53e3b72f8eb13acf3cb69d4cb124e8dc64fc541555c3c95cc8003b8046853955

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2017-Aug-23 07:32:44
Detected languages English - United States

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • RUNDLL32.EXE
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryA
  • GetProcAddress
Can access the registry:
  • RegOpenKeyExA
Possibly launches other programs:
  • ShellExecuteA
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Interacts with services:
  • ControlService
  • CreateServiceA
  • DeleteService
  • OpenSCManagerA
  • OpenServiceA
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 112 bytes of data starting at offset 0x71400.
Safe VirusTotal score: 0/67 (Scanned on 2026-08-24 10:52:36) All the AVs think this file is safe.

Hashes

MD5 6a6505b2413d2c7b16c6d059448db9e5 🔍
SHA1 dfe6c6b6051c26326a12dc9d0d5701cb4728266c 🔍
SHA256 53e3b72f8eb13acf3cb69d4cb124e8dc64fc541555c3c95cc8003b8046853955 🔍
SHA3 b01c93419052d702bca2701c8fac9d0a6e41829ef0da48d16ccf292dad5975cc 🔍
SSDeep 6144:JIeh4+TOKGuTSuXCJ6AtCoZPhGL/TnJ+z5rsxQhsCI9t/tk7MP:jpPTxXihA+zBhsC2Z 🔍
Imports Hash ed928bd060b03bab412d37a11b9d26a0 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2017-Aug-23 07:32:44
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 12.0
SizeOfCode 0x3c000
SizeOfInitializedData 0x35000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000003C078 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x7e000
SizeOfHeaders 0x400
Checksum 0x76d77
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 9c10a952d246bd14a67e564e81a521c7 🔍
SHA1 7e65a36da18d76e13a12419908803ebb370d4b75 🔍
SHA256 ddace92d860e1ed8cc269eebfc90b09a26cfe7f2f339ab6f0581f62a00f3a3ee 🔍
SHA3 ff8e0ce26be515e82a1b940fb3c1e54f8fa0b956d94e2dd0867ee841d2007747 🔍
VirtualSize 0x3bf15
VirtualAddress 0x1000
SizeOfRawData 0x3c000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.17049

.rdata

MD5 33512a691421ba80009a79faaa6bb88e 🔍
SHA1 0159478ab78dcab0e2a0bd0569b9de5c8ce2c629 🔍
SHA256 6724b691d53fc870ad80ece0cd249373bb60d148911ec669a309b793519e4f82 🔍
SHA3 acd77f0e41f5b00c7c00fb720471f3a36eaa94171de30be0a9f8a8ec3f7686d2 🔍
VirtualSize 0x1c96e
VirtualAddress 0x3d000
SizeOfRawData 0x1ca00
PointerToRawData 0x3c400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.10444

.data

MD5 afd9f11cb784110557b1d185f4178429 🔍
SHA1 7cff0cf5926d08e7eed64bc7bab4b895a17f6d8d 🔍
SHA256 001e4feead269ff29678a5f0e244a7fb355e78b8015e1867a1c24f55f49d3fa2 🔍
SHA3 4539bfa4ec51ae6b901bb97b34f284f9b64c762b684b7a712ff5addf9145c76c 🔍
VirtualSize 0x1d360
VirtualAddress 0x5a000
SizeOfRawData 0x13a00
PointerToRawData 0x58e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.74335

.pdata

MD5 ebb6fee06d488f95acce55cac1f575fc 🔍
SHA1 133a705e3fcc289969d176c1e13c3b626ce03856 🔍
SHA256 6918f3842bb3381cfbba3d068f5ba5e9fc7a1d95281131647ab07c341466d87f 🔍
SHA3 968d7e9c553940aa6cccdb516e96c3966e40d6a5904b9f0e76f0a959be67ec82 🔍
VirtualSize 0x27c0
VirtualAddress 0x78000
SizeOfRawData 0x2800
PointerToRawData 0x6c800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.54864

.rsrc

MD5 199500df301ada9a51b00529079f5516 🔍
SHA1 4005a27f56cf3b436d17dde8000e1de3cc3f82a8 🔍
SHA256 1a113272a3b16b236dd9bbdc5ceaa91e5a8b5086273302303adc94f9204d497b 🔍
SHA3 5e233843277858a3113039c87d55327e4eeaeedee309a028baf479e3b06dcb43 🔍
VirtualSize 0x488
VirtualAddress 0x7b000
SizeOfRawData 0x600
PointerToRawData 0x6f000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.40702

