4ca75131274cd879ea411104e8e34619fb69b31117692f0fca3a4ffd4e040b0e

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Dec-14 19:00:54
Detected languages English - United States

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryW
Can access the registry:
  • RegCloseKey
  • RegDeleteKeyW
  • RegDeleteValueW
  • RegOpenKeyExW
  • RegQueryInfoKeyW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Enumerates local disk drives:
  • GetDriveTypeW
Can take screenshots:
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Suspicious VirusTotal score: 2/65 (Scanned on 2026-08-09 04:16:43) APEX: Malicious
tehtris: Generic.Malware

Hashes

MD5 f45c3869a0c859050a0ba1db15ea6c47 🔍
SHA1 3b0c4561d822943f13d5012edda5852127ef618c 🔍
SHA256 4ca75131274cd879ea411104e8e34619fb69b31117692f0fca3a4ffd4e040b0e 🔍
SHA3 b6c7d53ab9988a3bbbfc51a98c6901d925d47bdc44d748dd6112254d56ef3c6d 🔍
SSDeep 24576:LvoUqWtuY4bYhrMfjc0l59vGjbC3ZPMlk/p:sUqWxJ0l59OjO3ZE 🔍
Imports Hash b19a86c4732c58b9e5ad1f88256e2794 🔍

DOS Header

e_magic MZ
e_cblp 0x78
e_cp 0x1
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x78

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 6
TimeDateStamp 2025-Dec-14 19:00:54
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0xbfc00
SizeOfInitializedData 0x43000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000BF781 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x109000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e5a83aa7d69195c2419954f755c3e230 🔍
SHA1 22c28706eecbb8887431a4ae8f9adbabec66c0be 🔍
SHA256 dc8d87627428adf2f48192eb3010f6862614bfe17921ef49146e25030b212756 🔍
SHA3 f2aa00b63c1ed15dfc7380633aac9a1668d1b3c11c0650491f6eca8049f99ad2 🔍
VirtualSize 0xbfb8c
VirtualAddress 0x1000
SizeOfRawData 0xbfc00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.62741

.rdata

MD5 9dfb8a57c9f11326ef2e2cbd10d39873 🔍
SHA1 688e1fbb8e5dde2adcffa6357a5b1c6c6bf10b3d 🔍
SHA256 9595c17766bd86515d2fec0ea0a82ad96b0b6833ef66acd5934e972137da24cc 🔍
SHA3 78be9c2aaf001964286160cda93089143c07674c3a67eba0b919f6d449dd0344 🔍
VirtualSize 0x3835c
VirtualAddress 0xc1000
SizeOfRawData 0x38400
PointerToRawData 0xc0000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.85138

.data

MD5 34b01ebe9f928bc8064e25b7f8087c63 🔍
SHA1 723c0b838da2596768fa454dba6de6f2b3a0c4b6 🔍
SHA256 357bf6211fa95aa290ca9a0fe8e32522b6a404ca3dd8fc319c8bc0d309538aa7 🔍
SHA3 ff9634248330ee2ab5770fad7b39a3faeb1d59e7663eb72368a9b5bca4d58b71 🔍
VirtualSize 0x30a8
VirtualAddress 0xfa000
SizeOfRawData 0x1a00
PointerToRawData 0xf8400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.7912

.eh_fram

MD5 8027e23d6e8742c9eab6fea5aff89d89 🔍
SHA1 99123e05e5c7eb2239c407088eea0c23d7f7cfb7 🔍
SHA256 65081ff27628855ad3fd2bbd33f4d2365c2faa6336c10bca1a654972382717df 🔍
SHA3 0467e06a5c16bcca7181ae2bb826927c9b4cc17b04c5688c98e95db3574dcb5c 🔍
VirtualSize 0x2420
VirtualAddress 0xfe000
SizeOfRawData 0x2600
PointerToRawData 0xf9e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.88674

.rsrc

MD5 8ad3a4b0204f2e16aa90bc4cd0d4ebce 🔍
SHA1 9ba0ddc59f2b3e8c2dd062553449e72dd1b413d9 🔍
SHA256 5980e208a49ad7fb2cf23cdc5273b9dc65fb09e50c7dfef60795f9068bcc2834 🔍
SHA3 ed8c2d0558861e3c918affd1d72f79c48dc1a335ccf06bc049d0ce8e72960171 🔍
VirtualSize 0x1758
VirtualAddress 0x101000
SizeOfRawData 0x1800
PointerToRawData 0xfc400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.87548

