992434a874c5c4e1e31dce54870650163d2d2d55bae6ad7d09f85e1fa55844a6

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Aug-29 03:39:00
Detected languages English - United States

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • virus
Contains domain names:
  • https://fontawesome.comFont
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • FindWindowA
Code injection capabilities (PowerLoader):
  • FindWindowA
  • GetWindowLongW
Possibly launches other programs:
  • ShellExecuteW
Uses functions commonly found in keyloggers:
  • CallNextHookEx
  • GetAsyncKeyState
  • GetForegroundWindow
Manipulates other processes:
  • OpenProcess
  • Process32NextW
  • Process32FirstW
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 175870b3a7f10d4bf5c04da70fed3d26 🔍
SHA1 a178bfcf82cbae7e41925711f489e4a09dd1f746 🔍
SHA256 992434a874c5c4e1e31dce54870650163d2d2d55bae6ad7d09f85e1fa55844a6 🔍
SHA3 f7ed525585eafe478dc1a745d9ff751265895b75853c8bbc48e2a37aa4489001 🔍
SSDeep 24576:8li3qmg9bbf/OGqf/JHG0ZXiDvtvQGTgnnYUo3RbS:8liamg9nWGqfJZyDvenYg 🔍
Imports Hash 748552427045f4a48163debe222931a6 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-29 03:39:00
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xb5400
SizeOfInitializedData 0xa5200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000B0BFC (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x15f000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 b758da16e0a5af20be458bfd1ef5eb19 🔍
SHA1 3f2b13dc10c92c6185d7ece1f005c00e0fe3b135 🔍
SHA256 de809af48ae3f356b352478b29c755f64a79625c055c5c1efb38b70dabe7a44e 🔍
SHA3 3df41c4cfe3c259da08ad40a4cb89a3ce0a5498c4569a996196896d968da0f32 🔍
VirtualSize 0xb5373
VirtualAddress 0x1000
SizeOfRawData 0xb5400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.49009

.rdata

MD5 4d434db569a2986c6b0464026238034a 🔍
SHA1 86f98b8fb731494d89170e79b6fa895940b88ac2 🔍
SHA256 73107139b44bc46c2cfe8695a5a78f29c30213e3257ee6e0340a8a8b17379213 🔍
SHA3 fed71ff8416dd51ca5ad99e76bc6e4c05899be9c24d4383ab10e0df610cc9c76 🔍
VirtualSize 0x858f6
VirtualAddress 0xb7000
SizeOfRawData 0x85a00
PointerToRawData 0xb5800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.26356

.data

MD5 0edcf0c73293b46c5c35164e11b58f87 🔍
SHA1 0d0d8939fa9a6ce4bd00438b3971d641498420f7 🔍
SHA256 01a1a4362c78488c5716a75ce1005b5f192f1dbb0012484af4942d297748e45e 🔍
SHA3 7c4823564b36f5f3702afe3a70619ade98345ee5ae3fc1c5146a58812ce4db87 🔍
VirtualSize 0x172d0
VirtualAddress 0x13d000
SizeOfRawData 0x1800
PointerToRawData 0x13b200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.39668

.pdata

MD5 fe7f24d72c6207cc5b676b688ed7f72a 🔍
SHA1 4acd5f1b9743f3c0244c562ad8f62a58e94b7386 🔍
SHA256 df644658b222bb2325164233d179eb1789748013c8c4875a91a439252c9ec682 🔍
SHA3 520b1f9669be5a707cade35410ffab61e12ec4cdbda7e8c504f2f376e974089e 🔍
VirtualSize 0x7944
VirtualAddress 0x155000
SizeOfRawData 0x7a00
PointerToRawData 0x13ca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.98348

