| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1970-Jan-01 00:00:00 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES |
| Suspicious | The PE is packed with UPX |
Unusual section name found: UPX0
Section UPX0 is both writable and executable. Unusual section name found: UPX1 Section UPX1 is both writable and executable. Unusual section name found: UPX2 The PE only has 0 import(s). |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| MD5 | 875e71d6077619fab56298edcb1179b2 🔍 |
|---|---|
| SHA1 | 740ab3070000baf9d5aa138bc544790cfdfd86ce 🔍 |
| SHA256 | d25d2611027f610e8940d72ce3ef8616a62b6354937be18182a0a35985d7bf0c 🔍 |
| SHA3 | 9614c0d50dd4023ba30e76f78f0ff19368a5362595ed37507732cd02b987f497 🔍 |
| SSDeep | 49152:4tSSEtOzolDpHeXJ5YDqmi1QPRlrXzMCsqmOI8aGGUtZZT7/i:USFtO8tpH6AJiQrjkqH2ZY/i 🔍 |
| Imports Hash | d41d8cd98f00b204e9800998ecf8427e 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0x4 |
| e_cparhdr | 0 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0x8b |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 3 |
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| PointerToSymbolTable | 0x4ba000 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 3.0 |
| SizeOfCode | 0x1bc000 |
| SizeOfInitializedData | 0x1000 |
| SizeOfUninitializedData | 0x328000 |
| AddressOfEntryPoint | 0x000000000005FDF0 (Section: UPX0) |
| BaseOfCode | 0x329000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.1 |
| ImageVersion | 1.0 |
| SubsystemVersion | 6.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x4e6000 |
| SizeOfHeaders | 0x200 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 960c3e324c1d910ff00a4f3404981019 🔍 |
|---|---|
| SHA1 | 142089fb3b35edd191cd5a2e9f6e086053bbaa07 🔍 |
| SHA256 | 7d6039ba478d664567136d85832a8662ef6c7b3b773bfad436572adf52015535 🔍 |
| SHA3 | 9e35bab6964df190d776df0be729039b32086d7bfe7ae9fa5f8f780f250c05be 🔍 |
| VirtualSize | 0x328000 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x328000 |
| PointerToRawData | 0x200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 5.6665 |
| MD5 | d3cbe6f3bd412053306f1a59b7afb850 🔍 |
|---|---|
| SHA1 | 6f8e61b6fbb9e9879b906fbb9579a4353c431ad4 🔍 |
| SHA256 | 20508f6e92623980f5f00cbe3cf95b0e21cbaae7ba672e2a6a1993140610e281 🔍 |
| SHA3 | b208bfdecd7202a397ecac8202d04175e3593c98c368d7c45bad7cfc71cdc405 🔍 |
| VirtualSize | 0x1bc000 |
| VirtualAddress | 0x329000 |
| SizeOfRawData | 0x1bba00 |
| PointerToRawData | 0x328200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 5.35416 |
| MD5 | 5eced560885d5772a483bf9f3463963d 🔍 |
|---|---|
| SHA1 | e09dab95b26bdb4517a27f80077ba84865cd51ca 🔍 |
| SHA256 | b6f4e934d5f717b5c139d70b6b8898bb0544fa262eca5f1138284c94e02c4394 🔍 |
| SHA3 | b8f2f276a367b7330f0a8104c3e0ceae71373c21128cb1a9643ac4eb02a7312c 🔍 |
| VirtualSize | 0x1000 |
| VirtualAddress | 0x4e5000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x4e3c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 1.56466 |
| KERNEL32.DLL | (EMPTY) |
|---|
No comments yet.