56beddd81c1a471cb9f3cea2866f27d892e95d3dd33f603cc24c56e85b5c3273

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-25 13:24:48
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.
Debug artifacts C:\Program Files (x86)\Microsoft\Edge\Application\installer\MicrosoftEdgeUpdate.pdb
CompanyName
FileDescription
FileVersion
InternalName
LegalCopyright
OriginalFilename
ProductName
ProductVersion

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Info Libraries used to perform cryptographic operations: Microsoft's Cryptography API
Suspicious The PE contains functions most legitimate programs don't use. Possibly launches other programs:
  • CreateProcessA
Uses Microsoft's cryptographic API:
  • CryptBinaryToStringA
  • CryptStringToBinaryA
Can create temporary files:
  • CreateFileA
  • GetTempPathA
Has Internet access capabilities:
  • WinHttpAddRequestHeaders
  • WinHttpCloseHandle
  • WinHttpConnect
  • WinHttpOpen
  • WinHttpOpenRequest
  • WinHttpQueryDataAvailable
  • WinHttpQueryHeaders
  • WinHttpReadData
  • WinHttpReceiveResponse
  • WinHttpSendRequest
  • WinHttpSetOption
  • WinHttpSetTimeouts
Enumerates local disk drives:
  • GetVolumeInformationA
Can take screenshots:
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Malicious The PE is possibly a dropper. Resource 740 is possibly compressed or encrypted.
Resource 2001 detected as a PE Executable.
Resources amount for 98.4247% of the executable.
Malicious The PE's digital signature is invalid. Signer: Microsoft Windows
Issuer: Microsoft Windows Production PCA 2011
The file was modified after it was signed.
Malicious VirusTotal score: 19/70 (Scanned on 2026-07-31 11:36:51) ALYac: Gen:Variant.Yogi.33607
AVG: Win64:MalwareX-gen [Misc]
AhnLab-V3: Trojan/Win.MalwareX-gen.R785986
Antiy-AVL: Trojan[Packed]/Win64.VMProtect
Arcabit: Trojan.Yogi.D8347
Avast: Win64:MalwareX-gen [Misc]
BitDefender: Gen:Variant.Yogi.33607
Bkav: W32.Malware.345057C
CTX: exe.unknown.yogi
DeepInstinct: MALICIOUS
ESET-NOD32: Win64/Packed.VMProtect.AM suspicious application
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Yogi.33607 (B)
GData: Gen:Variant.Yogi.33607
Kaspersky: Trojan.Win64.Agent.smfizr
MicroWorld-eScan: Gen:Variant.Yogi.33607
Microsoft: Trojan:Win32/Wacatac.B!ml
Trapmine: malicious.moderate.ml.score
VIPRE: Gen:Variant.Yogi.33607

Hashes

MD5 22cae549ecf04f49622c7e2c172f54f5
SHA1 499557bd3cde572b802caee3cc60ff96bb419395
SHA256 56beddd81c1a471cb9f3cea2866f27d892e95d3dd33f603cc24c56e85b5c3273
SHA3 0cb69a65127708e4f2723f151bf8519eeb60394cb9266804e7751dde23c9091d
SSDeep 393216:5VbAd3iXO71So89+2nnEyZhOnWOs9Ip9vylkorwojgzFVeusI+WR9/Knwmm:5ZRO71So89+2nnEDnWDCp90kWTjg/eAN
Imports Hash e1ae91eccc71625bdacb2aef0d012279

DOS Header

e_magic MZ
e_cblp 0x78
e_cp 0x1
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x78

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Jul-25 13:24:48
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x34000
SizeOfInitializedData 0x1192600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001000 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x11cc000
SizeOfHeaders 0x400
Checksum 0x11cc922
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 7042210d02141bb07bda0b30cfdbd17f
SHA1 1b354efe25a8f4d90e222ab2f848e398b21a63d7
SHA256 c7bdf287bb573928ba6ea30b13300005a09b6081a901253379b4d0595975c0e4
SHA3 cfd5bbb95bafd8dc4fce3de5d22b4da7c339d258a184b9fc80a40a05fdd8935a
VirtualSize 0x33eb6
VirtualAddress 0x1000
SizeOfRawData 0x34000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.35985

.rdata

MD5 8f46c4dcfc725809daa0d0ed90a4917e
SHA1 e48cc6ac53cfd3d7173a3e65fa1b0b1f15920d0a
SHA256 8932d311d9e69086c2099b6a0c5e1a96b51a1cca675d65f7cfdd595f7722302c
SHA3 49de0de5db7a9143953515defb113eb62a268a93ff9720f6d8978b89a406de3e
VirtualSize 0xc800
VirtualAddress 0x35000
SizeOfRawData 0xc800
PointerToRawData 0x34400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.91111

