a30d635253a77444c38cf25d439bb96cd913fd16b9d1d40898cb9014f4f43831

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 1970-Jan-01 00:00:00

Plugin Output

Suspicious PEiD Signature: HQR data file
Info Interesting strings found in the binary: Contains domain names:
  • .eq.github.com
  • .eq.golang.org
  • .hash.net
  • 2github.com
  • Gone1080readopensyncpipefilelinkStat.com
  • eq.github.com
  • eq.golang.org
  • github.com
  • golang.org
  • https://go.dev
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Suspicious The PE is possibly packed. Unusual section name found: .symtab
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • LoadLibraryExW
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Malicious VirusTotal score: 47/70 (Scanned on 2026-08-29 09:52:49) ALYac: Trojan.GenericKD.81179694
AVG: Win64:Malware-gen
AhnLab-V3: Trojan/Win.Generic.R788837
Alibaba: TrojanDropper:Win32/Generic.a96acaf6
Antiy-AVL: Trojan[PSW]/Win64.Salat
Arcabit: Trojan.Generic.D4D6B42E
Avast: Win64:Malware-gen
Avira: TR/W64.Malware
BitDefender: Trojan.GenericKD.81179694
Bkav: W32.Malware.FE7EE6EB
CAT-QuickHeal: Trojanpws.Win64
CTX: exe.trojan.salat
CrowdStrike: win/malicious_confidence_70% (D)
Cylance: Unsafe
Cynet: Malicious (score: 99)
DeepInstinct: MALICIOUS
ESET-NOD32: WinGo/TrojanDropper.Agent.NL trojan
Elastic: malicious (high confidence)
Emsisoft: Trojan.GenericKD.81179694 (B)
F-Secure: Trojan.TR/W64.Malware
Fortinet: W32/Agent.NL!tr
GData: Trojan.GenericKD.81179694
Google: Detected
Gridinsoft: Trojan.Win64.Agent.cl
K7AntiVirus: Trojan ( 005d95451 )
K7GW: Trojan ( 005d95451 )
Kaspersky: Trojan-PSW.Win64.Salat.ptx
Lionic: Trojan.Win32.Salat.i!c
Malwarebytes: Spyware.SalatStealer.GO
MaxSecure: Trojan.Malware.8328611.susgen
McAfeeD: ti!A30D635253A7
MicroWorld-eScan: Trojan.GenericKD.81179694
Microsoft: Trojan:Win32/Kepavll!rfn
Paloalto: generic.ml
Panda: Trj/PhxGD.A
Rising: Dropper.Agent!8.2F (CLOUD)
Sangfor: Trojan.Win32.Save.a
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
Tencent: Trojan.Win32.Stealer.16004537
Trapmine: suspicious.low.ml.score
TrellixENS: Artemis!E7D834EDF548
TrendMicro: Trojan.Win32.SALAT.USBLHN26
TrendMicro-HouseCall: Trojan.Win32.SALAT.USBLHN26
VIPRE: Trojan.GenericKD.81179694
Varist: W64/ABTrojan.KMYB-1688
alibabacloud: Trojan[dropper]:Multi/Agent.NE

Hashes

MD5 e7d834edf5487f8f3e8dfa36a6e0eb71 🔍
SHA1 d2b8b5b5974e8595a8b588f55d4e393e5595ee2d 🔍
SHA256 a30d635253a77444c38cf25d439bb96cd913fd16b9d1d40898cb9014f4f43831 🔍
SHA3 5a75511f13b3ee66b209a2ca16f0671eb3733eed0b4293ba29b890f957fdca72 🔍
SSDeep 196608:iGmMfff2q10we66W4Q1j+/snjsPsTPtUDQJ6Q:iGmMfffX0wJ6WT+/UjP+Q 🔍
Imports Hash d42595b695fc008ef2c56aabd8efd68e 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0x8b
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 8
TimeDateStamp 1970-Jan-01 00:00:00
PointerToSymbolTable 0xb1e400
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 3.0
SizeOfCode 0x2d6200
SizeOfInitializedData 0x52de00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000007C100 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 1.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0xb7f000
SizeOfHeaders 0x600
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 ef84502d81a4f01257d8ecc24fd321a5 🔍
SHA1 6cf16263e703530b3f194c7c052531525be37d85 🔍
SHA256 fdb78d5fca7bf16437b4376d5e6cbb4c928a0e8f84509c693ad1047db2382d69 🔍
SHA3 9263e39299d7fe8f3d880273acc8fb3dcf73dd7c6768e0031fd1450cb559f239 🔍
VirtualSize 0x2d61f1
VirtualAddress 0x1000
SizeOfRawData 0x2d6200
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.22733

.rdata

MD5 3f54570a0085277d5820546579a85466 🔍
SHA1 a57eeca64e6211a0b6407ea69130982d1f3019a9 🔍
SHA256 abfc4a568f03ec7e53a8856093fa034d3e63a05b70a615189ccc0f4b92853ec5 🔍
SHA3 280232b040d9c75153dc1c0cba47f2ab16cbac82f6a3a800e349e797c66d85c3 🔍
VirtualSize 0x2fa8a0
VirtualAddress 0x2d8000
SizeOfRawData 0x2faa00
PointerToRawData 0x2d6800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.60151

