c3df7f856dd2eae7ae0994716dc864eef8c316f74b667f2e23d48d485c946cf0

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2014-Feb-26 02:05:15
Detected languages English - United States

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 DLL (Debug)
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++
Microsoft Visual C++ v6.0
Info Interesting strings found in the binary: Contains domain names:
  • 6ixsoft.com
  • http://www.6ixsoft.com
  • http://www.6ixsoft.com.
  • www.6ixsoft.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Can access the registry:
  • RegOpenKeyExA
  • RegOpenKeyA
  • RegEnumKeyA
  • RegQueryValueExA
  • RegCloseKey
Possibly launches other programs:
  • ShellExecuteA
Uses Windows's Native API:
  • ntohl
  • ntohs
Can create temporary files:
  • GetTempPathA
  • CreateFileA
Uses functions commonly found in keyloggers:
  • MapVirtualKeyA
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Enumerates local disk drives:
  • GetDriveTypeA
Can use the microphone to record audio:
  • waveInOpen
Malicious VirusTotal score: 5/70 (Scanned on 2026-08-15 17:25:10) DrWeb: Trojan.Inject4.6518
MaxSecure: Trojan.Malware.300983.susgen
Microsoft: Trojan:Win32/Wacatac.B!ml
NANO-Antivirus: Trojan.Win32.Inject4.kkmxit
VBA32: Trojan.Inject

Hashes

MD5 c0b18acc7560b274e312ca3e8bb79618 🔍
SHA1 59f58a440d58a7eb9f114e7c9ca8e4756f8004ad 🔍
SHA256 c3df7f856dd2eae7ae0994716dc864eef8c316f74b667f2e23d48d485c946cf0 🔍
SHA3 8f82245f4747d89f79b6176926608839b24f8d50027c5ba467c6c33b2ed2a181 🔍
SSDeep 24576:Ktl25/phgIFUJDND1nb8rGEQHtASNRMS0wgAjIpr/511x:KtA5/InN51P0TN/rX 🔍
Imports Hash c87f27c035ab10cf299284a3cadc2af0 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2014-Feb-26 02:05:15
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0x104000
SizeOfInitializedData 0x81000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000014C7 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x105000
ImageBase 0x10000000
SectionAlignment 0x1000
FileAlignment 0x1000
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x18b000
SizeOfHeaders 0x1000
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 6a9be7bfea83a5efca087282da920be4 🔍
SHA1 539e427ce7ab222ad79d7bca98b27997e6196e29 🔍
SHA256 1a098254ab4a096539958addc891b9e994887d72740e4686dead56673f498eef 🔍
SHA3 d498d838fb97b9ecf7bd0f8fa88a5d2a542ad2ee09243dc2a1286511e5c1788d 🔍
VirtualSize 0x1033fc
VirtualAddress 0x1000
SizeOfRawData 0x104000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.71072

.rdata

MD5 85a58572382e0d03e0f015fba111a043 🔍
SHA1 7704d623d70e242508b5f46be6c43d4dd67c02a1 🔍
SHA256 88500e9099e14b51885712b1fe14b4d7dcd8a4e83a8f406e67f8fbe0a2afaa10 🔍
SHA3 d37eb50be179ffd6ea8b95f8a333d9370093ae29974c8716bdf75d167a11f1e2 🔍
VirtualSize 0xc967
VirtualAddress 0x105000
SizeOfRawData 0xd000
PointerToRawData 0x105000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.6959

.data

MD5 018803bea0b9789618b094ba773397bf 🔍
SHA1 a1f067d68fd43d8d839d6c892471c3677338c75c 🔍
SHA256 c775a96964b21ff8764facf1fc584b9405549a7069205c182864641477344874 🔍
SHA3 e2fc8dc2075ad493815a67e80da2ecea7c9930d3084f57f59606e168f07f14be 🔍
VirtualSize 0x62334
VirtualAddress 0x112000
SizeOfRawData 0x20000
PointerToRawData 0x112000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.90229

.rsrc

MD5 aad16f37e7701f05736b8eab5bf0c179 🔍
SHA1 5c0fda0e120c92a8f1ec46795d7935fb3853f570 🔍
SHA256 38f94a9b9dc3517c2e3ac0e648a892b9c9cc19e41ed791adfc24c6da80f23fa9 🔍
SHA3 ac08632d858c40d34977f55e30db428a50b9b749d592145a03b37e48ec62b9a5 🔍
VirtualSize 0x5cc8
VirtualAddress 0x175000
SizeOfRawData 0x6000
PointerToRawData 0x132000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.39943

