6e8965caab19a01aef12de547e1021922bd7592b8d6fed4394a61481122fde8b

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Sep-13 10:52:17
Detected languages English - United States

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • high-logic.com
  • http://www.high-logic.com
  • http://www.high-logic.com/
  • logic.com
  • www.high-logic.com
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • FindWindowA
Code injection capabilities:
  • WriteProcessMemory
  • OpenProcess
  • VirtualAllocEx
Can access the registry:
  • RegNotifyChangeKeyValue
  • RegCloseKey
  • RegOpenKeyExA
Uses functions commonly found in keyloggers:
  • AttachThreadInput
  • GetForegroundWindow
  • GetAsyncKeyState
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAllocEx
Manipulates other processes:
  • WriteProcessMemory
  • OpenProcess
  • ReadProcessMemory
Can take screenshots:
  • FindWindowA
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 2a3b6d32ac2275133dbbdeacea94695e 🔍
SHA1 ff9e4b65682fe8ce31ce555b2dbcfd0f1e2b8551 🔍
SHA256 6e8965caab19a01aef12de547e1021922bd7592b8d6fed4394a61481122fde8b 🔍
SHA3 e166b5aa532254feb11d4d21529477148e6a83899f2e16bdc129bf5d46525612 🔍
SSDeep 3072:gwX92yNu63I9tBrnDJmya89GruVqKYT2CQ5F0aJdoMD3bpRhHq2bPTJITkTF:ZiSQcyaPuVR9F0aJIan 🔍
Imports Hash fbf51c2d086aa9594cbbd9f3a82d0ade 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Sep-13 10:52:17
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x1d200
SizeOfInitializedData 0x16c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000000F478 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x39000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 da4a45250c79c9ea10b9fe8651657fb4 🔍
SHA1 8ca674cde550fe48a5beaccac31503f6a569e4eb 🔍
SHA256 2a2fb865a073bb10b3cb4524eb5f9183d5370b509c7085209ab94831d718292f 🔍
SHA3 505a119124aebd5f31afab3ee1006ec8de33d3dbc7f7f769c1420fc0cc7c53b0 🔍
VirtualSize 0x1d0ac
VirtualAddress 0x1000
SizeOfRawData 0x1d200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.51462

.rdata

MD5 79583538c70c0c8f225e8ae992fba4c4 🔍
SHA1 7367c0d34d28e8443365d105025d3ae20ff3c6f3 🔍
SHA256 3d031a35387ca467f5946fb3674a1373c7efc9dd179c27b6a0f1eb1e93d04af7 🔍
SHA3 6727073fbbb0c58962a4c1a6471f84f21af06b90abb00c3b120bca6d50f77d80 🔍
VirtualSize 0xca6c
VirtualAddress 0x1f000
SizeOfRawData 0xcc00
PointerToRawData 0x1d600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.05379

.data

MD5 3b80705051e685ae6bc034de37125885 🔍
SHA1 1ef9f769bcd25526bbcfeb5e443750e9a25445d2 🔍
SHA256 d8f261e9c558dc636fba3a6d9dad4e127d99f70834fde5b8b485af9f019f6099 🔍
SHA3 6a69da878b71f6e907b75fa19981dad51def9edde2e6d22f6c0c6043f661ccaa 🔍
VirtualSize 0x27d4
VirtualAddress 0x2c000
SizeOfRawData 0x1000
PointerToRawData 0x2a200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.63025

.pdata

MD5 409717a9d3f5718d5910630e6546780d 🔍
SHA1 ffc14b7e4874a015009f331e0ed97138acd0ae80 🔍
SHA256 349be18f2e6e094968343d6c5002f016688c54b58b962d4bf8f42c23f3f03ab9 🔍
SHA3 80a6350b23edd334bc57370fc4171d1470cdceb88b780577c044b150313a2436 🔍
VirtualSize 0x159c
VirtualAddress 0x2f000
SizeOfRawData 0x1600
PointerToRawData 0x2b200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.22479

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x31000
SizeOfRawData 0x200
PointerToRawData 0x2c800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 cc20bfc75baf033feb755da688326e5c 🔍
SHA1 6e4c71fc7fae513ef8db687ce8ab0335a5e3b367 🔍
SHA256 ca515555921878963d5586a22f161e78bf7af2e75be13081874a8d943a57d877 🔍
SHA3 64f963c71d0d374e05344e5782ac7d6768783f4dff9f22959bba2351b2a78825 🔍
VirtualSize 0x5758
VirtualAddress 0x32000
SizeOfRawData 0x5800
PointerToRawData 0x2ca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.91758

.reloc

MD5 a31c097a3a13cfabd74cc2661f1bc0af 🔍
SHA1 f503686831d9fc04b119e61f3df00ac545d12011 🔍
SHA256 275b0fab9e5d4affbc7f52a4ed50e434041ba90b2f446d7389cc9da78c02057a 🔍
SHA3 2f679ebc9293380e6c96b37cdf37b9e2794df67463402e0219e273e21e6faff7 🔍
VirtualSize 0x6f4
VirtualAddress 0x38000
SizeOfRawData 0x800
PointerToRawData 0x32200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.10998

