| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2021-Aug-14 18:32:30 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 31/70 (Scanned on 2026-07-12 23:03:23) |
AVG:
Win32:MalwareX-gen [Trj]
AhnLab-V3: Trojan/Win.Generic.R683476 Alibaba: HackTool:Win32/Generic.b7179c09 Antiy-AVL: Trojan/Win32.Agent Avast: Win32:MalwareX-gen [Trj] Avira: TR/W32.MalwareX Bkav: W32.Malware.53D8178A CTX: dll.trojan.generic CrowdStrike: win/grayware_confidence_100% (W) Cylance: Unsafe Cynet: Malicious (score: 100) DrWeb: Trojan.Siggen16.19619 Elastic: malicious (high confidence) F-Secure: Trojan.TR/W32.MalwareX Google: Detected Lionic: Trojan.Win32.Generic.4!c MaxSecure: Trojan.Malware.318522439.susgen McAfeeD: ti!8C5563F28D7E Microsoft: HackTool:Win32/Keygen Paloalto: generic.ml Rising: Hacktool.Keygen!8.B29 (CLOUD) Sangfor: Suspicious.Win32.Save.a Skyhigh: GenericRXQP-OG!E3C18DD5C84D Sophos: Generic Reputation PUA (PUA) Symantec: Trojan.Gen.MBT TrellixENS: GenericRXQP-OG!E3C18DD5C84D TrendMicro: PUA.Win32.GameHack.AVGO TrendMicro-HouseCall: PUA.Win32.GameHack.AVGO VBA32: Trojan.Wacatac Varist: W32/ABApplication.KETR-2979 Xcitium: Malware@#9sod1q8n2loq |
| MD5 | e3c18dd5c84dc9b9ca5bf0aa10d26f95 🔍 |
|---|---|
| SHA1 | 2f17493f23e9aee959f90c66db2e71c08328bfde 🔍 |
| SHA256 | 8c5563f28d7e630c746f7ece68e8c7b9c8abf952f195bd8d69f8e96c3cf21fdf 🔍 |
| SHA3 | 61c3b16415f603c65deab8b233addcf225cde083871372dd6672aeabc6a7b30b 🔍 |
| SSDeep | 49152:rfNunO7TbwVQc6A5RY7kw2R5TU2yqDCfFhdjN22Lj:TNunO7TbwVz6UY7kwApyqDCfjdT 🔍 |
| Imports Hash | 250a6454a31b8bb10418492cb9057108 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2021-Aug-14 18:32:30 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xf600 |
| SizeOfInitializedData | 0x18f000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00002AFC (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x11000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1a2000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | b5a521e3c48c3a3bfeefdf7157e766c2 🔍 |
|---|---|
| SHA1 | 900053f24faccd6ccd94c338e53242e1496db454 🔍 |
| SHA256 | 43fc0eee4868824d06ea6b3c5ff7e8c591bdf94e0336da1e71efa001a7a3fc45 🔍 |
| SHA3 | 7cc430cf0cfa3471820801e4f01cf79b4ec6266b908844dc8dc6f3c1afa90b0c 🔍 |
| VirtualSize | 0xf5f5 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0xf600 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.36642 |
| MD5 | 30f5a6bd0aac7553af8be6be3ba15b14 🔍 |
|---|---|
| SHA1 | 2a0305a4f078f2da59f00ce3f4ed85998dd4f9d0 🔍 |
| SHA256 | bfcba7ccbb388520ba5c31e20c7be46b2da016d802542fdd23e76e0d70943e12 🔍 |
| SHA3 | 312b32b3750745bb3dc2bfe345b2126e9e25719e8d07236bb4d7b44cdc3bfb42 🔍 |
| VirtualSize | 0x18dff4 |
| VirtualAddress | 0x11000 |
| SizeOfRawData | 0x18e000 |
| PointerToRawData | 0xfa00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.67252 |
| MD5 | aa8d1299fcf0c4348e2e732668317043 🔍 |
|---|---|
| SHA1 | bdd2490af1d6e4a5759bd16259207d39781b17e5 🔍 |
| SHA256 | 1281eb363ca7b1cd8259c7d9a6176cee534ab56438e6cdf83e2e4f1aaf42d4c3 🔍 |
| SHA3 | fa685abe18633e94a6ab837ae5d7a58f47a2115906a4643b78532e8730c028a1 🔍 |
| VirtualSize | 0x874 |
| VirtualAddress | 0x19f000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x19da00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 1.8985 |
