| Architecture |
IMAGE_FILE_MACHINE_I386
|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date |
2026-Apr-02 14:52:48
|
| TLS Callbacks |
2 callback(s) detected.
|
| Suspicious |
The PE is possibly packed. |
Unusual section name found: VEOS_CAL
Unusual section name found: /4
Unusual section name found: /14
|
| Info |
The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
- GetProcAddress
- LoadLibraryA
|
| Suspicious |
The file contains overlay data. |
29 bytes of data starting at offset 0xd000.
|
| Suspicious |
No VirusTotal score. |
This file has never been scanned on VirusTotal.
|
| MD5 |
19674d0cc7a22005a321217abc352a76
|
| SHA1 |
24fcf0879b8c750a2d5d64bfee953fd9cc71cc61
|
| SHA256 |
76ff9b077cd88cf701cbaf6fafe9a348cbb5361e58d909e494a4421672270732
|
| SHA3 |
45d661fb06bf927d980b9c113b4c00d7409636ea1d73f6ad5899a3ca8baa8109
|
| SSDeep |
768:AkaNvgIFhcss1FiNCN+C1kZxqkHA2p0VKhLcmvmreDL8Ff0PW4ku:A7vgIzoD+0Og2p3zmr28lD+
|
| Imports Hash |
3a52360e0d3f983f5c26d8af75133318
|
| e_magic |
MZ
|
| e_cblp |
0x90
|
| e_cp |
0x3
|
| e_crlc |
0
|
| e_cparhdr |
0x4
|
| e_minalloc |
0
|
| e_maxalloc |
0xffff
|
| e_ss |
0
|
| e_sp |
0xb8
|
| e_csum |
0
|
| e_ip |
0
|
| e_cs |
0
|
| e_ovno |
0
|
| e_oemid |
0
|
| e_oeminfo |
0
|
| e_lfanew |
0x80
|
| Signature |
PE
|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections |
11
|
| TimeDateStamp |
2026-Apr-02 14:52:48
|
| PointerToSymbolTable |
0xd000
|
| NumberOfSymbols |
0
|
| SizeOfOptionalHeader |
0xe0
|
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic |
PE32
|
| LinkerVersion |
2.0
|
| SizeOfCode |
0x5800
|
| SizeOfInitializedData |
0x7200
|
| SizeOfUninitializedData |
0x800
|
| AddressOfEntryPoint |
0x000013A0 (Section: .text)
|
| BaseOfCode |
0x1000
|
| BaseOfData |
0x7000
|
| ImageBase |
0
|
| SectionAlignment |
0x1000
|
| FileAlignment |
0x200
|
| OperatingSystemVersion |
4.0
|
| ImageVersion |
0.0
|
| SubsystemVersion |
4.0
|
| Win32VersionValue |
0
|
| SizeOfImage |
0x15000
|
| SizeOfHeaders |
0x400
|
| Checksum |
0x11716
|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve |
0x200000
|
| SizeofStackCommit |
0x1000
|
| SizeofHeapReserve |
0x100000
|
| SizeofHeapCommit |
0x1000
|
| LoaderFlags |
0
|
| NumberOfRvaAndSizes |
16
|
| MD5 |
0a532fa4702955a14bb6d58d6591da34
|
| SHA1 |
f8524b07352e8f2e7184cd661aa589b997544bf6
|
| SHA256 |
894f87719326746f353f331debff53a4ad6d2c72d3effbd849c48164eb24286a
|
| SHA3 |
b227ae9b4f829cbd51270c0e9ad3be6369eb40b709c035a296b7364d8a90f01b
|
| VirtualSize |
0x57c0
|
| VirtualAddress |
0x1000
|
| SizeOfRawData |
0x5800
|
| PointerToRawData |
0x400
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy |
6.07109
|
| MD5 |
4a998f248959fae99feb3c3e2c1b652b
|
| SHA1 |
283e383935a99f2946b09740cb72e68e84011cb7
|
| SHA256 |