.reloc

MD5 fab4dd736894dfd4c6a9e4b53981999b 🔍
SHA1 8354770bd053fa25a389d44769ca0206e9046fc9 🔍
SHA256 f99950d55b5c291753a4e94ed0f8e77de29cb8e69faed03f43d038290b1ebc77 🔍
SHA3 c56560a944d5449ac949f46fdbb2b3be0ca45fcecf04ce1032641272e235c461 🔍
VirtualSize 0xf406
VirtualAddress 0x17b000
SizeOfRawData 0x10000
PointerToRawData 0x138000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.25746

Imports

KERNEL32.dll FindResourceA
VirtualProtect
GetSystemTimeAsFileTime
FileTimeToLocalFileTime
FileTimeToSystemTime
SetThreadPriority
CreateThread
TerminateThread
GetDriveTypeA
DeviceIoControl
ResetEvent
QueryPerformanceFrequency
QueryPerformanceCounter
OpenFile
VirtualLock
LoadResource
LockResource
VirtualAlloc
GetModuleHandleA
GetCommandLineA
ExitProcess
LoadLibraryA
GetProcAddress
FreeLibrary
GetVersionExA
Sleep
GetTempPathA
GetSystemDirectoryA
GetWindowsDirectoryA
GetModuleFileNameA
CreateEventA
CloseHandle
SetEvent
WaitForSingleObject
MultiByteToWideChar
CreateDirectoryA
RemoveDirectoryA
DeleteFileA
CopyFileA
SetCurrentDirectoryA
GetCurrentDirectoryA
FindClose
FindFirstFileA
GetFileAttributesA
FindNextFileA
VirtualFree
GetFullPathNameA
EnterCriticalSection
InitializeCriticalSection
InterlockedExchange
DeleteCriticalSection
LeaveCriticalSection
InterlockedDecrement
InterlockedIncrement
WideCharToMultiByte
RtlUnwind
GetVersion
RaiseException
HeapAlloc
HeapFree
GetTimeZoneInformation
GetSystemTime
GetLocalTime
HeapReAlloc
LCMapStringA
LCMapStringW
GetCPInfo
CompareStringA
CompareStringW
TerminateProcess
GetCurrentProcess
HeapSize
GetLastError
GetCurrentThreadId
TlsSetValue
TlsAlloc
TlsFree
SetLastError
TlsGetValue
SetHandleCount
GetStdHandle
GetFileType
GetStartupInfoA
FreeEnvironmentStringsA
FreeEnvironmentStringsW
GetEnvironmentStrings
GetEnvironmentStringsW
GetEnvironmentVariableA
HeapDestroy
HeapCreate
WriteFile
SetUnhandledExceptionFilter
IsBadWritePtr
SetFilePointer
FlushFileBuffers
ReadFile
IsValidLocale
IsValidCodePage
GetLocaleInfoA
EnumSystemLocalesA
GetUserDefaultLCID
GetStringTypeA
GetStringTypeW
IsBadReadPtr
IsBadCodePtr
GetACP
GetOEMCP
SetEnvironmentVariableA
SetStdHandle
CreateFileA
SetEndOfFile
GetLocaleInfoW
SetEnvironmentVariableW
USER32.dll UpdateWindow
CreateWindowExA
RegisterClassA
LoadCursorA
UnregisterClassA
DestroyWindow
ShowCursor
ShowWindow
ClientToScreen
GetClientRect
SetCursorPos
ReleaseCapture
SetCapture
ScreenToClient
SetCursor
PostMessageA
EndPaint
BeginPaint
SetTimer
DefWindowProcA
DispatchMessageA
PeekMessageA
GetMessageA
GetWindowLongA
GetWindowRect
SetWindowPos
SetWindowLongA
InvalidateRect
MoveWindow
GetSystemMetrics
SystemParametersInfoA
ToAscii
MapVirtualKeyA
MessageBoxA
SetForegroundWindow
CharLowerBuffA
KillTimer
SendDlgItemMessageA
EndDialog
GetDlgItem
EnableWindow
GetWindowTextA
SetWindowTextA
GetForegroundWindow
DialogBoxParamA
GetDesktopWindow
GetCursorPos
WSOCK32.dll socket
bind
gethostbyname
WSACleanup
WSAStartup
setsockopt
listen
closesocket
getsockname
accept
send
ntohl
ioctlsocket
recv
connect
WSAGetLastError
inet_addr
__WSAFDIsSet
getpeername
ntohs
htonl
htons
sendto
select
inet_ntoa
recvfrom
WINMM.dll waveInReset
timeKillEvent
timeSetEvent
timeGetTime
timeEndPeriod
timeGetDevCaps
mciSendCommandA
mciGetErrorStringA
waveOutGetDevCapsA
waveOutGetNumDevs
waveOutOpen
waveOutClose
waveOutPrepareHeader
waveOutUnprepareHeader
waveOutWrite
waveOutReset
waveOutGetPosition
waveInAddBuffer
waveInPrepareHeader
waveInUnprepareHeader
waveInGetDevCapsA
waveInGetNumDevs
waveInStart
waveInOpen
waveInClose
timeBeginPeriod
mixerGetControlDetailsA
mixerGetLineControlsA
mixerGetLineInfoA
mixerSetControlDetails
mixerOpen
mixerGetNumDevs
mixerClose
d3dxof.dll DirectXFileCreate
DPLAYX.dll #4
DDRAW.dll DirectDrawCreateEx
DirectDrawEnumerateExA
DINPUT.dll DirectInputCreateEx
GDI32.dll GetStockObject
RemoveFontResourceA
ExtTextOutA
SetTextColor
SetBkColor
GetCharABCWidthsA
GetTextExtentPoint32A
DeleteObject
DeleteDC
GetTextMetricsA
SelectObject
CreateCompatibleDC
AddFontResourceA
CreateFontA
SHELL32.dll ShellExecuteA
ole32.dll CoCreateInstance
CoInitialize
CoUninitialize
CLSIDFromString
ADVAPI32.dll RegOpenKeyExA
RegOpenKeyA
RegEnumKeyA
RegQueryValueExA
RegCloseKey
MSACM32.dll acmStreamPrepareHeader
acmStreamSize
acmStreamOpen
acmFormatSuggest
acmStreamClose
acmStreamUnprepareHeader
acmStreamConvert

