b07de66a4e8dca3009e5dca31321105c9bfefe07f13e4fa2c4c5df4861a521dc

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Oct-10 15:11:24
TLS Callbacks 1 callback(s) detected.

Plugin Output

Info Cryptographic algorithms detected in the binary: Uses constants related to SHA256
Uses constants related to SHA512
Suspicious The PE is packed with UPX Unusual section name found: UPX0
Section UPX0 is both writable and executable.
Unusual section name found: UPX1
Section UPX1 is both writable and executable.
Unusual section name found: UPX2
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Possibly launches other programs:
  • ShellExecuteW
Leverages the raw socket API to access the Internet:
  • ws2_32.dll
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 8624b2e17ba8261e4139a706a3dde4f3 🔍
SHA1 5677c4c63cd55b6464501f6450fa4b7bea15d22a 🔍
SHA256 b07de66a4e8dca3009e5dca31321105c9bfefe07f13e4fa2c4c5df4861a521dc 🔍
SHA3 c957af97cc98e3b9f959ee60f808bc6797ab3622095315f8881e7a4c314ed178 🔍
SSDeep 24576:xtck7RuU4lwsP0fMii8FM7jlT1okyKMyIL9r8hXKnbvizDRmDv1/yK/Uc:x1Rr282rORBr8hXKnbaMDv1/jUc 🔍
Imports Hash 727de273269ce8010c2f5f6dde701a74 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 3
TimeDateStamp 2026-Oct-10 15:11:24
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 2.0
SizeOfCode 0x129000
SizeOfInitializedData 0x1000
SizeOfUninitializedData 0x15a000
AddressOfEntryPoint 0x0000000000283560 (Section: UPX1)
BaseOfCode 0x15b000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x285000
SizeOfHeaders 0x200
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

UPX0

MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍
VirtualSize 0x15a000
VirtualAddress 0x1000
SizeOfRawData 0
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

UPX1

MD5 78c7c7610ba88cba203070d9bfeb9452 🔍
SHA1 3c7a48d71fe5a1d19806c53cbd3b44574709fd75 🔍
SHA256 b65f3db7b25413a7a852ffec443d39ed67d832cc6dcf6fc0030695f7d6131abf 🔍
SHA3 9d80f2749539b833ddc39a59a79ec187aa12ac70c5f6f3b09d5a5087648ee7ad 🔍
VirtualSize 0x129000
VirtualAddress 0x15b000
SizeOfRawData 0x128a00
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.90375

UPX2

MD5 31adf7b4f8432aac38223ad73328cd67 🔍
SHA1 613524d355f80cb0ee4a35e1bef6614d2293b6ab 🔍
SHA256 88d154df708de62e676425e7e9d4401d4847424792669ab008acdba50fbdb66b 🔍
SHA3 b0597c73d636388bd320e518a3259fc104ec93ecc0adf82a1e674d8ca4c3331e 🔍
VirtualSize 0x1000
VirtualAddress 0x284000
SizeOfRawData 0x800
PointerToRawData 0x128c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.67826

Imports

advapi32.dll CopySid
api-ms-win-core-synch-l1-2-0.dll WaitOnAddress
api-ms-win-crt-environment-l1-1-0.dll __p__environ
api-ms-win-crt-heap-l1-1-0.dll free
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
api-ms-win-crt-math-l1-1-0.dll pow
api-ms-win-crt-private-l1-1-0.dll memcmp
api-ms-win-crt-runtime-l1-1-0.dll exit
api-ms-win-crt-stdio-l1-1-0.dll fflush
api-ms-win-crt-string-l1-1-0.dll memset
bcrypt.dll BCryptGenRandom
bcryptprimitives.dll ProcessPrng
gdi32.dll BitBlt
iphlpapi.dll GetIpForwardTable
KERNEL32.DLL LoadLibraryA
ExitProcess
GetProcAddress
VirtualProtect
netapi32.dll NetUserEnum
ntdll.dll NtOpenFile
oleaut32.dll GetErrorInfo
pdh.dll PdhCloseQuery
powrprof.dll CallNtPowerInformation
psapi.dll GetModuleFileNameExW
shell32.dll ShellExecuteW
user32.dll ReleaseDC
wlanapi.dll WlanFreeMemory
ws2_32.dll bind

Delayed Imports

Version Info

TLS Callbacks

StartAddressOfRawData 0x140283858
EndAddressOfRawData 0x140283860
AddressOfIndex 0x1402781fc
AddressOfCallbacks 0x140283860
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks 0x0000000140283805

Load Configuration

RICH Header

Errors

[*] Warning: Section UPX0 has a size of 0!
Leave a comment

No comments yet.