eef1ab9f47cdf0c8ab7646fec433b3d79e19a30f3ee97c4e68dda74cf4e5d513
|
| SHA3 |
e0dfc919862e335379032c4712ac4929c4b7ec1a959058e95eba18c392921846
|
| VirtualSize |
0x53c
|
| VirtualAddress |
0x7000
|
| SizeOfRawData |
0x600
|
| PointerToRawData |
0x5c00
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
3.91573
|
| MD5 |
4f7af9227932fabcb44626d2dcadc325
|
| SHA1 |
53fcec228c2661a8f0f52dabb487bbdf94bffcb8
|
| SHA256 |
ef15297b6f6928227dee5792cafad85b439b9742c68ef41bf8829af79637d293
|
| SHA3 |
d527e7d68f06e6760fccf10e07e08f72241e86b323a3ab3f9b346c08ee9e6ff4
|
| VirtualSize |
0x4c
|
| VirtualAddress |
0x8000
|
| SizeOfRawData |
0x200
|
| PointerToRawData |
0x6200
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
0.567242
|
| MD5 |
f332c179bd1196038b7e54f77ae90d8d
|
| SHA1 |
765b87a434786e5cda1ab0cd9cc257bcad5d8a1c
|
| SHA256 |
f9e764847336b27ba35a28bbdc891875a4ba7200ce4e17ae72fbb2b339d2eb4e
|
| SHA3 |
6de52ebd182b9ae9218a19aad758191466158a2d27d7e669288efbede80d915d
|
| VirtualSize |
0x2288
|
| VirtualAddress |
0x9000
|
| SizeOfRawData |
0x2400
|
| PointerToRawData |
0x6400
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
5.10993
|
| MD5 |
27679e90b55800256a9e2bf8d115962d
|
| SHA1 |
ea16d7bf1180718b322af8fe1fa2c1be4ccdd6f0
|
| SHA256 |
268ce156e5c3b6e79459c1f25caaa9cead5418d9c461257320226963a1118683
|
| SHA3 |
4d53005f38804be316ed0f316df8e5c6a5f4bf6abb9a0366532ca1403fdfdb8f
|
| VirtualSize |
0x1d34
|
| VirtualAddress |
0xc000
|
| SizeOfRawData |
0x1e00
|
| PointerToRawData |
0x8800
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy |
4.54012
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| VirtualSize |
0x748
|
| VirtualAddress |
0xe000
|
| SizeOfRawData |
0
|
| PointerToRawData |
0
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| MD5 |
476e99e5d228b6d97a415d2943c88205
|
| SHA1 |
f614fb27c31d123cbab0ee5b9bccd69bf29da99e
|
| SHA256 |
2a0b734957dc564c6f64e262b2974c95c63c5ed10a523b1ac8d9bd745230b485
|
| SHA3 |
4536fdcfff753bb86999b32780c79c178e9ef32363c8c96b84790b6af59be8d3
|
| VirtualSize |
0x1049
|
| VirtualAddress |
0xf000
|
| SizeOfRawData |
0x1200
|
| PointerToRawData |
0xa600
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy |
4.98911
|
| MD5 |
62e606177703446a05daffb4e9efb6fe
|
| SHA1 |
0665f94a07c0357f068b1eaffc3b2d22cc63bc89
|
| SHA256 |
5c6f1b8a52608d7c9a04d2373f4a7a69c72d88b8c01a1aaf69708d0d691e1399
|
| SHA3 |
2ebc460a5af043870caac59869505f4a73f1d074b4a52ea30de3b9f1211f3ac6
|
| VirtualSize |
0x748
|
| VirtualAddress |
0x11000
|
| SizeOfRawData |
0x800
|
| PointerToRawData |
0xb800
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy |
4.68202
|
| MD5 |
bf619eac0cdf3f68d496ea9344137e8b
|
| SHA1 |
5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
|
| SHA256 |
