7e859d751ceb50c78b676d365dc4aac845bad560fe450a8d4b5cc1f07f234ce8

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1970-Jan-01 00:00:00

Plugin Output

Suspicious PEiD Signature: HQR data file
Info Interesting strings found in the binary: Contains domain names:
  • gcc.gnu.org
  • https://gcc.gnu.org
  • https://gcc.gnu.org/bugs/
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA256
Uses constants related to RC5 or RC6
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CheckRemoteDebuggerPresent
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Suspicious The file contains overlay data. 4158760 bytes of data starting at offset 0x37800.
The overlay data has an entropy of 7.99994 and is possibly compressed or encrypted.
Overlay data amounts for 94.8171% of the executable.
Malicious VirusTotal score: 19/71 (Scanned on 2026-09-30 12:07:28) ALYac: Gen:Variant.Ulise.609087
APEX: Malicious
Arcabit: Trojan.Ulise.D94B3F
BitDefender: Gen:Variant.Ulise.609087
Bkav: W32.Malware.1622F363
CTX: exe.unknown.ulise
CrowdStrike: win/malicious_confidence_70% (D)
Cynet: Malicious (score: 100)
DrWeb: BackDoor.Reverse.244
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Ulise.609087 (B)
GData: Gen:Variant.Ulise.609087
McAfeeD: ti!7E859D751CEB
MicroWorld-eScan: Gen:Variant.Ulise.609087
Microsoft: Trojan:Win32/Wacatac.B!ml
SentinelOne: Static AI - Malicious PE
Symantec: ML.Attribute.HighConfidence
Trapmine: malicious.moderate.ml.score
VIPRE: Gen:Variant.Ulise.609087

Hashes

MD5 736698b1c41c60414fb8e0e59d2f4341 🔍
SHA1 08deabd24066a47d4a63316978cef74a4b7e5a7c 🔍
SHA256 7e859d751ceb50c78b676d365dc4aac845bad560fe450a8d4b5cc1f07f234ce8 🔍
SHA3 fb4185c13982848c3e1c568090a46079f1cfe2e3ede07b79789b5d1e107e3076 🔍
SSDeep 98304:ZuXMX+zqqgCWX4ieq7OyFBjWW3Fmzm9Rfpw9HLOD4:PX+zhOrx7dHWGweR69o4 🔍
Imports Hash 9765c83972fdba64094302d22fa60f2c 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 11
TimeDateStamp 1970-Jan-01 00:00:00
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 0.0
SizeOfCode 0x2a000
SizeOfInitializedData 0xd400
SizeOfUninitializedData 0xc00
AddressOfEntryPoint 0x0000000000001480 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x3f000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 a1d6e42de2381beae8f62ed3d9007ccc 🔍
SHA1 5647be97caca1f5367a9855646f38f141dfc2e09 🔍
SHA256 33c11e665862fd34b143c190f7dcbf08ddffad7f3f0cf760922feb304d9e8327 🔍
SHA3 2e2251126c06d6aa4c82ab33fedccbc3349eb58013308a673b71b1ad90e6d1b1 🔍
VirtualSize 0x29e60
VirtualAddress 0x1000
SizeOfRawData 0x2a000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.16429

.data

MD5 af84d43a3d1eb87d9fa44c7b0736b1ef 🔍
SHA1 d217dcf8a78809a250a09f3be1acc8afa73419e9 🔍
SHA256 d84db2336745e06c9775fe356d639040bcc47bc2466648d79c56eee950a2d894 🔍
SHA3 0f1996a90c3b1d8043b6fa184b235f27deb83b4561f9a2d226151b4e6843734a 🔍
VirtualSize 0x1c90
VirtualAddress 0x2b000
SizeOfRawData 0x1e00
PointerToRawData 0x2a400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.203873

.data1

MD5 fb14cfd7b2c408c2086e15ebe5151872 🔍
SHA1 d693718c5c2eeb9bb701e86d97c61b450e6e7729 🔍
SHA256 3c6681df64dd646687c9f765341f20dc29c33f3094fd449dd3bde13f17e5d633 🔍
SHA3 74d4b78353f2a50f7ba62145df02ac288265457a13be1be1761597b095eff389 🔍
VirtualSize 0x10
VirtualAddress 0x2d000
SizeOfRawData 0x200
PointerToRawData 0x2c200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.325622

.tls

MD5 6a3376f9eda2ea6c9cde569a96ff638f 🔍
SHA1 2833ad2d58499611e5a18c6decf3264e43b750f9 🔍
SHA256 2b7cda1eaf0adc290579e2251c8e02a01671562dbabaa1f455cc72cb3d0b0768 🔍
SHA3 46ba4433ae4aa1e43375f7df864848de8a40e9374dc70f82d20af3c70930702a 🔍
VirtualSize 0x4880
VirtualAddress 0x2e000
SizeOfRawData 0x4a00
PointerToRawData 0x2c400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.07064

.pdata

MD5 ee23dbfc3a79803218b9df8dac9b83cb 🔍
SHA1 b5d1f571a04d84103d5f6d37208de964d353143a 🔍
SHA256 892f85940f01300716ce18bfe910867c3f2a3cc132425a50442685df46079f09 🔍
SHA3 4ac1392bcecc11f6bb45f08d264bebc83d427856b5f14e807b47667d81b08c2a 🔍
VirtualSize 0x282c
VirtualAddress 0x33000
SizeOfRawData 0x2a00
PointerToRawData 0x30e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.35229