.rsrc

MD5 f423c3f39de7c7484e2714ab3167b58d 🔍
SHA1 1718b6369f8f9820b8aad86895e311285c7413fd 🔍
SHA256 fffa461740fa8121a9aa046074868719835532a6c7db5aa1786d95b714d875a8 🔍
SHA3 fc0791d4f093cc7106a7ee030601e0e7cf4ee0b1b7ce889f0b8e122fb309fde3 🔍
VirtualSize 0x1e0
VirtualAddress 0x15d000
SizeOfRawData 0x200
PointerToRawData 0x144400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.71768

.reloc

MD5 c22aa1261394f1fae4abe5f7312de4b3 🔍
SHA1 14cd8d5c0f9cee9f517fc964b691dbc4c8bc8a5d 🔍
SHA256 395c21f3d394e606dce9d5cac2fb09988aa518140d9dd730121fd68e14126bfa 🔍
SHA3 cea3154c608afdf61a006d3a438799ca50fdb3ecb27f213616e979beb69e9d1d 🔍
VirtualSize 0x694
VirtualAddress 0x15e000
SizeOfRawData 0x800
PointerToRawData 0x144600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.95541

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
d3dx11_43.dll D3DX11CreateShaderResourceViewFromMemory
freetype.dll FT_Load_Glyph
FT_New_Memory_Face
FT_Activate_Size
FT_Request_Size
FT_New_Library
FT_Render_Glyph
FT_GlyphSlot_Embolden
FT_Library_Version
FT_Done_Face
FT_Select_Charmap
FT_Done_Size
FT_Get_Char_Index
FT_Done_Library
FT_New_Size
FT_Add_Default_Modules
FT_GlyphSlot_Oblique
KERNEL32.dll CreateDirectoryW
GetLocaleInfoEx
GetFileInformationByHandleEx
GetConsoleScreenBufferInfo
SetConsoleTextAttribute
GetStdHandle
MultiByteToWideChar
FreeConsole
WriteConsoleW
AllocConsole
SetConsoleTitleW
GetLocaleInfoA
LoadLibraryA
QueryPerformanceFrequency
IsDBCSLeadByte
GetProcAddress
FreeLibrary
QueryPerformanceCounter
GlobalAlloc
GlobalFree
GlobalLock
WideCharToMultiByte
GlobalUnlock
GetModuleHandleW
Sleep
GetCurrentProcessId
WaitForSingleObject
CreateEventW
SetEvent
CloseHandle
CreateThread
CreateFileW
GetTickCount64
GetProcessId
OpenProcess
CreateToolhelp32Snapshot
Process32NextW
Process32FirstW
LoadLibraryW
Module32FirstW
Module32NextW
lstrcmpiW
FindClose
FormatMessageA
LocalFree
InitializeSListHead
GetSystemTimeAsFileTime
GetCurrentThreadId
GetStartupInfoW
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
GetCurrentProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
SleepConditionVariableSRW
WakeAllConditionVariable
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
SetFileInformationByHandle
FindFirstFileW
FindFirstFileExW
FindNextFileW
AreFileApisANSI
GetLastError
GetFileAttributesExW
GetTickCount
USER32.dll EnumWindows
FindWindowA
SendInput
GetMessageW
CallNextHookEx
GetAsyncKeyState
SetWindowDisplayAffinity
UnhookWindowsHookEx
LoadCursorW
SetWindowsHookExW
PostThreadMessageW
GetWindowThreadProcessId
GetSystemMetrics
GetWindowLongW
GetWindowRect
DestroyWindow
SetWindowPos
SetWindowLongPtrW
CreateWindowExW
UnregisterClassW
GetWindowLongPtrW
RegisterClassExW
ShowWindow
SetLayeredWindowAttributes
LoadIconW
SetWindowLongW
PostQuitMessage
UpdateWindow
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
DefWindowProcW
GetKeyState
IsWindow
GetKeyboardLayout
TrackMouseEvent
SetCapture
ClientToScreen
SetCursor
GetClientRect
IsWindowUnicode
GetCapture
GetForegroundWindow
ReleaseCapture
SetCursorPos
ScreenToClient
GetCursorPos
DispatchMessageW
PeekMessageW
TranslateMessage
GetMessageExtraInfo
SHELL32.dll ShellExecuteW
SHGetKnownFolderPath
ole32.dll CoTaskMemFree
D3DCOMPILER_47.dll D3DCompile
dwmapi.dll DwmExtendFrameIntoClientArea
