c6fdd33692bd2c1ae103fa82a28c180be629971e0f8ec7efff4f3885d6b4b203

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Sep-06 21:06:13
Detected languages English - United States

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Contains domain names:
  • github.com
  • http://www.marksimonson.com
  • http://www.marksimonson.comProxima
  • http://www.marksimonson.comhttp
  • https://github.com
  • https://indiantypefoundry.comThis
  • https://scripts.sil.org
  • https://scripts.sil.org/OF
  • https://scripts.sil.org/OFLPoppinsSemiBol
  • https://scripts.sil.org/OFLhttps
  • marksimonson.com
  • scripts.sil.org
  • www.marksimonson.com
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • CheckRemoteDebuggerPresent
  • CreateToolhelp32Snapshot
Code injection capabilities:
  • CreateRemoteThread
  • OpenProcess
  • VirtualAllocEx
  • WriteProcessMemory
Code injection capabilities (mapping injection):
  • CreateRemoteThread
  • CreateFileMappingW
  • MapViewOfFile
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAllocEx
Has Internet access capabilities:
  • WinHttpQueryHeaders
  • WinHttpReceiveResponse
  • WinHttpSendRequest
  • WinHttpAddRequestHeaders
  • WinHttpOpenRequest
  • WinHttpSetTimeouts
  • WinHttpSetOption
  • WinHttpQueryDataAvailable
  • WinHttpReadData
  • WinHttpConnect
  • WinHttpCloseHandle
  • WinHttpOpen
Enumerates local disk drives:
  • GetVolumeInformationW
Manipulates other processes:
  • OpenProcess
  • WriteProcessMemory
Can take screenshots:
  • GetDC
  • CreateCompatibleDC
  • BitBlt
Reads the contents of the clipboard:
  • GetClipboardData
Malicious The PE is possibly a dropper. Resource 777 detected as a PE Executable.
Resources amount for 98.9776% of the executable.
Malicious VirusTotal score: 9/67 (Scanned on 2026-09-06 21:10:45) APEX: Malicious
Bkav: W32.Malware.62A452C6
Elastic: malicious (high confidence)
MaxSecure: Trojan.Malware.300983.susgen
McAfeeD: ti!C6FDD33692BD
Microsoft: Trojan:Win32/Wacatac.B!ml
Sangfor: Trojan.Win32.Save.a
Symantec: ML.Attribute.HighConfidence
Trapmine: malicious.moderate.ml.score

Hashes

MD5 ba6288cf76c28ee11a3c83a8a8262707 🔍
SHA1 1db8b9b0a2d367193f9eb5cbfbbe1af6ae0a746b 🔍
SHA256 c6fdd33692bd2c1ae103fa82a28c180be629971e0f8ec7efff4f3885d6b4b203 🔍
SHA3 5995d93cc3167d4dc6f50756d1b7e71df38c1fb9b0085d7a64394bef4d2cc0ad 🔍
SSDeep 393216:IVmsE/JsBG9n8VNjabJaGLJqryJk8s+Mf4iAmovXXvNODjSBqVHv:2msZG9cjabgGL7Zs+MfNAzvf8jvH 🔍
Imports Hash 646f66a190955a68b2f9e98386c2dd21 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Sep-06 21:06:13
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x2ba00
SizeOfInitializedData 0x17fc600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000000C730 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x182c000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 90d10a5fde42ba6a05c31c0a2548f503 🔍
SHA1 10f38022cfa97de7c96291cf26416f93421f6752 🔍
SHA256 717919e3551a025b552c885aa604cc154f46cf755dedcc1c3eeff569f3f8c178 🔍
SHA3 d58c9b5666b4b4a7cfe202a4612ad0a7ffc972116ccb0c6e6e9b0d8f693570da 🔍
VirtualSize 0x2b990
VirtualAddress 0x1000
SizeOfRawData 0x2ba00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.53202

.rdata

MD5 bcaea4dc27cd47f60419a546dbb97fe2 🔍
SHA1 2b57282bd7495bfb5c3e412b14c35fdda6000c9a 🔍
SHA256 41593745014fa79eef531d99add45a081acad86e6dc165b3cf64d7d302cf0775 🔍
SHA3 908d73c6c8526262f35ae99158ff789682179d60400e62965a14717430c737e5 🔍
VirtualSize 0xfb9a
VirtualAddress 0x2d000
SizeOfRawData 0xfc00
PointerToRawData 0x2be00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.02419

.data

MD5 7154451e6c471ab11429f4162c2b8645 🔍
SHA1 d976a575bd62c30d247bf9242088da3942406964 🔍
SHA256 3122baef0d5e64d236a6f108cf1c170775501822856cb31489469fe3eb96de9b 🔍
SHA3 aca95bdf6b6adfbeba699213db48bb851d9612e64fe699298131675db49cbe42 🔍
VirtualSize 0x4438
VirtualAddress 0x3d000
SizeOfRawData 0xc00
PointerToRawData 0x3ba00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.02132