076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
|
| SHA3 |
622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
|
| VirtualSize |
0x8
|
| VirtualAddress |
0x12000
|
| SizeOfRawData |
0x200
|
| PointerToRawData |
0xc000
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
0
|
| MD5 |
4f47a0a0c860174d6d3645aee6d57f36
|
| SHA1 |
e4bb22cb3f591af9ee55f00566215c7c0cbaa42f
|
| SHA256 |
27afecd63cbb066cfe0f0e9bfae3caea66234b0f9dfe1941f0069f0cc20aa0ef
|
| SHA3 |
c47cdd13e4db3c5b74a66caaefa6dee39c069355c8ccc99d442522abc69c25d0
|
| VirtualSize |
0xa98
|
| VirtualAddress |
0x13000
|
| SizeOfRawData |
0xc00
|
| PointerToRawData |
0xc200
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy |
6.33143
|
| MD5 |
f3acbc0c4023f0b1e200a0f94a319d98
|
| SHA1 |
c3823e3b2ac5c3136369678d181fa1ac9cf745d6
|
| SHA256 |
8911249a25706ce7abb89a64d09008dcff28928fb3bae1040b32f0a56b359965
|
| SHA3 |
fae03ef1822d4ea9da586af63518fed96399aa2cf145ff2133ca6f2ff5818685
|
| VirtualSize |
0x14
|
| VirtualAddress |
0x14000
|
| SizeOfRawData |
0x200
|
| PointerToRawData |
0xce00
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy |
0.321716
|
| KERNEL32.dll |
DeleteCriticalSection
EnterCriticalSection
FreeLibrary
GetLastError
GetModuleHandleA
GetProcAddress
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryA
Sleep
TlsGetValue
VirtualProtect
VirtualQuery
|
| api-ms-win-crt-environment-l1-1-0.dll |
__p__environ
__p__wenviron
_wgetenv
getenv
|
| api-ms-win-crt-heap-l1-1-0.dll |
_set_new_mode
calloc
free
|
| api-ms-win-crt-math-l1-1-0.dll |
fmod
|
| api-ms-win-crt-runtime-l1-1-0.dll |
__p___argc
__p___argv
__p___wargv
_configure_narrow_argv
_configure_wide_argv
_crt_at_quick_exit
_crt_atexit
_execute_onexit_table
_exit
_initialize_narrow_environment
_initialize_onexit_table
_initialize_wide_environment
_initterm
_register_onexit_function
abort
|
| api-ms-win-crt-stdio-l1-1-0.dll |
__acrt_iob_func
__stdio_common_vfprintf
__stdio_common_vfwprintf
fwrite
|
| api-ms-win-crt-string-l1-1-0.dll |
strcmp
strlen
strncmp
|
| api-ms-win-crt-time-l1-1-0.dll |
__daylight
__timezone
__tzname
_tzset
|
| Ordinal |
10
|
| Address |
0xe640
|
| Ordinal |
11
|
| Address |
0xe63c
|
| Ordinal |
12
|
| Address |
0xe514
|
| Ordinal |
13
|
| Address |
0xe510
|
| Ordinal |
14
|
| Address |
0xe508
|
| Ordinal |
15
|
| Address |
0xe50c
|
| Ordinal |
16
|
| Address |
0xe64c
|
| Ordinal |
17
|
| Address |
0xe5a0
|
| Ordinal |
18
|
| Address |
0xe608
|
| Ordinal |
19
|
| Address |
0xe604
|
| Ordinal |
20
|
| Address |
0xe600
|
| Ordinal |
21
|
| Address |
0xe61c
|
| Ordinal |
22
|
| Address |
0xe614
|
| Ordinal |
23
|
| Address |
0xe60c
|
| Ordinal |
24
|
| Address |
0xe624
|
| Ordinal |
25
|
| Address |
0xe620
|
| Ordinal |
26
|
| Address |
0xe618
|
| Ordinal |
27
|
| Address |
0xe610
|
