58d63d63ba58859fbdcc888842856d054bdf551945c0d8d03dc9489d6df24c05

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-May-23 17:09:55
Detected languages English - United States
Turkish - Turkey

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • casedieresis.cn
  • casetilde.cn
  • commaaccentright.cn
  • cyrillictail.cn
  • cyrillictic.cn
  • github.com
  • http://scripts.sil.org
  • http://scripts.sil.org/OFLThis
  • http://scripts.sil.org/OFLhttps
  • https://github.com
  • https://rsms.me
  • koronisaccentleft.cn
  • marsnev.com
  • scripts.sil.org
  • tildecross.cn
  • www.marsnev.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses known Mersenne Twister constants
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Can access the registry:
  • RegQueryValueExA
  • RegCloseKey
  • RegOpenKeyExA
Possibly launches other programs:
  • CreateProcessA
  • CreateProcessW
Has Internet access capabilities:
  • URLDownloadToFileA
  • InternetCloseHandle
  • InternetOpenA
  • InternetOpenUrlA
  • InternetReadFile
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 37/69 (Scanned on 2026-08-30 11:27:49) APEX: Malicious
AVG: Win32:MalwareX-gen [Pws]
Avast: Win32:MalwareX-gen [Pws]
Avira: TR/W32.MalwareX
Bkav: W32.Malware.F5290591
CTX: exe.trojan.malwarex
CrowdStrike: win/malicious_confidence_90% (W)
Cylance: Unsafe
Cynet: Malicious (score: 100)
DeepInstinct: MALICIOUS
Elastic: malicious (high confidence)
F-Secure: Trojan.TR/W32.MalwareX
Fortinet: W32/PossibleThreat
Google: Detected
Gridinsoft: Trojan.Win32.Wacatac.cl
Kaspersky: UDS:DangerousObject.Multi.Generic
Kingsoft: Win32.Troj.Unknown.a
Lionic: Virus.Win32.Expiro.mBpk
Malwarebytes: Malware.AI.3958242890
MaxSecure: Trojan.Malware.338151687.susgen
McAfeeD: Real Protect-LS!3ED2C582C731
Microsoft: Trojan:Win32/Wacatac.B!ml
Paloalto: generic.ml
Rising: Spyware.ClipBanker!8.12E6C (CLOUD)
Sangfor: Trojan.Win32.Save.a
SentinelOne: Static AI - Suspicious PE
Skyhigh: BehavesLike.Win32.Generic.th
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
Trapmine: malicious.moderate.ml.score
TrellixENS: Artemis!3ED2C582C731
TrendMicro: Trojan.Win32.ZYX.USBLEP26
TrendMicro-HouseCall: Trojan.Win32.ZYX.USBLEP26
VBA32: Trojan.Phonzy
Varist: W32/ABTrojan.CKBD-1106
alibabacloud: Trojan:Win/Wacatac.B9nj
huorong: TrojanSpy/ClipBanker.w

Hashes

MD5 3ed2c582c7310b2926ab8ddcb1fadd2f 🔍
SHA1 20102cc731a607b572000cb9f9c093f0d6604790 🔍
SHA256 58d63d63ba58859fbdcc888842856d054bdf551945c0d8d03dc9489d6df24c05 🔍
SHA3 e0a87d2632d20a4c44ea808551ee275890e8cbee174885c5fd41d0d4bca939dd 🔍
SSDeep 24576:C4SCctUXaZ9EzOUoIyGfoJVNbjZO0R5P3rjD3gPH2EF1:CInXaZXHzGfmBOw3rjDZs 🔍
Imports Hash a02d1a01e57c45f7af584da73e9fff85 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 6
TimeDateStamp 2026-May-23 17:09:55
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x5a400
SizeOfInitializedData 0xc2e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0003334B (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x5c000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x122000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 88e3dc60031700ea8a8baf7640252651 🔍
SHA1 20685c5e5c9243bf46c2e9124f1a1c7115c0fef5 🔍
SHA256 b49822f3d79087ee5868ad899973ed3bfd592188d2c19460454dfd67acec45fc 🔍
SHA3 e0498073d2e4f5714b1242289438bd5a73e33e67736eae8d5a63fd1cd1557fbd 🔍
VirtualSize 0x5a23e
VirtualAddress 0x1000
SizeOfRawData 0x5a400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.72609

.rdata

MD5 6be950c805ab20e7ad8389c579af66b1 🔍
SHA1 6a191ffbcb18c28e8f1e84baf0099f565a31cc03 🔍
SHA256 47546ea94f7356b217b4e125db556c8f415c083429b001104a8a1713112b5f87 🔍
SHA3 66aae87d8295f80b60c6da1d8a4802f2e3da1c8f1bbbcb08462cddd1672e8a48 🔍
VirtualSize 0x6d0ac
VirtualAddress 0x5c000
SizeOfRawData 0x6d200
PointerToRawData 0x5a800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.00426

.data

MD5 89be1c2842581f1792115b6f0e40ef64 🔍
SHA1 75427386048dc57324a3727ad18fab052e235ce3 🔍
SHA256 3a4e9445f7356749631f6d7308ec8b32c089e430d2f249a55a833fdb8568dcce 🔍
SHA3 048d0bd454738cfd162a4f98bda4fadba10d125bf4f7b5b745216913b6a91668 🔍
VirtualSize 0x50f38
VirtualAddress 0xca000
SizeOfRawData 0x4e400
PointerToRawData 0xc7a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.26748

