7b3be2c72a2e5ebad81d7f8e6c3543488e53aaeb467787045e8dc57a80b9a21c

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2019-Apr-23 21:10:04
Debug artifacts Embedded COFF debugging symbols

Plugin Output

Suspicious The file contains overlay data. 7929 bytes of data starting at offset 0x1000.
Malicious VirusTotal score: 5/72 (Scanned on 2025-10-01 01:45:49) ClamAV: Win.Exploit.Mircer-9952311-0
CrowdStrike: win/malicious_confidence_60% (W)
Google: Detected
Ikarus: Exploit.Win32.Mircer
VBA32: TScope.Malware-Cryptor.SB

Hashes

MD5 86aaab4ea2fa04d03151bbc1406749cc 🔍
SHA1 57dbe330a911378c4a56d07e2af3ac8b6d2dde11 🔍
SHA256 7b3be2c72a2e5ebad81d7f8e6c3543488e53aaeb467787045e8dc57a80b9a21c 🔍
SHA3 859b168ab1299f53f1df5e351cfda60b1b1cea48f02c89457428e0d85d7db39f 🔍
SSDeep 96:GwjnyXxr7dsbRPKKrtroJXwXvD4g9rl2ou05MRWJ8Wr/+WqWsHWkuW/WRsWHWjWG:GR6rBeA/D4g9rZKhBepHfEObAYBXQzf 🔍
Imports Hash 3f3bd2d829c2c8de05c336de568e86f7 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2019-Apr-23 21:10:04
PointerToSymbolTable 0x1000
NumberOfSymbols 356
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0xa00
SizeOfInitializedData 0x600
SizeOfUninitializedData 0x200
AddressOfEntryPoint 0x000011C4 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x2000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 1.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x5000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
SizeofStackReserve 0x2000000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 0a0f7787725580a8516b4b046592062e 🔍
SHA1 f5083923a9308b7f71443c527645713c92d66ca1 🔍
SHA256 c96936a5af18a4b7be17cb8cac2df4100a0b641c6eac592adcab7f118a85edbb 🔍
SHA3 f73a848937cadae628357938ca437017c8823459c57d0e1523e7e63afb9cd4ef 🔍
VirtualSize 0x488
VirtualAddress 0x1000
SizeOfRawData 0x600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 4.74557

.data

MD5 d2b2988846f3cabae5203ac2ee1e6c02 🔍
SHA1 0f33e6e153a25d2511616e2b8bca8345a79bb1ed 🔍
SHA256 b230368cf1f5cc05507c1a912fab2931f06f1f198113076dc72daadcbc5e2f2c 🔍
SHA3 8b77cc07e7d1933136a02e1ba1a820337029aaadb5ae4071b0c68451bf074d79 🔍
VirtualSize 0x28
VirtualAddress 0x2000
SizeOfRawData 0x200
PointerToRawData 0xa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.127011

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍
VirtualSize 0x14
VirtualAddress 0x3000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 dda7e7c45184841446bbf2bac930681b 🔍
SHA1 ff28c39236bfb3edcfcf5aed2d7c20348cd3355f 🔍
SHA256 44875d64237310b7557f876a782c872bbe40a3bb067f6d30f2251071aa49bf67 🔍
SHA3 0454607adc41a0ef6c79dee090123c4f8a1802adac2f000d12b23de049a754b2 🔍
VirtualSize 0x258
VirtualAddress 0x4000
SizeOfRawData 0x400
PointerToRawData 0xc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.48105

Imports

crtdll.dll _fmode_dll
_fpreset
_iob
__GetMainArgs
_setmode
atexit
cos
printf
scanf
signal
_cexit
_environ_dll
_fileno
KERNEL32.dll ExitProcess
SetUnhandledExceptionFilter
crtdll.dll (#2) _fmode_dll
_fpreset
_iob
__GetMainArgs
_setmode
atexit
cos
printf
scanf
signal
_cexit
_environ_dll
_fileno

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

RICH Header

Errors

[*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF String Table's reported size is bigger than the remaining bytes! [*] Warning: Section .bss has a size of 0!
Leave a comment

No comments yet.