d25d2611027f610e8940d72ce3ef8616a62b6354937be18182a0a35985d7bf0c

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1970-Jan-01 00:00:00

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • -Inf.bat.cmd.com
  • .eq.golang.org
  • .eq.runtime.net
  • .hash.golang.org
  • .hash.net
  • .hash.runtime.net
  • Inf.bat.cmd.com
  • bat.cmd.com
  • eq.golang.org
  • eq.runtime.net
  • github.com
  • golang.org
  • hash.golang.org
  • hash.runtime.net
  • runtime.net
  • type..eq.golang.org
  • type..eq.net
  • type..eq.runtime.net
  • type..hash.golang.org
  • type..hash.net
  • type..hash.runtime.net
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Suspicious The PE is packed with UPX Unusual section name found: UPX0
Section UPX0 is both writable and executable.
Unusual section name found: UPX1
Section UPX1 is both writable and executable.
Unusual section name found: UPX2
The PE only has 0 import(s).
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 875e71d6077619fab56298edcb1179b2 🔍
SHA1 740ab3070000baf9d5aa138bc544790cfdfd86ce 🔍
SHA256 d25d2611027f610e8940d72ce3ef8616a62b6354937be18182a0a35985d7bf0c 🔍
SHA3 9614c0d50dd4023ba30e76f78f0ff19368a5362595ed37507732cd02b987f497 🔍
SSDeep 49152:4tSSEtOzolDpHeXJ5YDqmi1QPRlrXzMCsqmOI8aGGUtZZT7/i:USFtO8tpH6AJiQrjkqH2ZY/i 🔍
Imports Hash d41d8cd98f00b204e9800998ecf8427e 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0x4
e_cparhdr 0
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0x8b
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 3
TimeDateStamp 1970-Jan-01 00:00:00
PointerToSymbolTable 0x4ba000
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 3.0
SizeOfCode 0x1bc000
SizeOfInitializedData 0x1000
SizeOfUninitializedData 0x328000
AddressOfEntryPoint 0x000000000005FDF0 (Section: UPX0)
BaseOfCode 0x329000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 1.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0x4e6000
SizeOfHeaders 0x200
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

UPX0

MD5 960c3e324c1d910ff00a4f3404981019 🔍
SHA1 142089fb3b35edd191cd5a2e9f6e086053bbaa07 🔍
SHA256 7d6039ba478d664567136d85832a8662ef6c7b3b773bfad436572adf52015535 🔍
SHA3 9e35bab6964df190d776df0be729039b32086d7bfe7ae9fa5f8f780f250c05be 🔍
VirtualSize 0x328000
VirtualAddress 0x1000
SizeOfRawData 0x328000
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.6665

UPX1

MD5 d3cbe6f3bd412053306f1a59b7afb850 🔍
SHA1 6f8e61b6fbb9e9879b906fbb9579a4353c431ad4 🔍
SHA256 20508f6e92623980f5f00cbe3cf95b0e21cbaae7ba672e2a6a1993140610e281 🔍
SHA3 b208bfdecd7202a397ecac8202d04175e3593c98c368d7c45bad7cfc71cdc405 🔍
VirtualSize 0x1bc000
VirtualAddress 0x329000
SizeOfRawData 0x1bba00
PointerToRawData 0x328200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.35416

UPX2

MD5 5eced560885d5772a483bf9f3463963d 🔍
SHA1 e09dab95b26bdb4517a27f80077ba84865cd51ca 🔍
SHA256 b6f4e934d5f717b5c139d70b6b8898bb0544fa262eca5f1138284c94e02c4394 🔍
SHA3 b8f2f276a367b7330f0a8104c3e0ceae71373c21128cb1a9643ac4eb02a7312c 🔍
VirtualSize 0x1000
VirtualAddress 0x4e5000
SizeOfRawData 0x200
PointerToRawData 0x4e3c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.56466

Imports

KERNEL32.DLL (EMPTY)

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

RICH Header

Errors

[!] Error: Could not reach the HINT/NAME table. [*] Warning: An error occurred while trying to read functions imported by module KERNEL32.DLL.
Leave a comment

No comments yet.