IMM32.dll ImmSetCompositionWindow
ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow
MSVCP140.dll ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?_Syserror_map@std@@YAPEBDH@Z
?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?_Xbad_function_call@std@@YAXXZ
?_Winerror_map@std@@YAHH@Z
?_Xbad_alloc@std@@YAXXZ
??7ios_base@std@@QEBA_NXZ
?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z
?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
_Query_perf_frequency
?_Throw_Cpp_error@std@@YAXH@Z
_Mtx_lock
_Cnd_do_broadcast_at_thread_exit
_Query_perf_counter
_Thrd_detach
_Mtx_unlock
?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?_Xout_of_range@std@@YAXPEBD@Z
?_Xlength_error@std@@YAXPEBD@Z
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Id_cnt@id@locale@std@@0HA
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?always_noconv@codecvt_base@std@@QEBA_NXZ
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __std_exception_copy
__std_terminate
__C_specific_handler
memmove
strchr
__current_exception
memset
__current_exception_context
_CxxThrowException
memcpy
memchr
memcmp
__std_exception_destroy
api-ms-win-crt-string-l1-1-0.dll strncpy
strncmp
strcmp
strcpy_s
tolower
api-ms-win-crt-stdio-l1-1-0.dll __p__commode
_get_stream_buffer_pointers
_fseeki64
fsetpos
ungetc
fgetc
fputc
__stdio_common_vsprintf_s
_set_fmode
__stdio_common_vsscanf
fread
_wfopen
fwrite
fseek
fclose
fflush
__acrt_iob_func
ftell
__stdio_common_vsprintf
fgetpos
setvbuf
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-heap-l1-1-0.dll malloc
free
_set_new_mode
_callnewh
api-ms-win-crt-convert-l1-1-0.dll strtoll
strtod
atof
strtoull
api-ms-win-crt-runtime-l1-1-0.dll _invoke_watson
_c_exit
_register_thread_local_exe_atexit_callback
exit
_initterm_e
_errno
_initterm
abort
_get_narrow_winmain_command_line
_set_app_type
_seh_filter_exe
_cexit
_beginthreadex
_crt_atexit
_exit
_register_onexit_function
_initialize_onexit_table
_initialize_narrow_environment
_configure_narrow_argv
terminate
api-ms-win-crt-filesystem-l1-1-0.dll _unlock_file
_lock_file
api-ms-win-crt-math-l1-1-0.dll _dsign
fmodf
logf
lroundf
powf
_dclass
_fdclass
acosf
ceilf
__setusermatherr
cosf
sinf
sqrtf
expf
api-ms-win-crt-locale-l1-1-0.dll localeconv
_configthreadlocale
___lc_codepage_func

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-29 03:39:00
Version 0.0
SizeofData 912
AddressOfRawData 0x12be54
PointerToRawData 0x12a654

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-29 03:39:00
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x14012c208
EndAddressOfRawData 0x14012c218
AddressOfIndex 0x14013ec58
AddressOfCallbacks 0x1400b8068
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14013d040

RICH Header

XOR Key 0xf4634d06
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 18
Imports (35207) 6
ASM objects (35207) 4
C objects (35207) 10
C++ objects (35207) 36
C objects (CVTCIL) (33145) 1
Imports (35228) 2
Imports (21202) 2
Imports (33145) 19
Total imports 352
C++ objects (LTCG) (35228) 31
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment
🔑 Transfer № H4553 from Coinbase. NEXT => graph.org/Bitcoin-Mini 16 hours ago
🔑 Transfer № H4553 from Coinbase. NEXT => graph.org/Bitcoin-Mining-08-27?hs=f63a22a8e52f1b0b32c77ac343841777& 🔑