.data

MD5 0229e01fde00bf232022aff3349d0602
SHA1 941146c85558c8f9683ea8b48da1a90b84becd92
SHA256 d08f4dff1cae342b47eaf8a3974461bc8580ef87df0c8e467adfba556d09a12b
SHA3 756b23826f259f43bee50d0612d3f9c411241d85bd43d7e575f4c43aa59d51e2
VirtualSize 0x1091
VirtualAddress 0x42000
SizeOfRawData 0x400
PointerToRawData 0x40c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.09121

.pdata

MD5 ca5e4de1887bde9c5916337eb1a75668
SHA1 48da846e5a886a480e47b93612a44b96acb47d1f
SHA256 3f2fa3fb222eeb83285fc223201998658c27e9c18d0c2edde629c9419bfced68
SHA3 859670172c28f6e36668e36a042a6be22efa6055a98299fc9e07c9e4ea603df3
VirtualSize 0x162c
VirtualAddress 0x44000
SizeOfRawData 0x1800
PointerToRawData 0x41000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.14905

.tls

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x20
VirtualAddress 0x46000
SizeOfRawData 0x200
PointerToRawData 0x42800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 6efcb3e107ec15401df71576cc5df556
SHA1 c019ca19fac3573eb672ce70b5dded5f00b786bb
SHA256 e35b26e61485a38c29fb976d196a6af2b4e304c03440d73f5142901f3f6d6c09
SHA3 b3ed523d74c640acf2ad1ec237df343bb44bc131ac3b977052b563c99ac73b4e
VirtualSize 0x1183210
VirtualAddress 0x47000
SizeOfRawData 0x1183400
PointerToRawData 0x42a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.96439

.reloc

MD5 cec3c025aa1a6821578f75bad4a06f54
SHA1 fa1367d232e281e54d0089374346acfacebcdae8
SHA256 033e9f32114d82eb70300189fe2851da23a0e070ded542434344f259ca2f9cbf
SHA3 a3f93589b80c3462cc386496eaba93a85fcd513fbb465706e6751b4aa2146ce4
VirtualSize 0xbfc
VirtualAddress 0x11cb000
SizeOfRawData 0xc00
PointerToRawData 0x11c5e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.41415

Imports

USER32.dll GetDC
GetSystemMetrics
ReleaseDC
wsprintfA
SHELL32.dll ShellExecuteExA
CRYPT32.dll CryptBinaryToStringA
CryptStringToBinaryA
WINHTTP.dll WinHttpAddRequestHeaders
WinHttpCloseHandle
WinHttpConnect
WinHttpOpen
WinHttpOpenRequest
WinHttpQueryDataAvailable
WinHttpQueryHeaders
WinHttpReadData
WinHttpReceiveResponse
WinHttpSendRequest
WinHttpSetOption
WinHttpSetTimeouts
gdiplus.dll GdipAlloc
GdipCloneImage
GdipCreateBitmapFromHBITMAP
GdipDisposeImage
GdipFree
GdipGetImageEncoders
GdipGetImageEncodersSize
GdipSaveImageToStream
GdiplusShutdown
GdiplusStartup
GDI32.dll BitBlt
CreateCompatibleBitmap
CreateCompatibleDC
DeleteDC
DeleteObject
SelectObject
ole32.dll CreateStreamOnHGlobal
bcrypt.dll BCryptCloseAlgorithmProvider
BCryptCreateHash
BCryptDecrypt
BCryptDestroyHash
BCryptDestroyKey
BCryptFinishHash
BCryptGenerateSymmetricKey
BCryptGetProperty
BCryptHashData
BCryptOpenAlgorithmProvider
BCryptSetProperty
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
__p__commode
__p__fmode
__stdio_common_vfprintf
__stdio_common_vfwprintf
__stdio_common_vsprintf
__stdio_common_vswprintf
_fileno
_setmode
fflush
fputc
fputwc
setvbuf
api-ms-win-crt-string-l1-1-0.dll isspace
memset
strcat
strcmp
strlen
strncmp
strnlen
wcscmp
wcslen
wcsnlen
api-ms-win-crt-runtime-l1-1-0.dll _assert
__p___argc
__p___argv
__p__acmdln
_cexit
_configure_narrow_argv
_crt_atexit
_errno
_exit
_initialize_narrow_environment
_initterm
_initterm_e
_seh_filter_exe
_set_app_type
_set_invalid_parameter_handler
abort
exit
strerror
api-ms-win-crt-locale-l1-1-0.dll ___lc_codepage_func
___mb_cur_max_func
_configthreadlocale
localeconv
api-ms-win-crt-heap-l1-1-0.dll _aligned_free
_aligned_malloc
_set_new_mode
calloc
free
malloc
realloc
api-ms-win-crt-private-l1-1-0.dll memchr
memcmp
memcpy
memmove
strstr
api-ms-win-crt-utility-l1-1-0.dll rand
srand
ADVAPI32.dll GetUserNameA
KERNEL32.dll AcquireSRWLockExclusive
CloseHandle
CopyFileA
CreateDirectoryA
CreateEventW
CreateFileA
CreateMutexA
CreateProcessA
DeleteCriticalSection
EnterCriticalSection
ExitProcess
FindResourceA
GetCommandLineA
GetComputerNameA
GetEnvironmentVariableA
GetLastError
GetModuleFileNameA
GetModuleHandleA
GetModuleHandleW
GetProcAddress
GetStartupInfoA
GetSystemInfo
GetSystemTimeAsFileTime
GetTempPathA
GetTickCount
GetVolumeInformationA
GlobalMemoryStatusEx
InitializeCriticalSection
IsDBCSLeadByte
LeaveCriticalSection
LoadResource
LockResource
MultiByteToWideChar
RaiseException
ReleaseMutex
ReleaseSRWLockExclusive
RtlCaptureContext
RtlLookupFunctionEntry
RtlRestoreContext
RtlUnwindEx
RtlVirtualUnwind
SetErrorMode
SetThreadErrorMode
SetUnhandledExceptionFilter
SizeofResource
Sleep
SleepConditionVariableSRW
TlsGetValue
VirtualProtect
VirtualQuery
WaitForSingleObject
WakeAllConditionVariable
WideCharToMultiByte
WriteFile
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
api-ms-win-crt-environment-l1-1-0.dll __p__environ
getenv
api-ms-win-crt-convert-l1-1-0.dll mbrtowc
strtof
wcrtomb
api-ms-win-crt-filesystem-l1-1-0.dll _lock_file
_unlock_file