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x80
VirtualAddress 0x11b000
SizeOfRawData 0x200
PointerToRawData 0x115e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 4ef0140df71978600fab377393e349ee 🔍
SHA1 11ef431f7e2201159de8d044e3e45f9083819ea2 🔍
SHA256 96aee14c12205e42489d206a275605cca015fc2106cc89c72857bb7383989f6e 🔍
SHA3 0b34a312bdd80bf9a680ce3dcc3b41591ed2c3e4bcdcb80ba481d4cd99b7d4dc 🔍
VirtualSize 0x1338
VirtualAddress 0x11c000
SizeOfRawData 0x1400
PointerToRawData 0x116000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.47356

.reloc

MD5 e45c50388dd8d82512b80b02bd98b1ff 🔍
SHA1 5012be13b97f7faae19a235b107d557926ba7284 🔍
SHA256 20c0ddc9e6d8b72ccf91bde3809ce632b1cdb8b902f99cc1f3601f8387743cce 🔍
SHA3 597ff5bf7bf15338d09872b47563fea5ac273486007d86c69394318dc77fee98 🔍
VirtualSize 0x3498
VirtualAddress 0x11e000
SizeOfRawData 0x3600
PointerToRawData 0x117400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.58196

Imports

ADVAPI32.dll RegQueryValueExA
RegCloseKey
RegOpenKeyExA
KERNEL32.dll QueryPerformanceFrequency
QueryPerformanceCounter
GetModuleFileNameA
lstrcatA
Sleep
GetFileAttributesA
CloseHandle
SetFileAttributesA
CreateProcessA
WriteConsoleW
HeapSize
CreateFileW
SetStdHandle
GlobalUnlock
GetProcessHeap
SetEnvironmentVariableW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
GetCommandLineA
GetOEMCP
GetACP
IsValidCodePage
FindNextFileW
FindFirstFileExW
FindClose
HeapReAlloc
GetFileAttributesExW
GlobalLock
GlobalFree
GlobalAlloc
CreateProcessW
GetExitCodeProcess
WaitForSingleObject
DeleteFileW
GetFileSizeEx
GetConsoleOutputCP
FlushFileBuffers
EnumSystemLocalesW
GetUserDefaultLCID
IsValidLocale
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
EncodePointer
DecodePointer
MultiByteToWideChar
WideCharToMultiByte
LCMapStringEx
GetStringTypeW
GetCPInfo
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlUnwind
RaiseException
GetLastError
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
ExitProcess
GetModuleHandleExW
ReadFile
GetModuleFileNameW
GetStdHandle
WriteFile
SetFilePointerEx
GetConsoleMode
ReadConsoleW
GetFileType
HeapAlloc
HeapFree
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
VirtualProtect
CompareStringW
LCMapStringW
GetLocaleInfoW
SetEndOfFile
USER32.dll SetClipboardData
GetClipboardData
EmptyClipboard
CloseClipboard
OpenClipboard
GetCursorPos
SetCursorPos
ReleaseCapture
GetClientRect
MessageBoxA
GetKeyState
LoadCursorA
ScreenToClient
GetCapture
ClientToScreen
IsChild
GetForegroundWindow
SetCapture
SetCursor
IMM32.dll ImmReleaseContext
ImmSetCompositionWindow
ImmGetContext
XINPUT1_3.dll #4
#2
urlmon.dll URLDownloadToFileA
WININET.dll InternetCloseHandle
InternetOpenA
InternetOpenUrlA
InternetReadFile

Delayed Imports

1

Type RT_ICON
Language Turkish - Turkey
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.18014
MD5 f9a7943497338df358781197634608ac 🔍
SHA1 77889f5504e9f71d2b23c4fc2f278ecc388d5fea 🔍
SHA256 1cd3eef7fe31d856899f811605a27511ab488d98465f03f0ac1c97e97741af22 🔍
SHA3 c2662d5cb715cb922ad8779e52e9fe5c13f710b6921a402223bd4172973a5e21 🔍

101

Type RT_GROUP_ICON
Language Turkish - Turkey
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.7815
Detected Filetype Icon file
MD5 3c68f77c35c26ff079a1c410ee44fa62 🔍
SHA1 0b40150c95fc2c6414c90d44ee78b8d8814b3393 🔍
SHA256 a14e70ed824f3f17d3a51136aa08839954d6d3ccadaa067415c7bfc08e6636b0 🔍
SHA3 590dcbf2ec3f485a6c24e3e627f383ee7588eb49978321f12c07d8190a6c1396 🔍

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b 🔍
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-May-23 17:09:55
Version 0.0
SizeofData 984
AddressOfRawData 0xc47e4
PointerToRawData 0xc2fe4

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-May-23 17:09:55
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x4c4bd0
EndAddressOfRawData 0x4c5f74
AddressOfIndex 0x518778
AddressOfCallbacks 0x45c2a4
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0xc0
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x4ca080
SEHandlerTable 0x4c453c
SEHandlerCount 106

RICH Header

XOR Key 0x31179d3f
Unmarked objects 0
ASM objects (33140) 28
C++ objects (33140) 189
C objects (33140) 26
Imports (VS2010 build 30319) 2
ASM objects (35207) 24
C objects (35207) 19
C++ objects (35207) 82
Imports (33140) 10
Total imports 147
Imports (VS2015 v14.0.? compiler 24610) 3
C++ objects (LTCG) (35214) 8
Resource objects (35214) 1
151 1
Linker (35214) 1

Errors

Leave a comment

No comments yet.