Delayed Imports

_bbWinMain@0

Ordinal 1
Address 0x14c7

runtimeGetRuntime

Ordinal 2
Address 0x1421

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.4623
MD5 68ce246e55d32876439a255c84f936b3 🔍
SHA1 d190dbb310b7c7ae3ae99a05a5b7bee279d85257 🔍
SHA256 bd1b0f635e840236f04fde022f5fff56cc25b66951b4bbc4f2a53326fae53a27 🔍
SHA3 1abcac9a03ffb1ed8266936afc03d096cf8fec7d0e605a535d91ce9fb3c203b4 🔍

101

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x1c0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37163
MD5 46f7261d8a947bba1031252be1ddc986 🔍
SHA1 0ca15518dc056ef6dca1081391073cf7588acd1e 🔍
SHA256 de2b6bfe8f76ae94f4a952e231ed9c62359705efeb36f2004d1f3951b931674e 🔍
SHA3 b9086150ef7a8d882130a78f25497f13c3251798af959b8531551ad6cb4ea03c 🔍

1111

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x5111
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.49416
MD5 a2360f9e718c1f1914c1a40e10b63b72 🔍
SHA1 1d56b29923394da9d50c5ece47e61aba4e9d432d 🔍
SHA256 26a594e971a223a384787c27882202f41563a3a961d252ef7c2a62c22e40600b 🔍
SHA3 c69ae491bee5bf20b8832fe37fa93d37c013ae566ee9c150f5ea02e7114edff6 🔍

107

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.81924
Detected Filetype Icon file
MD5 cbee427fa121aba9b9b265ff05de5383 🔍
SHA1 24fcae33001c8e0f5ec795c6edf076a69d59589f 🔍
SHA256 494e4fd717fa1ee0c5c7bb3b4e28fdab4b7f6e95b4f9865f5ab86f03f62ae62c 🔍
SHA3 a3fa35d56632275ba55716a4964f02031270f61f06a903fc460ac2dd6bebde85 🔍

Version Info

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x71d53605
Unmarked objects 0
12 (7291) 3
14 (7299) 50
C++ objects (8047) 13
C objects (8047) 6
C++ objects (VC++ 6.0 SP5 build 8804) 5
C objects (VC++ 6.0 SP5 build 8804) 75
C objects (VS98 SP6 build 8804) 210
19 (9049) 10
Unmarked objects (#2) 15
19 (8034) 22
Total imports 255
C++ objects (VS98 SP6 build 8804) 98
Resource objects (VS98 SP6 cvtres build 1736) 1
Linker (VC++ 6.0 SP5 imp/exp build 8447) 1

Errors

Leave a comment

No comments yet.