.pdata

MD5 493daf78d7a48310b1e0c76c6543b279 🔍
SHA1 3857f63f272cf9743844b034d554e297b6a4f7e1 🔍
SHA256 a7847c44c8d4f4bfe7f8bd617b33736c7174071d6b3ede369068ea3caabea479 🔍
SHA3 adbb13f7814f4f8dee5c10472677266cde232024f341ad34ba8bea248d53c976 🔍
VirtualSize 0x1f38
VirtualAddress 0x42000
SizeOfRawData 0x2000
PointerToRawData 0x3c600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.39991

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x44000
SizeOfRawData 0x200
PointerToRawData 0x3e600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 bfe37019ea83258d46e367adb12e12d0 🔍
SHA1 6441e6c8d52874711845188ba2e9fc48d02cb2f2 🔍
SHA256 9c0195346941f9122ce03fed8fd75ab5ddf759d3a79381ccfa081444141512f1 🔍
SHA3 91bf7aedb6953c64300dbb193007d205b2cda44e74c304b6b84d822ce5e2d443 🔍
VirtualSize 0x17e5890
VirtualAddress 0x45000
SizeOfRawData 0x17e5a00
PointerToRawData 0x3e800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.97158

.reloc

MD5 4f4680c0124d86f7d40016267bbfb23d 🔍
SHA1 50a7689223b0d41b654763a35967f5924f8e854d 🔍
SHA256 2bed5646a3d70be0109090e10f43e9d9d4320de2d40ee228231690eb70250628 🔍
SHA3 9c30ccc9cbf4dd3dbe47bd4299e4b51be05c2e25a8d17f8acfa5f5a391ab80b1 🔍
VirtualSize 0x698
VirtualAddress 0x182b000
SizeOfRawData 0x800
PointerToRawData 0x1824200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.95516

Imports

USER32.dll DispatchMessageW
DefWindowProcW
PostQuitMessage
RegisterClassExW
CreateWindowExW
DestroyWindow
ShowWindow
IsWindowVisible
TranslateMessage
CloseClipboard
GetClipboardData
IsClipboardFormatAvailable
GetKeyState
SetCapture
ReleaseCapture
SetTimer
GetSystemMetrics
DrawTextW
UpdateWindow
OpenClipboard
GetWindowThreadProcessId
GetDC
ReleaseDC
BeginPaint
EndPaint
SetWindowRgn
InvalidateRect
GetWindowTextW
GetWindowTextLengthW
GetClientRect
MessageBoxW
LoadCursorW
GetMessageW
EnumWindows
ScreenToClient
SetCursor
GDI32.dll GetTextFaceW
TextOutW
MoveToEx
GetObjectW
CreateDIBSection
SetTextColor
SetBkMode
SelectObject
SelectClipRgn
RoundRect
LineTo
RemoveFontResourceExW
AddFontResourceExW
GetTextExtentPoint32W
GetStockObject
EnumFontFamiliesExW
Ellipse
DeleteObject
DeleteDC
CreateSolidBrush
CreateRoundRectRgn
CreateRectRgn
CreatePen
CreateFontW
CreateCompatibleDC
CreateCompatibleBitmap
BitBlt
gdiplus.dll GdipDisposeImage
GdipBitmapLockBits
GdipGetImageHeight
GdipGetImageWidth
GdipBitmapUnlockBits
GdipCreateBitmapFromFile
GdiplusShutdown
GdiplusStartup
MSIMG32.dll AlphaBlend
bcrypt.dll BCryptHashData
BCryptCreateHash
BCryptDestroyHash
BCryptFinishHash
BCryptCloseAlgorithmProvider
BCryptOpenAlgorithmProvider
BCryptGenRandom
WINHTTP.dll WinHttpQueryHeaders
WinHttpReceiveResponse
WinHttpSendRequest
WinHttpAddRequestHeaders
WinHttpOpenRequest
WinHttpSetTimeouts
WinHttpSetOption
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpConnect
WinHttpCloseHandle
WinHttpOpen
KERNEL32.dll LoadLibraryExW
VirtualProtect
HeapFree
GetFileType
HeapReAlloc
FindFirstFileExW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetStringTypeW
GetProcessHeap
GetConsoleOutputCP
GetConsoleMode
GetFileSizeEx
SetFilePointerEx
HeapSize
ReadConsoleW
SetEndOfFile
LCMapStringW
HeapAlloc
UnhandledExceptionFilter
RtlVirtualUnwind
RtlCaptureContext
IsProcessorFeaturePresent
GetModuleHandleExW
FreeLibrary
TerminateProcess
ExitProcess
GetStdHandle
RtlPcToFileHeader
RaiseException
EncodePointer
RtlLookupFunctionEntry
InitializeCriticalSectionEx
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
SetLastError
RtlUnwindEx
GetStartupInfoW
SetUnhandledExceptionFilter
InitializeSListHead
GetSystemTimeAsFileTime
GetCurrentThreadId
WriteConsoleW
QueryPerformanceCounter
SystemTimeToFileTime
GetCommandLineW
GetEnvironmentVariableW
CreateDirectoryW
CreateFileW
DeleteFileW
FindClose
FindFirstFileW
FindNextFileW
FlushFileBuffers
GetFileAttributesW
ReadFile
WriteFile
GetTempPathW
IsDebuggerPresent
CheckRemoteDebuggerPresent
CloseHandle
GetLastError
QueryPerformanceFrequency
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
WaitForSingleObject
Sleep
GetCurrentProcess
GetCurrentProcessId
CreateThread
CreateRemoteThread
OpenProcess
GetLocalTime
GetTickCount
GetTickCount64
VirtualAllocEx
WriteProcessMemory
CreateFileMappingW
OpenFileMappingW
MapViewOfFile
VirtualFreeEx
UnmapViewOfFile
IsWow64Process
GetModuleFileNameW
GetModuleHandleW
GetProcAddress
LoadResource
LockResource
SizeofResource
FindResourceW
GlobalUnlock
GlobalLock
QueryFullProcessImageNameW
MultiByteToWideChar
WideCharToMultiByte
AttachConsole
CreateToolhelp32Snapshot
Module32FirstW
Module32NextW
CompareFileTime
GetVolumeInformationW
GetSystemTime
GetComputerNameW
FileTimeToSystemTime
ADVAPI32.dll GetUserNameW