.reloc

MD5 d472f5fb11a63e3ea320e238f2dba5a2 🔍
SHA1 d6508465f3c3c11b3b3698531fb6e198128eee0d 🔍
SHA256 05a5283cbed2d8053ec3978b39a84dca8ecbc7abe6d7fd6c02375d2e8a782abd 🔍
SHA3 5ba15319d1590040a6bc9e8e52357cebb62fe1604e58618e3156bae64514b5b2 🔍
VirtualSize 0x527c
VirtualAddress 0x103000
SizeOfRawData 0x5400
PointerToRawData 0xfdc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.66689

Imports

KERNEL32.dll CloseHandle
CompareStringW
CreateFileW
CreateMutexW
CreatePipe
CreateProcessW
CreateThread
DecodePointer
DeleteCriticalSection
DeleteFileW
DuplicateHandle
EncodePointer
EnterCriticalSection
EnumSystemLocalesW
ExitProcess
FileTimeToSystemTime
FindClose
FindFirstFileExW
FindFirstFileW
FindNextFileW
FlushFileBuffers
FreeEnvironmentStringsW
FreeLibrary
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentDirectoryW
GetCurrentProcess
GetCurrentProcessId
GetCurrentThread
GetCurrentThreadId
GetDriveTypeW
GetEnvironmentStringsW
GetFileAttributesW
GetFileInformationByHandle
GetFileSize
GetFileSizeEx
GetFileType
GetLastError
GetLocaleInfoW
GetModuleFileNameW
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
GetTempPathW
GetTimeZoneInformation
GetUserDefaultLCID
GetVersionExW
HeapAlloc
HeapCreate
HeapDestroy
HeapFree
HeapReAlloc
HeapSize
InitializeCriticalSection
InitializeCriticalSectionAndSpinCount
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
IsValidLocale
LCMapStringW
LeaveCriticalSection
LoadLibraryExW
LoadLibraryW
MulDiv
MultiByteToWideChar
PeekNamedPipe
QueryPerformanceCounter
RaiseException
ReadConsoleW
ReadFile
RegisterWaitForSingleObject
RemoveDirectoryW
RtlUnwind
SetCurrentDirectoryW
SetEndOfFile
SetEnvironmentVariableW
SetFileAttributesW
SetFilePointer
SetFilePointerEx
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
Sleep
SystemTimeToTzSpecificLocalTime
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
UnhandledExceptionFilter
UnregisterWait
VerSetConditionMask
VerifyVersionInfoW
WaitForSingleObject
WideCharToMultiByte
WriteConsoleW
WriteFile
USER32.dll AdjustWindowRectEx
BeginPaint
CallWindowProcW
CharLowerW
ClientToScreen
CreateAcceleratorTableW
CreateWindowExW
DefFrameProcW
DefWindowProcW
DestroyAcceleratorTable
DestroyIcon
DestroyMenu
DestroyWindow
DispatchMessageW
DrawIconEx
DrawMenuBar
DrawStateW
DrawTextW
EnableMenuItem
EnableWindow
EndPaint
EnumChildWindows
EnumPropsExW
EnumWindows
FillRect
GetActiveWindow
GetClassNameW
GetClientRect
GetCursorPos
GetDC
GetFocus
GetForegroundWindow
GetIconInfo
GetKeyState
GetMenuItemCount
GetMenuItemInfoW
GetMessageW
GetParent
GetPropW
GetSysColor
GetSysColorBrush
GetSystemMenu
GetSystemMetrics
GetWindow
GetWindowLongW
GetWindowRect
GetWindowTextLengthW
GetWindowTextW
GetWindowThreadProcessId
InvalidateRect
IsChild
IsIconic
IsWindowEnabled
IsWindowVisible
IsZoomed
KillTimer
LoadCursorW
LoadIconW
MapWindowPoints
MessageBoxW
MoveWindow
MsgWaitForMultipleObjects
PeekMessageW
PostMessageW
RedrawWindow
RegisterClassExW
RegisterClassW
RegisterWindowMessageW
ReleaseCapture
ReleaseDC
RemovePropW
ScreenToClient
SendMessageW
SetActiveWindow
SetCapture
SetClassLongW
SetFocus
SetForegroundWindow
SetMenu
SetPropW
SetRect
SetWindowLongW
SetWindowPos
ShowWindow
SystemParametersInfoW
TrackPopupMenu
TranslateAcceleratorW
TranslateMessage
UnregisterClassW
UpdateWindow
ValidateRect
GDI32.dll BitBlt
CreateCompatibleBitmap
CreateCompatibleDC
CreateDCW
CreateDIBSection
CreateFontIndirectW
CreateFontW
CreatePatternBrush
CreateRectRgn
CreateRectRgnIndirect
CreateSolidBrush
DPtoLP
DeleteDC
DeleteObject
EndDoc
EndPage
ExtSelectClipRgn
GdiGetBatchLimit
GdiSetBatchLimit
GetClipRgn
GetDIBits
GetDeviceCaps
GetMapMode
GetObjectType
GetObjectW
GetPixel
GetStockObject
GetTextExtentPoint32W
GetTextMetricsW
OffsetViewportOrgEx
SelectClipRgn
SelectObject
SetBkColor
SetBkMode
SetBrushOrgEx
SetMapMode
SetStretchBltMode
SetTextAlign
SetTextColor
SetViewportOrgEx
StartDocW
StartPage
StretchBlt
TextOutW
COMDLG32.dll PrintDlgW
ADVAPI32.dll RegCloseKey
RegDeleteKeyW
RegDeleteValueW
RegOpenKeyExW
RegQueryInfoKeyW
ole32.dll CoCreateGuid
CoCreateInstance
CoInitialize
CoUninitialize
OleInitialize
OleUninitialize
RevokeDragDrop
StringFromGUID2
SHELL32.dll SHGetFileInfoW
ShellExecuteExW
ShellExecuteW
Shell_NotifyIconW
COMCTL32.dll InitCommonControlsEx
WINSPOOL.DRV #203
SHLWAPI.dll PathFileExistsW
gdiplus.dll GdipDeleteFont
GdipDeleteGraphics
GdipDeleteMatrix
GdipDeletePath
GdipDeletePen
GdipDeleteStringFormat
GdipFree

