be629df69df763fcb099c6cd8993ab9f5fa5ac66c219d614db3b977c1ce2668a

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Aug-29 03:38:37
Detected languages English - United States

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Possibly launches other programs:
  • ShellExecuteW
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 a6a881237f0c33505eac7891801c02a9 🔍
SHA1 d13b05e6d768eafef9d6cba8dab8e6acc11745e3 🔍
SHA256 be629df69df763fcb099c6cd8993ab9f5fa5ac66c219d614db3b977c1ce2668a 🔍
SHA3 5f5032f7f1d5dd0bb22f4eb0eba5ca9d62d28c44ba8ab734e947bc8b1edb3c83 🔍
SSDeep 6144:E1epLe//3DLCmoJXrBltpv0Xa10EuH3f34Vpv3OEPUikgiynQ3y0I5w5R:wec//HoJtpvl10vXffYiynQi 🔍
Imports Hash fbc86d3feae159976bd03d7f5d48b285 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-29 03:38:37
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x42000
SizeOfInitializedData 0x15600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000004180C (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x5b000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 7e8dcc426a8055bf28fce2ee72883051 🔍
SHA1 4518325ce1d3fa57fbaa80c7eb3ed4c02d833e12 🔍
SHA256 8491abe9523b7ca2c561f70bf56f0dc5051f829121f283d75844cb21ad7b793d 🔍
SHA3 ab393306230d73173c6216cc963ee273d6a61ee1d7f0e41d2586383d7eae207a 🔍
VirtualSize 0x41e2b
VirtualAddress 0x1000
SizeOfRawData 0x42000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.44683

.rdata

MD5 ec0c569482a29fb01d1a993574ebe58e 🔍
SHA1 3d5e6b67c01ee321062fa0b3632de6914a71e9ca 🔍
SHA256 41a16c1b44e3594f6f528c5a8a86b052792430139046f6aa41b45a9d94d6cabb 🔍
SHA3 16550c22b784f698e35f0111e2736677f86638d7563bcc505ee40f742ea9398a 🔍
VirtualSize 0x10f60
VirtualAddress 0x43000
SizeOfRawData 0x11000
PointerToRawData 0x42400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.33829

.data

MD5 27fcf5a1fe14f0d0c4462ed2ea6bf510 🔍
SHA1 7bf72d0142a7191e350e8b4ddd2f3068124958e4 🔍
SHA256 b7d2c905ca4ff24d256773f8ee64f33c3be21dc8f5cc66258e6f011f6256fa86 🔍
SHA3 79eb1cbfa782414e67a60d0ab880bc03362fde4c2cdfa0c924fc6a51dc3c97ab 🔍
VirtualSize 0x9d0
VirtualAddress 0x54000
SizeOfRawData 0x200
PointerToRawData 0x53400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.79407

.pdata

MD5 e13c8013fa0d04385d9ccc43f8cce7a0 🔍
SHA1 d7b920ad49eceef0d1ee212c905ec949988f6827 🔍
SHA256 8d09ced64a60fb6e7410951a241a02c047eda814e41de97fd7b0c78ced659a77 🔍
SHA3 0478330e76845554efad341cd506c5d3a1248451389c4c25a568cebc8ea813fe 🔍
VirtualSize 0x3450
VirtualAddress 0x55000
SizeOfRawData 0x3600
PointerToRawData 0x53600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.60717

.rsrc

MD5 1b90abf985fa570bc2f4bdb9f5cedf1d 🔍
SHA1 29f8c03ff41d6dac32dacaf2ef23c55133f351a8 🔍
SHA256 546fb15b760841066a6d0fd9820d369e33cde1ead524eae1e3a508cbe92c68c6 🔍
SHA3 19483ff0e951ec2b49cce9f12a8d39f5d1bcf53bcad5e52039a1e1a7df41e034 🔍
VirtualSize 0x1e0
VirtualAddress 0x59000
SizeOfRawData 0x200
PointerToRawData 0x56c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.71768

.reloc

MD5 b5f137f93e5eb652c7df539bc22625ce 🔍
SHA1 24a8897d57c95cd2d22068ef83b26f204a0f66d4 🔍
SHA256 b6261c91e0d14e7f6186418256a335c3b18147c9154da4ea688eaac4bec833f7 🔍
SHA3 e0e01e71416dfd52c72f0b8eeddbf97de96fc3dc3cd3d3bea7ec9a13bb620f6a 🔍
VirtualSize 0x254
VirtualAddress 0x5a000
SizeOfRawData 0x400
PointerToRawData 0x56e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 3.73687

