| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date |
2026-Jan-07 10:19:00
|
| Debug artifacts |
Embedded COFF debugging symbols
|
|
Suspicious
|
The PE is possibly packed. |
The PE only has 0 import(s).
|
|
Suspicious
|
The file contains overlay data. |
3064 bytes of data starting at offset 0xa00.
|
|
Malicious
|
VirusTotal score: 5/68 (Scanned on 2026-09-15 05:11:58) |
Bkav:
W32.Malware.42D33711
CrowdStrike:
win/malicious_confidence_60% (W)
Malwarebytes:
Malware.Heuristic.2006
McAfeeD:
ti!5A3F98ABB4E1
Paloalto:
generic.ml
|
| MD5 |
40f1366349a7e8343340ff92305d1c1b
🔍
|
| SHA1 |
e2b003a0c7bce8500685f9976be66ae70764ce77
🔍
|
| SHA256 |
5a3f98abb4e17f629fd46f4b052ed9fb876b9b51515df75fd7353cd57dc2c78b
🔍
|
| SHA3 |
be2306de6493d1de0acc847f7b5a624af291304a849a0dfd2676a7ff98190351
🔍
|
| SSDeep |
48:6C15G/1QMea4H7mAtADoFtZ8qwBDXPgiWZzzjGpS2XFWOOw2J9UD0RWg+e:01Qla4HnOqtZmhX2tsWku9F
🔍
|
| Imports Hash |
d41d8cd98f00b204e9800998ecf8427e
🔍
|
| e_magic |
MZ
|
| e_cblp |
0x90
|
| e_cp |
0x3
|
| e_crlc |
0
|
| e_cparhdr |
0x4
|
| e_minalloc |
0
|
| e_maxalloc |
0xffff
|
| e_ss |
0
|
| e_sp |
0xb8
|
| e_csum |
0
|
| e_ip |
0
|
| e_cs |
0
|
| e_ovno |
0
|
| e_oemid |
0
|
| e_oeminfo |
0
|
| e_lfanew |
0x80
|
| Signature |
PE
|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections |
3
|
| TimeDateStamp |
2026-Jan-07 10:19:00
|
| PointerToSymbolTable |
0xa00
|
| NumberOfSymbols |
92
|
| SizeOfOptionalHeader |
0xf0
|
| Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
|
| Magic |
PE32+
|
| LinkerVersion |
2.0
|
| SizeOfCode |
0x200
|
| SizeOfInitializedData |
0x400
|
| SizeOfUninitializedData |
0
|
| AddressOfEntryPoint |
0x0000000000001000 (Section: .text)
|
| BaseOfCode |
0x1000
|
| ImageBase |
0x140000000
|
| SectionAlignment |
0x1000
|
| FileAlignment |
0x200
|
| OperatingSystemVersion |
4.0
|
| ImageVersion |
0.0
|
| SubsystemVersion |
5.2
|
| Win32VersionValue |
0
|
| SizeOfImage |
0x4000
|
| SizeOfHeaders |
0x400
|
| Checksum |
0x9a0c
|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve |
0x200000
|
| SizeofStackCommit |
0x1000
|
| SizeofHeapReserve |
0x100000
|
| SizeofHeapCommit |
0x1000
|
| LoaderFlags |
0
|
| NumberOfRvaAndSizes |
16
|
| MD5 |
db1915bb46b57d30a6b4590879d49dc4
🔍
|
| SHA1 |
8d2ffd369a3864b2c964b80090b41e88bfecb724
🔍
|
| SHA256 |
a088c272c4232fd6ba79f35c66a6577d552255684817319dd072f844b0d80a27
🔍
|
| SHA3 |
10f5a70aa59f7d787d89b54f09ecb28d586031686a889812809bd12d5d28913b
🔍
|
| VirtualSize |
0x88
|
| VirtualAddress |
0x1000
|
| SizeOfRawData |
0x200
|
| PointerToRawData |
0x400
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy |
1.24871
|
| MD5 |
cb598dfcf1cf66ad15e7843d3c6e16f3
🔍
|
| SHA1 |
6fb3ecb332ba2d934408400328980e7aa8072c4a
🔍
|
| SHA256 |
c7586e57dbfa348a0d9f4a7ecaf303c9372c0482e9ca483ed4948543c632a479
🔍
|
| SHA3 |
3bd04db8ab3fcde640ac0c6a4edfde69516245965fca0b29cbd3deefe0109d2f
🔍
|
| VirtualSize |
0x84
|
| VirtualAddress |
0x2000
|
| SizeOfRawData |
0x200
|
| PointerToRawData |
0x600
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
0.415364
|
| MD5 |
bf619eac0cdf3f68d496ea9344137e8b
🔍
|
| SHA1 |
5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
🔍
|
| SHA256 |
076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
🔍
|
| SHA3 |
622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
🔍
|
| VirtualSize |
0x14
|
| VirtualAddress |
0x3000
|
| SizeOfRawData |
0x200
|
| PointerToRawData |
0x800
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
0
|
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF symbol's section number is bigger than the number of sections!
[*] Warning: COFF String Table's reported size is bigger than the remaining bytes!