9d29c23a4b0bf6003fdd7ce2e4a14a157ecb9974f7cf76b079490c7f2ad972d9

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2062-Feb-13 08:08:21
CompanyName RisxnInstaller
FileDescription RisxnInstaller
FileVersion 1.0.0.0
InternalName RisxnInstaller.dll
LegalCopyright
OriginalFilename RisxnInstaller.dll
ProductName RisxnInstaller
ProductVersion 1.0.0
Assembly Version 1.0.0.0

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to security software:
  • GMT.EXE
Contains domain names:
  • github.com
  • http://schemas.microsoft.com
  • http://schemas.microsoft.com/expression/blend/2008
  • http://schemas.microsoft.com/winfx/2006/xaml
  • http://schemas.microsoft.com/winfx/2006/xaml/presentation
  • http://schemas.openxmlformats.org
  • http://schemas.openxmlformats.org/markup-compatibility/2006
  • https://files.catbox.moe
  • https://files.catbox.moe/d2zdyj.bat
  • https://github.com
  • https://scripts.sil.org
  • https://scripts.sil.org/OFLThis
  • https://scripts.sil.org/OFLwww.rfuenzalida.comwww.fragtypefoundry.xyzRodrigo
  • microsoft.com
  • openxmlformats.org
  • schemas.microsoft.com
  • schemas.openxmlformats.org
  • scripts.sil.org
Suspicious The PE is possibly packed. The PE only has 0 import(s).
Malicious VirusTotal score: 7/69 (Scanned on 2026-07-23 03:03:55) APEX: Malicious
Bkav: W32.Malware.F8613DB5
CrowdStrike: win/malicious_confidence_90% (W)
Elastic: malicious (moderate confidence)
Microsoft: Trojan:Win32/Wacatac.B!ml
SentinelOne: Static AI - Suspicious PE
TrendMicro-HouseCall: Trojan.MSIL.Gen.TL0101GC26Z7

Hashes

MD5 76bf80c314da3373c1c12760ec75ce96
SHA1 9b5d2453ea20dd271e7578f5ddf9419dd921a7ed
SHA256 9d29c23a4b0bf6003fdd7ce2e4a14a157ecb9974f7cf76b079490c7f2ad972d9
SHA3 9e5205c8cb02617be4034489426a260f6e324b37bed27b06e067ae3fa93e8822
SSDeep 12288:9ff3uIOHUHkAybcuvtPYOJjms25I6UdBcc7F4x4GjGPPPPPPPpX5:xBrgtwOpMfUdT1GqPPPPPPPpX5
Imports Hash d41d8cd98f00b204e9800998ecf8427e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 2
TimeDateStamp 2062-Feb-13 08:08:21
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 48.0
SizeOfCode 0x11d200
SizeOfInitializedData 0x1200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000000000 (Section: ?)
BaseOfCode 0x2000
ImageBase 0x400000
SectionAlignment 0x2000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x122000
SizeOfHeaders 0x200
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x400000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x2000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 75f6bfbec6e8ef94cb293c1559d6bb60
SHA1 8baf5a832d3935160e8e84cf809dc4b8a74f1383
SHA256 d27d329e13eaed44b508af39b6890b70526212f698be970af481648ec854e90e
SHA3 c7e855b40f0a1b23ab8574d1c54e5d3d2d36aa2e8d2ea599fa950784f6b01d8a
VirtualSize 0x11d014
VirtualAddress 0x2000
SizeOfRawData 0x11d200
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.93393

.rsrc

MD5 4503e657f58fcbec43c74068fd9a3f6a
SHA1 027beb28a2e3bb7f93d1f69269c1894e80cff276
SHA256 b3e9387419f63d79957ee50e3a4242c27db5605cc1ac40eae27a014356d8e985
SHA3 4cae9c4c45ad939018178af4498b9bcd1fa1261567461114658318288c051307
VirtualSize 0x10ef
VirtualAddress 0x120000
SizeOfRawData 0x1200
PointerToRawData 0x11d400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.92253

Imports

Delayed Imports

1

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x2fc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.19144
MD5 f15f7f3dc8b5b04562df945c1a116906
SHA1 e9f253bc73335b700b41289f24e74310d27a906d
SHA256 3e18dccd0245260efdb0924987e8d7e624525c479ce69e7d3bd33d74ecf4b974
SHA3 3a07a3bf7b29e7829fc4487754c2d005e74520b4740462fb7b19dd8b90086167

1 (#2)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0xd53
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.01752
MD5 a99c09dbd4a65da324e2d732f5351786
SHA1 164d3ec47c9487bd42d9ec580fb730a61dc156d7
SHA256 59c778ad5af1032a264960d8cf35e7b4226e9ab5d1d9cbe91d4f93b347768b88
SHA3 5e12a029662dd5cc2e838e5e40d2e0715685e718c429233ccb2e35881abdd4e6

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName RisxnInstaller
FileDescription RisxnInstaller
FileVersion (#2) 1.0.0.0
InternalName RisxnInstaller.dll
LegalCopyright
OriginalFilename RisxnInstaller.dll
ProductName RisxnInstaller
ProductVersion (#2) 1.0.0
Assembly Version 1.0.0.0
Resource LangID UNKNOWN

TLS Callbacks

Load Configuration

RICH Header

Errors

Leave a comment

No comments yet.