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.93002
MD5 5a7706050856119cf0503e126b3f2c23 🔍
SHA1 b0c369a90b4fb73929eaa5d8fc1677a917241799 🔍
SHA256 d1503be52f1c20fcd2c30482a3ccb12dc3f465e0a62824960f8de2031d17f018 🔍
SHA3 5308107996bc5d716efc84e41e56e3ff0296f2f5a5be1492dddf6d6ad688b261 🔍

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.49352
MD5 62d64943b2668cfd39e2048f1e3efeb4 🔍
SHA1 ac59e477135fbf7016c5c5f17dc18f24010b0d94 🔍
SHA256 d7265c45fabef74c445305be8ae89cf3213d122641a3cc8c2448f2d5d67adba1 🔍
SHA3 a5112f2cf2b573c07121bb38a167c01a60b0f5ef4deb3ff951cb7fd8206f8782 🔍

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.91542
MD5 6485ee6e9296f554817d6204ee72b3da 🔍
SHA1 52498f46011deffeb0c2bf1543df403b947f1ecf 🔍
SHA256 e866854c2565c494a156d915d853c02b215f1fd995677f7559d710642a74adf2 🔍
SHA3 d9ab009a8e071b9c9345da29352f6b39a71a6f2c9a9f88e19803281788d1b30f 🔍

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.47677
MD5 319b1094488389e5407d6d578c5904fc 🔍
SHA1 ff7dd6662245c74d026c3e50eb59dc1f15c427c6 🔍
SHA256 139ce322088456b3fdbe6c6c500b9c2766dd9cf10485530bf786668387abc15c 🔍
SHA3 89b919f49e0afdf6a576125b8f1ee9db0e3d1f35a67cb9a7fcad5cbe38dd9f09 🔍

0

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x3e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.64576
Detected Filetype Icon file
MD5 78ac2e66598116da6e3e7ee439eea7e9 🔍
SHA1 8939cc8392bac2ed76d190ebf8d4dca9cb1efc74 🔍
SHA256 effad6fefb36f30033a0d7771cc29e4ea5a1ac90f3fffc62ac7199523ab39775 🔍
SHA3 e25be03f578f085377254905cb542afb5d57c7a53950c01c4b01ca002d5bf2d4 🔍

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x380
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.19855
MD5 9f2ffbda24ffbf3f4da29043779feab9 🔍
SHA1 7450d277175818f831fcb99df6f92c682ce198a7 🔍
SHA256 8198b4d5b3866130b5c7a3429e840fd137bdaaaf7ca222feb9f717a59b42287e 🔍
SHA3 7a1c5ea95afe9b384bb789be223c8828c59adee2a4064e803f409a17c8623530 🔍

Version Info

TLS Callbacks

Load Configuration

Size 0xc0
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x4fb040
SEHandlerTable 0
SEHandlerCount 0

RICH Header

Errors

Leave a comment

No comments yet.