| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Sep-22 04:03:54 |
| TLS Callbacks | 3 callback(s) detected. |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| MD5 | 8cbb269514c8ca8c16695bae39e7ef3a 🔍 |
|---|---|
| SHA1 | 437db39480636f065d5f4b6e7e55f261cb14c595 🔍 |
| SHA256 | 815069f4179ad3a84bb0c312ac3fa65915064be2e912ffd4d6cb3b633be69b31 🔍 |
| SHA3 | 747ab5c9f4fa2cf4e47f248469aa12760666c861bd6177b7dee2dd3e68a1c497 🔍 |
| SSDeep | 3072:z4qJ50pMXGhlWBBbPFh9LhE8fArQJQ45s/h4:z30p0Bv54QJQ4h 🔍 |
| Imports Hash | b294465520c73426822299a427dff5b6 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 9 |
| TimeDateStamp | 2026-Sep-22 04:03:54 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x13c00 |
| SizeOfInitializedData | 0x6000 |
| SizeOfUninitializedData | 0xc00 |
| AddressOfEntryPoint | 0x00000000000013F0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x20000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | e5ac67eee4e502abd8eae8bba00fc7a4 🔍 |
|---|---|
| SHA1 | b3fb735b1a6a249b35ee33106c7b9f3843f5375b 🔍 |
| SHA256 | 1de6a1c422f0b82bfc59b2e306e74bbd33b9af763a4155ffc84f3b19be1866b1 🔍 |
| SHA3 | 991fb5186b77279e887c5abd8b42f952bd4645c7a711cd42ed83c7daa450eb7d 🔍 |
| VirtualSize | 0x13b20 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x13c00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.10344 |
| MD5 | 543d36df237392a866dc9f8c19580adc 🔍 |
|---|---|
| SHA1 | e50aaa54dfdefa300aa955e58d5f8b3d7917dc37 🔍 |
| SHA256 | 6424690eac2dbafa7a016e7c2792167cc8d109fbfa20ecdcd6ffc7c0dfffb58c 🔍 |
| SHA3 | 622e36df0968f14e170e3aefa921096921fe65b561c10e339727dfe153f5a60f 🔍 |
| VirtualSize | 0x2d0 |
| VirtualAddress | 0x15000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x14000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 1.47066 |
| MD5 | bc846c77f20b0131d631fa963def6ce7 🔍 |
|---|---|
| SHA1 | d9084fab019196cccba4855ad2b2fdc6ac16d084 🔍 |
| SHA256 | 4f484425b99235ccffc1123d70062a5704018fd32cc4d3905dbe9f790848a28a 🔍 |
| SHA3 | 987f9a3e211130d0790b90f52af481b5986769b12e9fb6ed7391dfffde917c16 🔍 |
| VirtualSize | 0x1ae0 |
| VirtualAddress | 0x16000 |
| SizeOfRawData | 0x1c00 |
| PointerToRawData | 0x14400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.03881 |
| MD5 | 5bcfd2c7911c22722d282ec3c4048384 🔍 |
|---|---|
| SHA1 | 81b05a45892de1d8a71656b34525b9402f746b2f 🔍 |
| SHA256 | 110ae3f41da50f6939967146fb2b2268ecf666d662eada435f3bfc9b9d5226c1 🔍 |
| SHA3 | 7ebfa3d8fae9fae6677c888b715f9d15d4363a5c10ce23730650f3d9e7651578 🔍 |
| VirtualSize | 0x18c0 |
| VirtualAddress | 0x18000 |
| SizeOfRawData | 0x1a00 |
| PointerToRawData | 0x16000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.72049 |
| MD5 | 057fe70bde0937ad12066bce18b04137 🔍 |
|---|---|
| SHA1 | ef52be0b72ca0e507b851abc96280eee0b2b0be7 🔍 |
| SHA256 | af0093f2ca36500a49e29d8b8102ab1d02376df79b6b93eefc082ce728d0c7c2 🔍 |
| SHA3 | fedce6aab2e7826f25dcdda2789c669a6f86a79a4a29bf148d510f1d20fa7111 🔍 |
| VirtualSize | 0x12ac |
| VirtualAddress | 0x1a000 |
| SizeOfRawData | 0x1400 |
| PointerToRawData | 0x17a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 3.1188 |
| MD5 | d41d8cd98f00b204e9800998ecf8427e 🔍 |
|---|---|
| SHA1 | da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍 |
| SHA256 | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍 |
| SHA3 | a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍 |
| VirtualSize | 0xba0 |
| VirtualAddress | 0x1c000 |
| SizeOfRawData | 0 |
| PointerToRawData | 0 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| MD5 | cbf23252e63d80bdc1b78304256ec65c 🔍 |
|---|---|
| SHA1 | 78281b6fd305f52ddd0f826375e72400dda468c8 🔍 |
| SHA256 | 803c675823c55ab6b62964832e5549549d076c84b60a23851f845a44002c1c49 🔍 |
| SHA3 | beaed32e41b449c20b2de6b375883c35285487f9505fb46b155840851bf16a60 🔍 |
| VirtualSize | 0xdd4 |
| VirtualAddress | 0x1d000 |
| SizeOfRawData | 0xe00 |
| PointerToRawData | 0x18e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 3.88545 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x10 |
| VirtualAddress | 0x1e000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x19c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | e00d1025b69c2b5c7fce3a0839f9197b 🔍 |
|---|---|
| SHA1 | a229a3eefef5de37b455e4143ac36b3f1c132f3e 🔍 |
| SHA256 | 74a8259d942fed468ac19cd25b4bcaf1bed934d315ba167af273be01b9e70922 🔍 |
| SHA3 | 39ce49032aa6aeb7536f7c86bf4f95c30111ccce4eef362e606c026042489838 🔍 |
| VirtualSize | 0x98 |
| VirtualAddress | 0x1f000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x19e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 1.94263 |
| KERNEL32.DLL |
CloseHandle
CreateFileA CreateProcessA CreateThread CreateWaitableTimerA DeleteCriticalSection DeleteFileA EnterCriticalSection ExitProcess FreeLibrary GetCurrentThread GetLastError GetModuleFileNameA GetModuleHandleA GetProcAddress GetSystemTimeAsFileTime InitializeCriticalSection IsDBCSLeadByteEx IsDebuggerPresent LeaveCriticalSection LoadLibraryA MultiByteToWideChar ReadFile SetUnhandledExceptionFilter SetWaitableTimer Sleep TlsGetValue VirtualProtect VirtualQuery WaitForSingleObject WideCharToMultiByte WriteFile |
|---|---|
| msvcrt.dll |
__C_specific_handler
___lc_codepage_func ___mb_cur_max_func __getmainargs __initenv __iob_func __set_app_type __setusermatherr _amsg_exit _cexit _commode _errno _fmode _initterm _lock _onexit _strnicmp _unlock abort calloc clock exit fclose fgetc fgets fopen fprintf fputc free fwrite getc isspace isxdigit localeconv malloc memcpy memset perror realloc signal strcmp strcpy strcspn strerror strlen strncmp strncpy strrchr strstr strtol strtoul tolower ungetc vfprintf wcslen _strtoui64 _strtoi64 |
| WS2_32.dll |
WSACleanup
WSAStartup bind closesocket connect freeaddrinfo getaddrinfo htons recv send socket |
| StartAddressOfRawData | 0x14001e000 |
|---|---|
| EndAddressOfRawData | 0x14001e008 |
| AddressOfIndex | 0x14001c08c |
| AddressOfCallbacks | 0x140017ab0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x0000000140001480
0x0000000140006AF0 0x0000000140006AC0 |
No comments yet.