Delayed Imports

777

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x1775600
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97516
Detected Filetype PE Executable
MD5 90e1a5f01a974d24cb792f2b53306520 🔍
SHA1 84f5fbf1d9182741ca71201995f63fb0c5414612 🔍
SHA256 8cb2f8cd5830810669369b12c3d997062ac8d28379f1f5cbbfa4a32f889faa74 🔍
SHA3 1c40b623391b1703dc242685b8d05d4df74b8ba2137cc88b5d491b1744122f3e 🔍

778

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x8745
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.96575
Detected Filetype PNG graphic file
MD5 f999cb776408b65033f6609d66e5ad83 🔍
SHA1 0ec975cf8833571ac29e935783574a1d5db83a91 🔍
SHA256 1b4ede21ce1c4ae6d208cac59234be9d7e0746e0dc4eeb39746ef31801a8386d 🔍
SHA3 f9a6ec32458c804030a3d9ee9e2aefbbd8afe520f18cd62b1035abeb04668408 🔍

779

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x26680
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.71763
Detected Filetype TrueType font file
MD5 2c63e05091c7d89f6149c274971c7c23 🔍
SHA1 622ca6ccbe2f22c5611dffa016b745bd26be154c 🔍
SHA256 d3bf1bdaf0550e83da9ac0b1d1d9fe6db086835a83aa28578e609a394b9a0286 🔍
SHA3 fafa92f3a11400e9e8cac77dcce0749eb867eae4530526a89de6ddb1e7a074b1 🔍

780

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x2723c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.72744
Detected Filetype TrueType font file
MD5 09acac7457bdcf80af5cc3d1116208c5 🔍
SHA1 86a425be5a919d86729b85b2bc1d07da5ce413d4 🔍
SHA256 7e65201e9b79159e2300267cc885e16c8dcef2424cdfa09a29bfb0980a94a7ba 🔍
SHA3 05aa3912951e7c85704c41822fc6ab0d0388806f19b1a958cfb28307de834870 🔍

781

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0xf68a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.79929
MD5 94acf04db51d177e554f6279e4de7842 🔍
SHA1 f991dcc9382c02ed721309ed14ea6b94d7f143d6 🔍
SHA256 4f0f1d05d935a1f626a47267bf4e7f13b350263d0e03ee7768e31f32c20becda 🔍
SHA3 dd1f635579f73029bc4f7a095e3a367273feaee6e1fad33a434ce0485d8fe829 🔍

782

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0xa8e6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.56681
Detected Filetype TrueType font file
MD5 2a602802127b4beda08fe0f4ca61c64b 🔍
SHA1 7d18a3be360c668fce8ff180947aab175710da86 🔍
SHA256 4af19ad1ccc5405142c48e540a38976fd71d9a63d6433b4b770ea5782cc5def2 🔍
SHA3 cbbe776f73fc82cea09863abd69cdf0b8a064a740f914a6c27ae5a07d646e8f2 🔍

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Sep-06 21:06:13
Version 0.0
SizeofData 840
AddressOfRawData 0x38d38
PointerToRawData 0x37b38

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14003d080

RICH Header

XOR Key 0x2ca76288
Unmarked objects 0
C++ objects (33145) 158
C objects (33145) 13
ASM objects (33145) 14
ASM objects (35721) 9
C objects (35721) 19
C++ objects (35721) 39
Imports (33145) 17
Total imports 221
C objects (36256) 2
Resource objects (36256) 1
151 2
Linker (36256) 1

Errors

Leave a comment

No comments yet.