d2c0b8c5adb1b91b82a405f1c8cd668e7ca75957127c02d898af7a959204e207

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1970-Jan-01 00:00:00

Plugin Output

Suspicious PEiD Signature: PeStubOEP v1.x
HQR data file
UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX -> www.upx.sourceforge.net
UPX 3.02
UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX 2.00-3.0X -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX v3.0 (EXE_LZMA) -> Markus Oberhumer & Laszlo Molnar & John Reiser
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • sc.exe
Contains references to security software:
  • rshell.exe
May have dropper capabilities:
  • CurrentVersion\Run
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • -github.com
  • .eq.github.com
  • .eq.golang.org
  • .github.com
  • .hash.golang.org
  • .hash.net
  • 0github.com
  • 1github.com
  • 2github.com
  • 4github.com
  • 8github.com
  • 9github.com
  • cloudflare-dns.com
  • enabledgithub.com
  • eq.github.com
  • eq.golang.org
  • github.com
  • golang.org
  • hash.golang.org
  • https://1.1.1.1
  • https://1.1.1.1/dns-query?name
  • https://cloudflare-dns.com
  • https://dns.google
  • https://github.com
  • https://go.dev
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Suspicious The PE is packed with UPX Unusual section name found: UPX0
Unusual section name found: UPX1
Unusual section name found: UPX2
The PE only has 0 import(s).
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 cbe801a3361b3d918312f54b3b479d3b 🔍
SHA1 738ffb81d374eb111c46a2f63a8fe3a9d12fe642 🔍
SHA256 d2c0b8c5adb1b91b82a405f1c8cd668e7ca75957127c02d898af7a959204e207 🔍
SHA3 4abee2b730c3af6ec5c7a9e7d0371a6c74747d851bb79486d34e7b29185e0805 🔍
SSDeep 98304:7xbKk02vxUSGMt3nVq55t/ZYt34SG2Z1BEm:UkHU0t3A5t/Zk3/8m 🔍
Imports Hash d41d8cd98f00b204e9800998ecf8427e 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0x8b
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 3
TimeDateStamp 1970-Jan-01 00:00:00
PointerToSymbolTable 0xbfde00
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 3.0
SizeOfCode 0x36e000
SizeOfInitializedData 0x1000
SizeOfUninitializedData 0x8e7000
AddressOfEntryPoint 0x00C549A0 (Section: UPX1)
BaseOfCode 0x8e8000
BaseOfData 0xc56000
ImageBase 0x540000
SectionAlignment 0x1000
FileAlignment 0x1000
OperatingSystemVersion 6.1
ImageVersion 1.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0xc57000
SizeOfHeaders 0x200
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

UPX0

MD5 417c52b248710f0d7a1121d8baaa912e 🔍
SHA1 1968fef1efd9c5d2bef94274a0a911d459fb6bdd 🔍
SHA256 aedb143ba26fd2c39840bd31cc56c60a558fe7697fe92e98440dc1f7ec3e44fb 🔍
SHA3 5f1cff454d64587122485edb0c377700f336f2f173cf582714b54f626870c564 🔍
VirtualSize 0x8e7000
VirtualAddress 0x1000
SizeOfRawData 0x8e7000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.31373

UPX1

MD5 76b2261f21fc001bb3305c32cd65163d 🔍
SHA1 a1263ea9f20b2e3ab99b104265727737bb5cc462 🔍
SHA256 07d186634a0e33fb512d1d9187fe57adc6dd255176408ceb4f2fa75519aaf36a 🔍
SHA3 f22800d3aa4fafcec58cdd76be1e4e8809d3e18baca38d5569e94ffbb27d0a0f 🔍
VirtualSize 0x36e000
VirtualAddress 0x8e8000
SizeOfRawData 0x36e000
PointerToRawData 0x8e8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.72533

UPX2

MD5 0c960ca2a48fe58ef4624d7140dcb831 🔍
SHA1 2e32867ed48381218bf49eb7cbf8530d1eb84fdd 🔍
SHA256 a2dcb92734b5a87f93390aac3e8ec38ccec0854e4046585e631c3a6872f10ed5 🔍
SHA3 43df01f17c3ea1a040c6e8140434182168bd63f1000520f73f327e175226ee8e 🔍
VirtualSize 0x1000
VirtualAddress 0xc56000
SizeOfRawData 0x1000
PointerToRawData 0xc56000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.265109

Imports

KERNEL32.DLL (EMPTY)

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

RICH Header

Errors

[!] Error: Could not reach the HINT/NAME table. [*] Warning: An error occurred while trying to read functions imported by module KERNEL32.DLL.
Leave a comment

No comments yet.