Imports

USER32.dll GetClassNameA
FindWindowExA
EnumWindows
SendMessageA
FindWindowA
SetCapture
ReleaseCapture
IsRectEmpty
IntersectRect
GetWindowThreadProcessId
GetWindowRect
LoadCursorA
DestroyWindow
GetDC
SetWindowPos
FillRect
GetSystemMetrics
ShowWindow
OffsetRect
DrawTextA
ClientToScreen
AttachThreadInput
GetForegroundWindow
RegisterClassA
DefWindowProcA
CreateWindowExA
SetLayeredWindowAttributes
SetCursor
GetClientRect
GetWindowLongPtrA
PtInRect
UpdateWindow
SetForegroundWindow
ReleaseDC
GetCursorPos
BeginPaint
EndPaint
SetProcessDpiAwarenessContext
DispatchMessageA
GetAsyncKeyState
TranslateMessage
PeekMessageA
PostQuitMessage
InvalidateRect
GDI32.dll AddFontMemResourceEx
GetDeviceCaps
CreateRectRgnIndirect
CombineRgn
GetRgnBox
Ellipse
RoundRect
SetBrushOrgEx
BitBlt
CreateCompatibleBitmap
CreateFontA
SelectObject
CreateDIBSection
CreateCompatibleDC
StretchBlt
GetStockObject
DeleteDC
SetTextColor
SetBkMode
LineTo
CreatePen
Rectangle
MoveToEx
SetStretchBltMode
DeleteObject
CreateSolidBrush
GetObjectA
KERNEL32.dll MultiByteToWideChar
GetCommandLineW
GetCommandLineA
GetCPInfo
GetOEMCP
GetACP
IsValidCodePage
FindNextFileW
FindFirstFileExW
FindClose
HeapFree
HeapAlloc
WriteConsoleW
GetEnvironmentStringsW
FreeEnvironmentStringsW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
InitializeCriticalSectionEx
VirtualProtect
LCMapStringW
GetProcessHeap
GetFileType
SetStdHandle
GetStringTypeW
HeapSize
HeapReAlloc
WideCharToMultiByte
Sleep
QueryPerformanceFrequency
QueryPerformanceCounter
GetCurrentThreadId
SizeofResource
FindResourceA
LockResource
LoadResource
lstrcpynA
MulDiv
WriteProcessMemory
WaitForSingleObject
lstrcmpA
GetModuleHandleA
OpenProcess
LoadLibraryA
CloseHandle
CreateThread
GetProcAddress
VirtualAllocEx
ReadProcessMemory
VirtualFreeEx
CreateEventA
WriteFile
CreateFileW
SetFilePointerEx
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeSListHead
RtlPcToFileHeader
RaiseException
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
EncodePointer
ExitProcess
GetModuleHandleExW
GetModuleFileNameW
GetStdHandle
dwmapi.dll DwmInvalidateIconicBitmaps
DwmSetWindowAttribute
DwmSetIconicLivePreviewBitmap
DwmSetIconicThumbnail
ADVAPI32.dll RegNotifyChangeKeyValue
RegCloseKey
RegOpenKeyExA

Delayed Imports

PRSTART_FONT

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x5348
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.73016
Detected Filetype TrueType font file
MD5 65cb344c64e3d29ae35396789de64c2e 🔍
SHA1 f702f317bd9510197b2f4d6d789f09660f9ab80e 🔍
SHA256 d20bc4812fa2625d5a2d2a6ef65526bca6c61481359c7844e23a8235ad068930 🔍
SHA3 ad5c737681425c82992633ff5dbcad40e210812fa087b23c524c3a05bd303aab 🔍

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x34b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.31255
MD5 23181e7cd4c22dfc7760af8f18876386 🔍
SHA1 483d133b517fdc959a0fa52495e0c7dcb7d55fd4 🔍
SHA256 125c0b67e22ef0ff429bfc6fef436c011ba96e5d3da7c8a967daa71e0c1a84f0 🔍
SHA3 768b51712816166948e8cdadcb1081729b25312de9d98962d9e7161b7b47ff37 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Sep-13 10:52:17
Version 0.0
SizeofData 900
AddressOfRawData 0x28b48
PointerToRawData 0x27148

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14002c040

RICH Header

XOR Key 0x9dd6a611
Unmarked objects 0
C++ objects (33140) 145
C objects (33140) 17
ASM objects (33140) 14
ASM objects (35207) 9
C objects (35207) 16
C++ objects (35207) 43
Imports (33140) 11
Total imports 189
C++ objects (LTCG) (35217) 14
Resource objects (35217) 1
Linker (35217) 1

Errors

Leave a comment

No comments yet.