Delayed Imports

740

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x3200
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99111
MD5 ae4ffb58bb0c3d416cb14efd3301249d
SHA1 0e7633e655df61313c31730059e1c43ac1c1182b
SHA256 ea15ef66dae749b2bfd1bd6a4bc266a9d50b0fbe91faf32ba7042c731e09f7ab
SHA3 e599ca4de35dc1969aaa25e7d07af62752886930c594431d70a2b1a4ca8a96c9

908

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x9b844
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.97492
MD5 e29e019c63afba2eefb6e8a999d4712f
SHA1 b507edf17c6e0da05fa79ea73f0bfd00de3bc04e
SHA256 ab2b7b103f246d669d52c11121928819eb52678bc3ce3329b6b3d0128798a4cb
SHA3 97816258fc6fd2f760003785aa4dd95e2fb4a1330e7ccf18a5d6f2adbc1a901a

2001

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x10e4000
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99781
Detected Filetype PE Executable
MD5 fee0ee78c8e2f650d231cb85d52354fa
SHA1 d43e00a7e636fd52661998cc6a997daeeeb2d6ab
SHA256 66408b745468a3100f9324eebb664d95b0ae4f9dac74056005beac98d7950fa3
SHA3 bfed4e2c8793d9c306e35434c334dbc026717f066a1458784c794e8907782635

2002

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x36
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.07812
MD5 c5c430e8b646a6e95442decb02fed2a5
SHA1 944e8dda9f7688b8973260215aeff0cc53d01bd2
SHA256 3a1cb116362d4663d3c675002e7da8f59d0932263e2e8f66a9fed1ad7dd8ed3a
SHA3 be1276b4875e7ca0b68ee97d6be1996b7d7cba8e00154c1579d816b7efbaaf7c

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x214
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.06758
MD5 c89130b71121794d17072c7a3fa63853
SHA1 ae6a0a50603191dc1ea83a59ba813fb7a6c82abc
SHA256 4032b5b1cf0a96a70a3b9d947a2fdb581fc775d8a5a406cce3330c857caf3792
SHA3 9d6e027a9fb4a5ea80c626c4510a13cc7338f81bceefe251ba6a0b9549b8393a

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x3f5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.21357
MD5 2b5f9867876b28d9214b8c2c3a239530
SHA1 e897b0a92d3886aa5a83f2d8889dc80defda8d12
SHA256 b1b0f916d7ae183076092afb5a7010db174774b0bd95bea23d829868a72f1c68
SHA3 e67480e55bd94c71d1431210c8dbadd0797bc099b81a35f29b22f0042b781cd7

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 10.0.26200.1
ProductVersion 10.0.26200.1
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName
FileDescription
FileVersion (#2)
InternalName
LegalCopyright
OriginalFilename
ProductName
ProductVersion (#2)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
SizeofData 108
AddressOfRawData 0x41778
PointerToRawData 0x40b78
Referenced File C:\Program Files (x86)\Microsoft\Edge\Application\installer\MicrosoftEdgeUpdate.pdb

TLS Callbacks

StartAddressOfRawData 0x140046000
EndAddressOfRawData 0x140046018
AddressOfIndex 0x140042314
AddressOfCallbacks 0x14003d2b0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x000000014000D720
0x000000014000D7A0

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0

RICH Header

Errors

Leave a comment

No comments yet.