGjbC3ZPMlk/p:sUqWxJ0l59OjO3ZE 🔍 |
| Imports Hash | b19a86c4732c58b9e5ad1f88256e2794 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x78 |
| e_cp | 0x1 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0 |
| e_ss | 0 |
| e_sp | 0 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x78 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2025-Dec-14 19:00:54 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xbfc00 |
| SizeOfInitializedData | 0x43000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000BF781 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x109000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | e5a83aa7d69195c2419954f755c3e230 🔍 |
|---|---|
| SHA1 | 22c28706eecbb8887431a4ae8f9adbabec66c0be 🔍 |
| SHA256 | dc8d87627428adf2f48192eb3010f6862614bfe17921ef49146e25030b212756 🔍 |
| SHA3 | f2aa00b63c1ed15dfc7380633aac9a1668d1b3c11c0650491f6eca8049f99ad2 🔍 |
| VirtualSize | 0xbfb8c |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0xbfc00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.62741 |
| MD5 | 9dfb8a57c9f11326ef2e2cbd10d39873 🔍 |
|---|---|
| SHA1 | 688e1fbb8e5dde2adcffa6357a5b1c6c6bf10b3d 🔍 |
| SHA256 | 9595c17766bd86515d2fec0ea0a82ad96b0b6833ef66acd5934e972137da24cc 🔍 |
| SHA3 | 78be9c2aaf001964286160cda93089143c07674c3a67eba0b919f6d449dd0344 🔍 |
| VirtualSize | 0x3835c |
| VirtualAddress | 0xc1000 |
| SizeOfRawData | 0x38400 |
| PointerToRawData | 0xc0000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.85138 |
| MD5 | 34b01ebe9f928bc8064e25b7f8087c63 🔍 |
|---|---|
| SHA1 | 723c0b838da2596768fa454dba6de6f2b3a0c4b6 🔍 |
| SHA256 | 357bf6211fa95aa290ca9a0fe8e32522b6a404ca3dd8fc319c8bc0d309538aa7 🔍 |
| SHA3 | ff9634248330ee2ab5770fad7b39a3faeb1d59e7663eb72368a9b5bca4d58b71 🔍 |
| VirtualSize | 0x30a8 |
| VirtualAddress | 0xfa000 |
| SizeOfRawData | 0x1a00 |
| PointerToRawData | 0xf8400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 2.7912 |
| MD5 | 8027e23d6e8742c9eab6fea5aff89d89 🔍 |
|---|---|
| SHA1 | 99123e05e5c7eb2239c407088eea0c23d7f7cfb7 🔍 |
| SHA256 | 65081ff27628855ad3fd2bbd33f4d2365c2faa6336c10bca1a654972382717df 🔍 |
| SHA3 | 0467e06a5c16bcca7181ae2bb826927c9b4cc17b04c5688c98e95db3574dcb5c 🔍 |
| VirtualSize | 0x2420 |
| VirtualAddress | 0xfe000 |
| SizeOfRawData | 0x2600 |
| PointerToRawData | 0xf9e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.88674 |
| MD5 | 8ad3a4b0204f2e16aa90bc4cd0d4ebce 🔍 |
|---|---|
| SHA1 | 9ba0ddc59f2b3e8c2dd062553449e72dd1b413d9 🔍 |
| SHA256 | 5980e208a49ad7fb2cf23cdc5273b9dc65fb09e50c7dfef60795f9068bcc2834 🔍 |
| SHA3 | ed8c2d0558861e3c918affd1d72f79c48dc1a335ccf06bc049d0ce8e72960171 🔍 |
| VirtualSize | 0x1758 |
| VirtualAddress | 0x101000 |
| SizeOfRawData | 0x1800 |
| PointerToRawData | 0xfc400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.87548 |
| MD5 | d472f5fb11a63e3ea320e238f2dba5a2 🔍 |
|---|---|
| SHA1 | d6508465f3c3c11b3b3698531fb6e198128eee0d 🔍 |
| SHA256 | 05a5283cbed2d8053ec3978b39a84dca8ecbc7abe6d7fd6c02375d2e8a782abd 🔍 |
| SHA3 | 5ba15319d1590040a6bc9e8e52357cebb62fe1604e58618e3156bae64514b5b2 🔍 |
| VirtualSize | 0x527c |
| VirtualAddress | 0x103000 |
| SizeOfRawData | 0x5400 |
| PointerToRawData | 0xfdc00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.66689 |
| KERNEL32.dll |
CloseHandle