| MD5 | 2e1d696970bb326f1ea03ec316eb55a5 🔍 |
|---|---|
| SHA1 | ce81e169823a364638d8ae7532775b136273efb3 🔍 |
| SHA256 | ee4dff81aa052a46e48d30185f1bc90be7aa2c7acd9fea15f2b4dd8cb56ccdae 🔍 |
| SHA3 | 9af95e9c62c47b00ccd404518bd29464bbc9395e25b0eef5ffa4d9fe1efe8adb 🔍 |
| VirtualSize | 0x1e0 |
| VirtualAddress | 0x1a0000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x19dc00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.70855 |
| MD5 | 6d16216f7a955cc5636774b0937e193e 🔍 |
|---|---|
| SHA1 | a48fd3813a25cc634849c63a7e2f6a4d087d48b9 🔍 |
| SHA256 | 2010a26d00efe6793007df2619408a90820865b460d867a72d96bf6685a413f5 🔍 |
| SHA3 | 209f2fc70dece4690437469c717b5dcf64988d09a26426ce5a76bd0d028c7366 🔍 |
| VirtualSize | 0x3c4 |
| VirtualAddress | 0x1a1000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x19de00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.18367 |
| KERNEL32.dll |
DisableThreadLibraryCalls
LoadLibraryA CloseHandle CreateThread GetProcAddress LeaveCriticalSection InitializeCriticalSectionAndSpinCount DeleteCriticalSection SetEvent ResetEvent WaitForSingleObjectEx CreateEventW GetModuleHandleW IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead GetCurrentProcess EnterCriticalSection TerminateProcess |
|---|---|
| MSVCP140.dll |
?_Xout_of_range@std@@YAXPBD@Z
?_Xlength_error@std@@YAXPBD@Z |
| VCRUNTIME140.dll |
memmove
__std_exception_copy strstr memset _CxxThrowException _except_handler4_common memcpy __std_exception_destroy __CxxFrameHandler3 __std_type_info_destroy_list |
| api-ms-win-crt-heap-l1-1-0.dll |
free
_callnewh malloc |
| api-ms-win-crt-string-l1-1-0.dll |
isdigit
tolower |
| api-ms-win-crt-runtime-l1-1-0.dll |
_initterm
_execute_onexit_table _register_onexit_function _initialize_onexit_table _configure_narrow_argv _seh_filter_dll _initterm_e _cexit _crt_atexit _initialize_narrow_environment _invalid_parameter_noinfo_noreturn |
| api-ms-win-crt-convert-l1-1-0.dll |
strtoul
atoi |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2021-Aug-14 18:32:30 |
| Version | 0.0 |
| SizeofData | 780 |
| AddressOfRawData | 0x19e4b8 |
| PointerToRawData | 0x19ceb8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2021-Aug-14 18:32:30 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1019e7d4 |
|---|---|
| EndAddressOfRawData | 0x1019e7dc |
| AddressOfIndex | 0x1019f0f4 |
| AddressOfCallbacks | 0x10011118 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0xa4 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1019f014 |
| SEHandlerTable | 0x1019e4b0 |
| SEHandlerCount | 2 |
| XOR Key | 0x26fe30b6 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 8 |
| C++ objects (VS2019 Update 2 (16.2) compiler 27905) | 18 |
| C objects (VS2019 Update 2 (16.2) compiler 27905) | 10 |
| ASM objects (VS2019 Update 2 (16.2) compiler 27905) | 3 |
| Imports (VS2019 Update 2 (16.2) compiler 27905) | 4 |
| Imports (VS2017 v14.15 compiler 26715) | 3 |
| Total imports | 68 |
| C++ objects (LTCG) (VS2019 Update 3 (16.3) compiler 28107) | 5 |
| Resource objects (VS2019 Update 3 (16.3) compiler 28107) | 1 |
| Linker (VS2019 Update 3 (16.3) compiler 28107) | 1 |
No comments yet.