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
freetype.dll FT_GlyphSlot_Oblique
FT_New_Memory_Face
FT_Load_Glyph
FT_Activate_Size
FT_GlyphSlot_Embolden
FT_Library_Version
FT_Done_Face
FT_Select_Charmap
FT_Done_Size
FT_Get_Char_Index
FT_Done_Library
FT_New_Size
FT_Add_Default_Modules
FT_Request_Size
FT_Render_Glyph
FT_New_Library
KERNEL32.dll UnhandledExceptionFilter
RtlVirtualUnwind
InitializeSListHead
GetSystemTimeAsFileTime
GetCurrentThreadId
GetCurrentProcessId
GetStartupInfoW
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
GetConsoleScreenBufferInfo
SetConsoleTextAttribute
GetStdHandle
MultiByteToWideChar
FreeConsole
SetUnhandledExceptionFilter
AllocConsole
SetConsoleTitleW
GetLocaleInfoA
LoadLibraryA
QueryPerformanceFrequency
IsDBCSLeadByte
GetProcAddress
FreeLibrary
QueryPerformanceCounter
GlobalAlloc
GlobalFree
GlobalLock
WideCharToMultiByte
GlobalUnlock
GetModuleHandleW
RtlLookupFunctionEntry
RtlCaptureContext
GetCurrentProcess
WriteConsoleW
USER32.dll GetWindowRect
DestroyWindow
SetWindowPos
SetWindowLongPtrW
CreateWindowExW
UnregisterClassW
GetWindowLongPtrW
RegisterClassExW
ShowWindow
SetLayeredWindowAttributes
LoadIconW
PostQuitMessage
UpdateWindow
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
DefWindowProcW
GetKeyState
GetMessageExtraInfo
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
TranslateMessage
GetKeyboardLayout
GetForegroundWindow
LoadCursorW
SetCapture
SetCursor
GetClientRect
IsWindowUnicode
ReleaseCapture
SetCursorPos
GetCursorPos
DispatchMessageW
PeekMessageW
SetClipboardData
SHELL32.dll ShellExecuteW
D3DCOMPILER_47.dll D3DCompile
dwmapi.dll DwmExtendFrameIntoClientArea
IMM32.dll ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow
ImmSetCompositionWindow
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll memcmp
memcpy
memmove
__current_exception_context
_CxxThrowException
memset
__current_exception
memchr
__C_specific_handler
__std_terminate
__std_exception_destroy
__std_exception_copy
api-ms-win-crt-string-l1-1-0.dll strncmp
strcmp
api-ms-win-crt-stdio-l1-1-0.dll __stdio_common_vsprintf
_set_fmode
__stdio_common_vsscanf
fread
fwrite
__p__commode
ftell
fseek
_wfopen
fclose
fflush
__acrt_iob_func
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
free
_callnewh
malloc
api-ms-win-crt-runtime-l1-1-0.dll _exit
exit
_initterm_e
_initterm
_register_thread_local_exe_atexit_callback
terminate
_get_narrow_winmain_command_line
_set_app_type
_seh_filter_exe
_c_exit
_cexit
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
_crt_atexit
api-ms-win-crt-math-l1-1-0.dll expf
__setusermatherr
fmodf
sinf
sqrtf
acosf
ceilf
powf
cosf
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-29 03:38:37
Version 0.0
SizeofData 912
AddressOfRawData 0x4d488
PointerToRawData 0x4c888

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-29 03:38:37
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x14004d838
EndAddressOfRawData 0x14004d840
AddressOfIndex 0x1400547b8
AddressOfCallbacks 0x140043648
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140054040

RICH Header

XOR Key 0xdf329c2b
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 18
Imports (35207) 6
ASM objects (35207) 4
C objects (35207) 10
C++ objects (35207) 29
Imports (35228) 2
Imports (21202) 2
Imports (33145) 17
Total imports 243
C++ objects (LTCG) (35228) 18
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment
🔍 Transfer № L4757 from Coinbase. SIGN IN ->>> graph.org/Bitcoin 16 hours ago
🔍 Transfer № L4757 from Coinbase. SIGN IN ->>> graph.org/Bitcoin-Mining-08-27?hs=7202151b0c43d98d4ceae5a029e74f70& 🔍