.reloc

MD5 c54bc3eb67e0685b11ecf6176bcaede8 🔍
SHA1 969fb7d223575a304ed89d35ac39de4a397a44e9 🔍
SHA256 e4478227226c2dfc24dda8e910e3af5e86500246054e3f44bb2bf987e5e02af4 🔍
SHA3 19d6a5c97bbcea3f813906f505081d9163d694cff311e77a1484a3ad7ef9f0f8 🔍
VirtualSize 0x1d10
VirtualAddress 0x7c000
SizeOfRawData 0x1e00
PointerToRawData 0x6f600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.56817

Imports

KERNEL32.dll ReadConsoleInputA
SetConsoleMode
GetCommandLineA
QueryPerformanceCounter
GetCurrentProcessId
GetFullPathNameA
CloseHandle
Sleep
GetCurrentProcess
GetSystemDirectoryA
GetWindowsDirectoryA
CreateFileA
DeviceIoControl
GetModuleFileNameA
GetModuleHandleA
GetCurrentDirectoryA
DeleteFileA
GetLastError
CreateMutexA
SetThreadExecutionState
SetConsoleCtrlHandler
ReadFile
WriteFile
CreateNamedPipeA
CreateThread
LocalFree
EncodePointer
DecodePointer
EnterCriticalSection
LeaveCriticalSection
GetSystemTimeAsFileTime
GetTimeZoneInformation
ExitProcess
GetModuleHandleExW
AreFileApisANSI
MultiByteToWideChar
WideCharToMultiByte
HeapFree
RtlLookupFunctionEntry
RtlUnwindEx
HeapAlloc
RtlPcToFileHeader
RaiseException
GetEnvironmentStringsW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
SetLastError
GetCurrentThreadId
DeleteCriticalSection
FlushFileBuffers
GetConsoleCP
GetConsoleMode
IsDebuggerPresent
IsProcessorFeaturePresent
GetStdHandle
GetFileType
GetStartupInfoW
RtlCaptureContext
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
InitializeCriticalSectionAndSpinCount
TerminateProcess
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetModuleHandleW
GetModuleFileNameW
LoadLibraryExW
GetProcessHeap
ReadConsoleW
SetFilePointerEx
HeapReAlloc
GetStringTypeW
CompareStringW
LCMapStringW
SetStdHandle
WriteConsoleW
OutputDebugStringW
CreateFileW
SetEnvironmentVariableA
SetEndOfFile
GetVersionExA
LoadLibraryA
GetProcAddress
HeapSize
FreeLibrary
FreeEnvironmentStringsW
SHELL32.dll ShellExecuteA
USER32.dll DefWindowProcA
DispatchMessageA
TranslateMessage
GetMessageA
RegisterClassExA
MessageBoxA
BlockInput
SystemParametersInfoA
ExitWindowsEx
CreateWindowExA
wsprintfA
ADVAPI32.dll ControlService
RegOpenKeyExA
LookupPrivilegeValueA
AdjustTokenPrivileges
OpenProcessToken
CloseServiceHandle
CreateServiceA
DeleteService
OpenSCManagerA
OpenServiceA
StartServiceA

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x42f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.15309
MD5 52f23bcd31edd80adb18ca867808eac4 🔍
SHA1 767a7cd9c7a8420c6b41bf6d14c94e4137c49e42 🔍
SHA256 d5bcce227ccce5d2fc89cc01c0facadbb718a4d227b4fdfc59f57ea6107bda10 🔍
SHA3 dae65ab7b63c8bb97e89672aa125a681ecfa72661ec92650828c24f2e58dd46f 🔍

Version Info

TLS Callbacks

Load Configuration

Size 0x70
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14006d1f0

RICH Header

XOR Key 0x96a9d37e
Unmarked objects 0
199 (41118) 2
C++ objects (20806) 52
C objects (20806) 144
ASM objects (20806) 12
209 (65501) 1
Imports (65501) 9
Total imports 127
C++ objects (VS2013 build 21005) 44
Linker (VS2013 build 21005) 1

Errors

Leave a comment

No comments yet.