.rdata

MD5 0a4b57706657ffabcca61e3b96c18c6f 🔍
SHA1 1d9af95ee66a4f846e817e8022969c84814aa6ae 🔍
SHA256 7d3687ee00edf2b1d8eb0f5615fd3e0560e4dd94283c74f26bc3ac6671a1e280 🔍
SHA3 1cf96343f9d8b4db27f64c924c6bd01abe3ec79bba91cf9a851884de1c9e0cd6 🔍
VirtualSize 0x210c
VirtualAddress 0x36000
SizeOfRawData 0x2200
PointerToRawData 0x33800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.02561

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍
VirtualSize 0xad8
VirtualAddress 0x39000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 a7c0b3a2c5ad3ae929ed1c05ab7a65f3 🔍
SHA1 6ebfaf105d0af18bc2bf59b987b2a75a7ef1d607 🔍
SHA256 08d7e8e927f9b48d3849dfc3ba345260b895a3b2c1b0eb60229dc6959adfab77 🔍
SHA3 f61d864b96253da872ceb42d880832e40fbf89302b08823738c5b7b45ba97a7d 🔍
VirtualSize 0x1140
VirtualAddress 0x3a000
SizeOfRawData 0x1200
PointerToRawData 0x35a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.35742

.data2

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x20
VirtualAddress 0x3c000
SizeOfRawData 0x200
PointerToRawData 0x36c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 723419f90eb228649ea052d3fcb1813b 🔍
SHA1 38ff7a6dbca26ecbe641a6a3b51f95bff9a669be 🔍
SHA256 bf49d21e9f2ba383a6f2b19eea59ebece7f882c4900860388ff8860fb99452ae 🔍
SHA3 fdd468a68a88e33be786982f3990d595d1ce368ebf0a19d35325cc9f25612eb2 🔍
VirtualSize 0x320
VirtualAddress 0x3d000
SizeOfRawData 0x400
PointerToRawData 0x36e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.70256

.reloc

MD5 e8dbe35a35de6a777d2a96fd95f0f5f1 🔍
SHA1 a82f3d3586acaad2447601b1100c5ebe99d32d92 🔍
SHA256 e7c3725a5549a2b81b65f4861f3a6ac5e97b47316e6992c49a90a284a09bedfe 🔍
SHA3 fbd407b898bdc280ac3e83739f0c67813e8808697cde06fece8576e02125cfa5 🔍
VirtualSize 0x43c
VirtualAddress 0x3e000
SizeOfRawData 0x600
PointerToRawData 0x37200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.46497

Imports

KERNEL32.dll AddVectoredExceptionHandler
CheckRemoteDebuggerPresent
CloseHandle
CreateEventA
CreateEventW
CreateFileA
CreateFileMappingA
DeleteCriticalSection
EnterCriticalSection
FormatMessageA
GetCurrentProcess
GetCurrentThreadId
GetFileSize
GetFileSizeEx
GetLastError
GetModuleFileNameA
GetModuleHandleA
GetProcAddress
GetSystemTimeAsFileTime
GetTickCount
GetTickCount64
InitializeCriticalSection
IsDebuggerPresent
IsProcessorFeaturePresent
LeaveCriticalSection
LoadLibraryA
LocalFree
MapViewOfFile
QueryPerformanceCounter
QueryPerformanceFrequency
RaiseException
ReadFile
RemoveVectoredExceptionHandler
RtlCaptureContext
RtlLookupFunctionEntry
RtlUnwindEx
RtlVirtualUnwind
SetEvent
SetUnhandledExceptionFilter
Sleep
TerminateProcess
UnmapViewOfFile
VirtualAlloc
VirtualProtect
VirtualQuery
WaitForMultipleObjects
WaitForSingleObject
api-ms-win-crt-convert-l1-1-0.dll mbrtowc
strtoul
wcrtomb
api-ms-win-crt-environment-l1-1-0.dll __p__environ
getenv
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
free
malloc
realloc
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
localeconv
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
api-ms-win-crt-private-l1-1-0.dll memchr
memcmp
memcpy
memmove
strchr
api-ms-win-crt-runtime-l1-1-0.dll __p___argc
__p___argv
_cexit
_configure_narrow_argv
_crt_atexit
_errno
_exit
_initialize_narrow_environment
_seh_filter_exe
_initterm
_initterm_e
_set_app_type
_set_invalid_parameter_handler
abort
exit
strerror
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
__p__commode
__p__fmode
__stdio_common_vfprintf
_read
_write
fflush
fputc
fputs
fwrite
setvbuf
api-ms-win-crt-string-l1-1-0.dll _stricmp
memset
strcmp
strlen
strncmp
strnlen
wcslen
wcsnlen
api-ms-win-crt-utility-l1-1-0.dll rand_s

Delayed Imports

1

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x2c6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.31884
MD5 9ad96638d72bbbbc6440da9c856e4c39 🔍
SHA1 29afb0ef053afc70b447be919383f8c8fd562df9 🔍
SHA256 e989bc9ba32a3f5b1f5a565d5971e07462a2d6a504e7af682bd36cc8cc263f29 🔍
SHA3 bc609fa29e449d5658a65d53fff8f9bf73c07e46d140fc507870fc7b6a6f9857 🔍

Version Info

TLS Callbacks

StartAddressOfRawData 0x14003c000
EndAddressOfRawData 0x14003c018
AddressOfIndex 0x14002b010
AddressOfCallbacks 0x140032820
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0!
Leave a comment

No comments yet.