| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Oct-08 15:02:56 |
| Detected languages |
English - United States
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| MD5 | cfdc51a89e329588277da57e748209ea 🔍 |
|---|---|
| SHA1 | 080fb6bc12e8316470db74f8a15580b1d81cff95 🔍 |
| SHA256 | a6f8b4f39a303aaea13fcdb0c243faac9c38abd976bd2f19d556e5ce9e494102 🔍 |
| SHA3 | fb2f10e58e6829cabf72d983e9fe203ddbc1cefb65e00c0c24cc55e6a56bf425 🔍 |
| SSDeep | 196608:OcJNHE27YBCF/AbEepRxoJua7BIDmg/Htumr3U/3qKySMkHG7FoXJm+kLS3/hys:R7MYobEkohIDmonw6KySJHGBoX4yPQs 🔍 |
| Imports Hash | 7e256579048a66670b7396979874230e 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x128 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Oct-08 15:02:56 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x1e1c00 |
| SizeOfInitializedData | 0x968c00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000019FA00 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xb4f000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 198e86f82d165d0f683cb47bbe497ca4 🔍 |
|---|---|
| SHA1 | 17467165e0ca3f4755f6c0a3329f6ea80412f437 🔍 |
| SHA256 | 4a313588e4d7b88294bed8828cc447af94fda69c3fc63e6604134b4bdbe20c7b 🔍 |
| SHA3 | db35f84c04c4a4f0a170a5c9d3b559da3f1d082469a747be8cf1ed6a2494dfd7 🔍 |
| VirtualSize | 0x1e1a8c |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x1e1c00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.56913 |
| MD5 | b5fd4ed4fd4a8f14fc87415abf574e7b 🔍 |
|---|---|
| SHA1 | f59131206f7fee693d9c64afa0ba7430acb9d15c 🔍 |
| SHA256 | 5bf3e2e3a8187ad9b15a41dc09cd5478b27bffe9e5cf337f69cea2160865c2af 🔍 |
| SHA3 | c76363f5f49447d116c201eb942cea26892c5c3e25e73f706d94853422b6e90d 🔍 |
| VirtualSize | 0x94f400 |
| VirtualAddress | 0x1e3000 |
| SizeOfRawData | 0x94f400 |
| PointerToRawData | 0x1e2000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 7.52876 |
| MD5 | 7e3b66f6da6f3d520f64c92b80506724 🔍 |
|---|---|
| SHA1 | 269a72d6f1981e97422ca33e29581ae678827a8c 🔍 |
| SHA256 | 98d9b5e1210216c54c10f3373bc920b5bdf2f6564759db8e1910149eb4332e0f 🔍 |
| SHA3 | adeb9071cb7627e87699211f8521452c2bd334fadfc735ebe49bd7e568869d91 🔍 |
| VirtualSize | 0x5634 |
| VirtualAddress | 0xb33000 |
| SizeOfRawData | 0x2e00 |
| PointerToRawData | 0xb31400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.20029 |
| MD5 | f350e56af717a5052f68de8f95492084 🔍 |
|---|---|
| SHA1 | 9a3533fae757fae2ffa14a36ec0111331dc8d75e 🔍 |
| SHA256 | 272b5fd61e11c14fccecb3900ea701e48cb8ef2da57e5254cf3502bfbc0eb89d 🔍 |
| SHA3 | d72ace754be11f488a6d304a7986b5f9ca603a1eaee348c994584d5ffab676c3 🔍 |
| VirtualSize | 0x123cc |
| VirtualAddress | 0xb39000 |
| SizeOfRawData | 0x12400 |
| PointerToRawData | 0xb34200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.21616 |
| MD5 | ebc1f6aa01407446bd55ad14cf925a83 🔍 |
|---|---|
| SHA1 | fff37aff68f8357aa41090e2734181ff21ce7b99 🔍 |
| SHA256 | 1da168b42fa6b74649e49c0908352ca6b37609c8e6f9dc422b961edcd8ff8a0f 🔍 |
| SHA3 | d88638e81af1a8a343cbb1e27acefcb2e98efa905103bf483791aaef8200ea3b 🔍 |
| VirtualSize | 0x1e0 |
| VirtualAddress | 0xb4c000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0xb46600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.71768 |
| MD5 | 63a3901a58f22b0b46ca4ea2cd31cb5b 🔍 |
|---|---|
| SHA1 | dc50acff08136e8b0c98f6c8cf89b39a0d15d0fb 🔍 |
| SHA256 | 34ff649e952fbf45686aa8978ff8af0400b67520ce48619850907d8f00432ea2 🔍 |
| SHA3 | eff519f806ea0dedeeef09508f45ee726d6d2fd3810616f5a4667a4fd4ab23b2 🔍 |
| VirtualSize | 0x18e0 |
| VirtualAddress | 0xb4d000 |
| SizeOfRawData | 0x1a00 |
| PointerToRawData | 0xb46800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.33914 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| D3DCOMPILER_43.dll |
D3DCompile
|
| KERNEL32.dll |
GetTempPathW