CompareStringW CreateFileW CreateMutexW CreatePipe CreateProcessW CreateThread DecodePointer DeleteCriticalSection DeleteFileW DuplicateHandle EncodePointer EnterCriticalSection EnumSystemLocalesW ExitProcess FileTimeToSystemTime FindClose FindFirstFileExW FindFirstFileW FindNextFileW FlushFileBuffers FreeEnvironmentStringsW FreeLibrary GetACP GetCPInfo GetCommandLineA GetCommandLineW GetConsoleMode GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetDriveTypeW GetEnvironmentStringsW GetFileAttributesW GetFileInformationByHandle GetFileSize GetFileSizeEx GetFileType GetLastError GetLocaleInfoW GetModuleFileNameW GetModuleHandleExW GetModuleHandleW GetOEMCP GetProcAddress GetProcessHeap GetStartupInfoW GetStdHandle GetStringTypeW GetSystemTimeAsFileTime GetTempPathW GetTimeZoneInformation GetUserDefaultLCID GetVersionExW HeapAlloc HeapCreate HeapDestroy HeapFree HeapReAlloc HeapSize InitializeCriticalSection InitializeCriticalSectionAndSpinCount InitializeSListHead IsDebuggerPresent IsProcessorFeaturePresent IsValidCodePage IsValidLocale LCMapStringW LeaveCriticalSection LoadLibraryExW LoadLibraryW MulDiv MultiByteToWideChar PeekNamedPipe QueryPerformanceCounter RaiseException ReadConsoleW ReadFile RegisterWaitForSingleObject RemoveDirectoryW RtlUnwind SetCurrentDirectoryW SetEndOfFile SetEnvironmentVariableW SetFileAttributesW SetFilePointer SetFilePointerEx SetLastError SetStdHandle SetUnhandledExceptionFilter Sleep SystemTimeToTzSpecificLocalTime TerminateProcess TlsAlloc TlsFree TlsGetValue TlsSetValue UnhandledExceptionFilter UnregisterWait VerSetConditionMask VerifyVersionInfoW WaitForSingleObject WideCharToMultiByte WriteConsoleW WriteFile |
|---|---|
| USER32.dll |
AdjustWindowRectEx
BeginPaint CallWindowProcW CharLowerW ClientToScreen CreateAcceleratorTableW CreateWindowExW DefFrameProcW DefWindowProcW DestroyAcceleratorTable DestroyIcon DestroyMenu DestroyWindow DispatchMessageW DrawIconEx DrawMenuBar DrawStateW DrawTextW EnableMenuItem EnableWindow EndPaint EnumChildWindows EnumPropsExW EnumWindows FillRect GetActiveWindow GetClassNameW GetClientRect GetCursorPos GetDC GetFocus GetForegroundWindow GetIconInfo GetKeyState GetMenuItemCount GetMenuItemInfoW GetMessageW GetParent GetPropW GetSysColor GetSysColorBrush GetSystemMenu GetSystemMetrics GetWindow GetWindowLongW GetWindowRect GetWindowTextLengthW GetWindowTextW GetWindowThreadProcessId InvalidateRect IsChild IsIconic IsWindowEnabled IsWindowVisible IsZoomed KillTimer LoadCursorW LoadIconW MapWindowPoints MessageBoxW MoveWindow MsgWaitForMultipleObjects PeekMessageW PostMessageW RedrawWindow RegisterClassExW RegisterClassW RegisterWindowMessageW ReleaseCapture ReleaseDC RemovePropW ScreenToClient SendMessageW SetActiveWindow SetCapture SetClassLongW SetFocus SetForegroundWindow SetMenu SetPropW SetRect SetWindowLongW SetWindowPos ShowWindow SystemParametersInfoW TrackPopupMenu TranslateAcceleratorW TranslateMessage UnregisterClassW UpdateWindow ValidateRect |
| GDI32.dll |
BitBlt
CreateCompatibleBitmap CreateCompatibleDC CreateDCW CreateDIBSection CreateFontIndirectW CreateFontW CreatePatternBrush CreateRectRgn CreateRectRgnIndirect CreateSolidBrush DPtoLP DeleteDC DeleteObject EndDoc EndPage ExtSelectClipRgn GdiGetBatchLimit GdiSetBatchLimit GetClipRgn GetDIBits GetDeviceCaps GetMapMode GetObjectType GetObjectW GetPixel GetStockObject GetTextExtentPoint32W GetTextMetricsW OffsetViewportOrgEx SelectClipRgn SelectObject SetBkColor SetBkMode SetBrushOrgEx SetMapMode SetStretchBltMode SetTextAlign SetTextColor SetViewportOrgEx StartDocW StartPage StretchBlt TextOutW |