.data

MD5 22727fa8ad9f31fa91c7bb0550ce1469 🔍
SHA1 8723e20105111dde35167007d6034f8df0674d4f 🔍
SHA256 d160a1250886cd7a8418c79754ae86a0ab813e719f5933ed46a7156a5158592d 🔍
SHA3 3c93311432dfe04c2fe47c6353cb64c6ca3427358925504b6bb4ad2261ebf446 🔍
VirtualSize 0x588fb0
VirtualAddress 0x5d3000
SizeOfRawData 0x52de00
PointerToRawData 0x5d1200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.97151

.pdata

MD5 da707241689cf90221bebb12ecde6e4d 🔍
SHA1 c126e1d36aedd2fae59e284e1422090259ec57be 🔍
SHA256 fc1c8537d5a3802d408f956da26a47b1d70bb37c97f7f5adb384f14b62febb3e 🔍
SHA3 677cfb4e2d03f2997eca2d7c348ae2b2e3b9d154daa5d86aeb56c8b2c71b67b6 🔍
VirtualSize 0x10428
VirtualAddress 0xb5c000
SizeOfRawData 0x10600
PointerToRawData 0xaff000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.50615

.xdata

MD5 ed4be24205261f7ab4204e27e25077a6 🔍
SHA1 bfe5d7198c9e46534073071acff745863aac385a 🔍
SHA256 78a4b9ed09286700b889415d443806e81c05a1e9b297f2f3863278558f7bcb71 🔍
SHA3 866d79373f5ef526ed4efb5fbc1d15d9b8dbd72580f362e710d697e641776054 🔍
VirtualSize 0xb4
VirtualAddress 0xb6d000
SizeOfRawData 0x200
PointerToRawData 0xb0f600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.78321

.idata

MD5 c8c282c308d249bccd4ec4b743ea5637 🔍
SHA1 cb5a668849e209adf85c20bd248c89635350cbe6 🔍
SHA256 f1576e3c3aeecad8192ff45abd381fcdab9047df7ff61c6bd9c6f71644c0421f 🔍
SHA3 a0b8326555578ebefed64c8d445af542908eea57ad3330323f7952cf665b66c1 🔍
VirtualSize 0x53e
VirtualAddress 0xb6e000
SizeOfRawData 0x600
PointerToRawData 0xb0f800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.00912

.reloc

MD5 3e0082d04d2f724f2f186a60f01bf047 🔍
SHA1 53db95bdafca8afec038472498f18a0f44c2459d 🔍
SHA256 6f4cbf0d7dde5f4146ac1ee3a09f7076e948538795c1737786287e747f8adafc 🔍
SHA3 ef7a9d7b8b21ce6344f4237729310cfc3a051380b73fafce178e6ec49a95e7cc 🔍
VirtualSize 0xe500
VirtualAddress 0xb6f000
SizeOfRawData 0xe600
PointerToRawData 0xb0fe00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.43376

.symtab

MD5 07b5472d347d42780469fb2654b7fc54 🔍
SHA1 943ae54f4818e52409fbbaf60ffd71318d966b0d 🔍
SHA256 3e67f4a7d14b832ff2a2433e9cf0f6f5720821f67148a87c0ee2595a20c96c68 🔍
SHA3 a70a3e18515c06557b62676f2a8eb6d7d41962d8c9c7c49f4641c429cc65b977 🔍
VirtualSize 0x4
VirtualAddress 0xb7e000
SizeOfRawData 0x200
PointerToRawData 0xb1e400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.0203931

Imports

kernel32.dll WriteFile
WriteConsoleW
WerSetFlags
WerGetFlags
WaitForMultipleObjects
WaitForSingleObject
VirtualQuery
VirtualFree
VirtualAlloc
TlsAlloc
SwitchToThread
SuspendThread
SetWaitableTimer
SetProcessPriorityBoost
SetEvent
SetErrorMode
SetConsoleCtrlHandler
RtlVirtualUnwind
RtlLookupFunctionEntry
ResumeThread
RaiseFailFastException
PostQueuedCompletionStatus
LoadLibraryW
LoadLibraryExW
SetThreadContext
GetThreadContext
GetSystemInfo
GetSystemDirectoryA
GetStdHandle
GetQueuedCompletionStatusEx
GetProcessAffinityMask
GetProcAddress
GetErrorMode
GetEnvironmentStringsW
GetCurrentThreadId
GetConsoleMode
FreeEnvironmentStringsW
ExitProcess
DuplicateHandle
CreateWaitableTimerExW
CreateThread
CreateIoCompletionPort
CreateEventA
CloseHandle
AddVectoredExceptionHandler
AddVectoredContinueHandler

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

RICH Header

Errors

Leave a comment

No comments yet.