FindClose CreateFileW GetFileAttributesW SetFileAttributesW Sleep GetTickCount64 GetLastError GetFileAttributesA MoveFileExA CreateFileA DeleteFileW CloseHandle Beep LocalFree ExitProcess GetSystemTimeAsFileTime MoveFileW GetFileTime GetModuleHandleW OpenProcess CreateToolhelp32Snapshot Process32NextW Process32FirstW K32GetModuleBaseNameA K32GetModuleInformation Module32FirstW Module32NextW K32EnumProcessModules VirtualAllocEx GetCurrentProcessId VirtualFreeEx VirtualQueryEx GetStartupInfoW LoadLibraryW ReadFile HeapAlloc HeapReAlloc HeapFree GetProcessHeap MapViewOfFile UnmapViewOfFile CreateFileMappingA GetEnvironmentStringsW GetCommandLineA GetOEMCP GetACP IsValidCodePage GetTimeZoneInformation ReadConsoleW EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW LoadLibraryExW VirtualProtect GetConsoleMode GetConsoleOutputCP FlushFileBuffers SetFilePointerEx SetEndOfFile UnhandledExceptionFilter IsDebuggerPresent RtlVirtualUnwind RtlCaptureContext WriteFile GetStdHandle TerminateProcess IsProcessorFeaturePresent GetModuleHandleExW FreeLibraryAndExitThread ExitThread CreateThread RtlUnwind FlsFree FlsSetValue FlsGetValue FlsAlloc SetLastError RaiseException RtlPcToFileHeader RtlUnwindEx RtlLookupFunctionEntry SetFilePointer FindNextFileA GetModuleFileNameW SetFileTime GetCurrentProcess FindNextFileW GetCommandLineW FindFirstFileA GetFileSizeEx MoveFileA FindFirstFileW GetVolumeInformationW QueryDosDeviceW GlobalUnlock WideCharToMultiByte GlobalLock GlobalFree GlobalAlloc QueryPerformanceCounter FreeLibrary GetProcAddress QueryPerformanceFrequency LoadLibraryA MultiByteToWideChar WriteConsoleW GetLocaleInfoA GetModuleHandleA GetLocalTime GetTempPathA FreeEnvironmentStringsW InitializeSListHead SetUnhandledExceptionFilter GetCPInfo WakeAllConditionVariable LCMapStringEx DecodePointer EncodePointer DeleteCriticalSection InitializeCriticalSectionEx LeaveCriticalSection EnterCriticalSection GetStringTypeW SleepConditionVariableSRW AcquireSRWLockExclusive ReleaseSRWLockExclusive GetExitCodeThread WaitForSingleObjectEx GetCurrentThreadId GetSystemTimePreciseAsFileTime GetFileInformationByHandleEx AreFileApisANSI CreateFile2 SetFileInformationByHandle GetFileAttributesExW FindFirstFileExW SetEnvironmentVariableW SetStdHandle HeapSize GetFileType FormatMessageA GetLocaleInfoEx CreateDirectoryW |
| USER32.dll |
LoadCursorW
GetForegroundWindow GetKeyboardLayout TrackMouseEvent ClientToScreen GetCapture ScreenToClient GetMessageExtraInfo GetKeyState SetClipboardData GetClipboardData EmptyClipboard CloseClipboard SetCursor SendInput GetSystemMetrics TranslateMessage PeekMessageW DispatchMessageW mouse_event GetWindowTextW EnumWindows GetWindowTextLengthW GetWindowThreadProcessId SetForegroundWindow GetClientRect GetAsyncKeyState GetCursorPos SetCursorPos SetCapture IsWindowUnicode OpenClipboard ShowWindow UpdateWindow DefWindowProcW CreateWindowExW RegisterClassExW SetWindowLongW MapWindowPoints MoveWindow SetLayeredWindowAttributes ReleaseCapture |
| ADVAPI32.dll |
RegEnumKeyExA
RegQueryValueExW RegEnumValueW RegDeleteValueA RegDeleteValueW RegEnumValueA RegGetValueW RegOpenKeyExW LookupPrivilegeValueW AdjustTokenPrivileges RegCloseKey RegQueryValueExA AllocateAndInitializeSid RegSetValueExW RegSetValueExA OpenProcessToken FreeSid CheckTokenMembership RegOpenKeyExA |
| SHELL32.dll |
SHGetFolderPathA
CommandLineToArgvW SHGetKnownFolderPath ShellExecuteA |
| ole32.dll |
CoTaskMemFree
|
| d3dx11_43.dll |
D3DX11CreateShaderResourceViewFromMemory
|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| WS2_32.dll |
setsockopt
htons inet_ntop htonl recv connect socket send getsockname WSAStartup inet_pton listen select closesocket bind accept WSACleanup |
| bcrypt.dll |
BCryptEncrypt
BCryptDestroyKey BCryptDecrypt BCryptOpenAlgorithmProvider BCryptFinishHash BCryptCloseAlgorithmProvider BCryptDestroyHash BCryptHashData BCryptSetProperty BCryptGenerateSymmetricKey |
| IMM32.dll |
ImmGetContext
ImmSetCandidateWindow ImmReleaseContext ImmSetCompositionWindow |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Oct-08 15:02:56 |
| Version | 0.0 |
| SizeofData | 1068 |
| AddressOfRawData | 0xb109c8 |
| PointerToRawData | 0xb0f9c8 |
| StartAddressOfRawData | 0x140b10e40 |
|---|---|
| EndAddressOfRawData | 0x140b10e48 |
| AddressOfIndex | 0x140b36510 |
| AddressOfCallbacks | 0x1401e3a48 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140b33180 |
| XOR Key | 0x5f9edce0 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (35222) | 185 |
| C objects (35222) | 30 |
| ASM objects (35222) | 28 |
| 253 (35721) | 1 |
| ASM objects (35721) | 17 |
| C objects (35721) | 18 |
| C++ objects (35721) | 97 |
| C objects (CVTCIL) (35222) | 1 |
| Imports (35222) | 22 |
| C objects (VS2022 Update 1 (17.1.6) compiler 31107) | 26 |
| Imports (21202) | 7 |
| Total imports | 301 |
| C++ objects (LTCG) (36252) | 56 |
| Resource objects (36252) | 1 |
| Linker (36252) | 1 |
No comments yet.