| COMDLG32.dll |
PrintDlgW
|
| ADVAPI32.dll |
RegCloseKey
RegDeleteKeyW RegDeleteValueW RegOpenKeyExW RegQueryInfoKeyW |
| ole32.dll |
CoCreateGuid
CoCreateInstance CoInitialize CoUninitialize OleInitialize OleUninitialize RevokeDragDrop StringFromGUID2 |
| SHELL32.dll |
SHGetFileInfoW
ShellExecuteExW ShellExecuteW Shell_NotifyIconW |
| COMCTL32.dll |
InitCommonControlsEx
|
| WINSPOOL.DRV |
#203
|
| SHLWAPI.dll |
PathFileExistsW
|
| gdiplus.dll |
GdipDeleteFont
GdipDeleteGraphics GdipDeleteMatrix GdipDeletePath GdipDeletePen GdipDeleteStringFormat GdipFree |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | Latin 1 / Western European |
| Size | 0x2e8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.93002 |
| MD5 | 5a7706050856119cf0503e126b3f2c23 🔍 |
| SHA1 | b0c369a90b4fb73929eaa5d8fc1677a917241799 🔍 |
| SHA256 | d1503be52f1c20fcd2c30482a3ccb12dc3f465e0a62824960f8de2031d17f018 🔍 |
| SHA3 | 5308107996bc5d716efc84e41e56e3ff0296f2f5a5be1492dddf6d6ad688b261 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | Latin 1 / Western European |
| Size | 0x128 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.49352 |
| MD5 | 62d64943b2668cfd39e2048f1e3efeb4 🔍 |
| SHA1 | ac59e477135fbf7016c5c5f17dc18f24010b0d94 🔍 |
| SHA256 | d7265c45fabef74c445305be8ae89cf3213d122641a3cc8c2448f2d5d67adba1 🔍 |
| SHA3 | a5112f2cf2b573c07121bb38a167c01a60b0f5ef4deb3ff951cb7fd8206f8782 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | Latin 1 / Western European |
| Size | 0x8a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.91542 |
| MD5 | 6485ee6e9296f554817d6204ee72b3da 🔍 |
| SHA1 | 52498f46011deffeb0c2bf1543df403b947f1ecf 🔍 |
| SHA256 | e866854c2565c494a156d915d853c02b215f1fd995677f7559d710642a74adf2 🔍 |
| SHA3 | d9ab009a8e071b9c9345da29352f6b39a71a6f2c9a9f88e19803281788d1b30f 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | Latin 1 / Western European |
| Size | 0x568 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.47677 |
| MD5 | 319b1094488389e5407d6d578c5904fc 🔍 |
| SHA1 | ff7dd6662245c74d026c3e50eb59dc1f15c427c6 🔍 |
| SHA256 | 139ce322088456b3fdbe6c6c500b9c2766dd9cf10485530bf786668387abc15c 🔍 |
| SHA3 | 89b919f49e0afdf6a576125b8f1ee9db0e3d1f35a67cb9a7fcad5cbe38dd9f09 🔍 |
| Type |
RT_GROUP_ICON
|
|---|---|
| Language | English - United States |
| Codepage | Latin 1 / Western European |
| Size | 0x3e |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 2.64576 |
| Detected Filetype | Icon file |
| MD5 | 78ac2e66598116da6e3e7ee439eea7e9 🔍 |
| SHA1 | 8939cc8392bac2ed76d190ebf8d4dca9cb1efc74 🔍 |
| SHA256 | effad6fefb36f30033a0d7771cc29e4ea5a1ac90f3fffc62ac7199523ab39775 🔍 |
| SHA3 | e25be03f578f085377254905cb542afb5d57c7a53950c01c4b01ca002d5bf2d4 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | Latin 1 / Western European |
| Size | 0x380 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.19855 |
| MD5 | 9f2ffbda24ffbf3f4da29043779feab9 🔍 |
| SHA1 | 7450d277175818f831fcb99df6f92c682ce198a7 🔍 |
| SHA256 | 8198b4d5b3866130b5c7a3429e840fd137bdaaaf7ca222feb9f717a59b42287e 🔍 |
| SHA3 | 7a1c5ea95afe9b384bb789be223c8828c59adee2a4064e803f409a17c8623530 🔍 |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x4fb040 |
| SEHandlerTable | 0 |
| SEHandlerCount | 0 |
No comments yet.