| Ordinal |
28
|
| Address |
0xe628
|
| Ordinal |
29
|
| Address |
0xe5a4
|
| Ordinal |
30
|
| Address |
0xe5b0
|
| Ordinal |
31
|
| Address |
0xe5ac
|
| Ordinal |
32
|
| Address |
0xe5a8
|
| Ordinal |
33
|
| Address |
0xe5c4
|
| Ordinal |
34
|
| Address |
0xe5bc
|
| Ordinal |
35
|
| Address |
0xe5b4
|
| Ordinal |
36
|
| Address |
0xe5cc
|
| Ordinal |
37
|
| Address |
0xe5c8
|
| Ordinal |
38
|
| Address |
0xe5c0
|
| Ordinal |
39
|
| Address |
0xe5b8
|
| Ordinal |
40
|
| Address |
0xe5d0
|
| Ordinal |
41
|
| Address |
0xe5dc
|
| Ordinal |
42
|
| Address |
0xe5d8
|
| Ordinal |
43
|
| Address |
0xe5d4
|
| Ordinal |
44
|
| Address |
0xe5f0
|
| Ordinal |
45
|
| Address |
0xe5e8
|
| Ordinal |
46
|
| Address |
0xe5e0
|
| Ordinal |
47
|
| Address |
0xe5f8
|
| Ordinal |
48
|
| Address |
0xe5f4
|
| Ordinal |
49
|
| Address |
0xe5ec
|
| Ordinal |
50
|
| Address |
0xe5e4
|
| Ordinal |
51
|
| Address |
0xe5fc
|
| Ordinal |
52
|
| Address |
0xe57c
|
| Ordinal |
53
|
| Address |
0xe578
|
| Ordinal |
54
|
| Address |
0xe574
|
| Ordinal |
55
|
| Address |
0xe590
|
| Ordinal |
56
|
| Address |
0xe588
|
| Ordinal |
57
|
| Address |
0xe580
|
| Ordinal |
58
|
| Address |
0xe598
|
| Ordinal |
59
|
| Address |
0xe594
|
| Ordinal |
60
|
| Address |
0xe58c
|
| Ordinal |
61
|
| Address |
0xe584
|
| Ordinal |
62
|
| Address |
0xe59c
|
| Ordinal |
63
|
| Address |
0xe518
|
| Ordinal |
64
|
| Address |
0xe524
|
| Ordinal |
65
|
| Address |
0xe520
|
| Ordinal |
66
|
| Address |
0xe51c
|
| Ordinal |
67
|
| Address |
0xe538
|
| Ordinal |
68
|
| Address |
0xe530
|
| Ordinal |
69
|
| Address |
0xe528
|
| Ordinal |
70
|
| Address |
0xe540
|
| Ordinal |
71
|
| Address |
0xe53c
|
| Ordinal |
72
|
| Address |
0xe534
|
| Ordinal |
73
|
| Address |
0xe52c
|
| Ordinal |
74
|
| Address |
0xe544
|
| Ordinal |
75
|
| Address |
0xe550
|
| Ordinal |
76
|
| Address |
0xe54c
|
| Ordinal |
77
|
| Address |
0xe548
|
| Ordinal |
78
|
| Address |
0xe564
|
| Ordinal |
79
|
| Address |
0xe55c
|
| Ordinal |
80
|
| Address |
0xe554
|
| Ordinal |
81
|
| Address |
0xe56c
|
| Ordinal |
82
|
| Address |
0xe568
|
| Ordinal |
83
|
| Address |
0xe560
|
| Ordinal |
84
|
| Address |
0xe558
|
| Ordinal |
85
|
| Address |
0xe570
|
| Ordinal |
86
|
| Address |
0xe648
|
| Ordinal |
87
|
| Address |
0xe644
|
| Ordinal |
88
|
| Address |
0xe650
|
| StartAddressOfRawData |
0x12000
|
| EndAddressOfRawData |
0x12004
|
| AddressOfIndex |
0xe700
|
| AddressOfCallbacks |
0xb274
|
| SizeOfZeroFill |
0
|
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x000057C0
0x00005770
|
[*] Warning: Tried to read outside the COFF string table to get the name of section /4!
[*] Warning: Tried to read outside the COFF string table to get the name of section /14!
[*] Warning: Section .bss has a size of 0!