| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Oct-10 15:39:55 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA256 Uses constants related to SHA512 |
| Suspicious | The PE is possibly packed. | Unusual section name found: nWD2DA1F |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| MD5 | 10788e82d0352e58bc0f962e6ae8401f 🔍 |
|---|---|
| SHA1 | 642485fc9d483338ff5c1cc94bdf7ae3b5aed9c9 🔍 |
| SHA256 | df90a1ba59c89d98d99069b3393561b972bf65b5703b3d6c0a85bb89fa89e4b4 🔍 |
| SHA3 | 7c1f5c9626916f3f0e4a7bdfb40eeab0bc0e027d8d94e5e7b0d84a085cda7043 🔍 |
| SSDeep | 49152:YDxCVIU6ismtyiI3XhFzLRDdIsMYX1PSkkg6Pq5j/:YNr+smQXhbddTX1Px+q5z 🔍 |
| Imports Hash | 0bed6dc33c1baf7a3eb4b0169dfa9c03 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 11 |
| TimeDateStamp | 2026-Oct-10 15:39:55 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x1dba00 |
| SizeOfInitializedData | 0x9de00 |
| SizeOfUninitializedData | 0x400 |
| AddressOfEntryPoint | 0x0000000000280840 (Section: nWD2DA1F) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x3c0000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | d41d8cd98f00b204e9800998ecf8427e 🔍 |
|---|---|
| SHA1 | da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍 |
| SHA256 | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍 |
| SHA3 | a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍 |
| VirtualSize | 0x1db930 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0 |
| PointerToRawData | 0 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| MD5 | 56222b87cd44fa35a6e3f8424081cb5c 🔍 |
|---|---|
| SHA1 | 3a9937384c66553004fefbe9458dc0a0e3ee6b06 🔍 |
| SHA256 | 09de0e5fae443f81f6c965bf531ac6a55a7b77d867bd4dfae2104bf4e5ddf939 🔍 |
| SHA3 | 49ccc244c1a61e5a29ebd79b6426498907faf6382ec4f73cafad7df7e17515de 🔍 |
| VirtualSize | 0xd80 |
| VirtualAddress | 0x1dd000 |
| SizeOfRawData | 0xe00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0.433565 |
| MD5 | d3730559ad62f97ddd2d55bfff0e1414 🔍 |
|---|---|
| SHA1 | a6317dd088ee8e463231a93258f515eec4aec12a 🔍 |
| SHA256 | df05c856a811ac0b39676ff0273a9f2f865672f22410d5de785a28a29dbaf8e4 🔍 |
| SHA3 | 73b1a15f0be2308d046ed5d5cb7ef044b303509978483800628ebd619aac4290 🔍 |
| VirtualSize | 0x780e0 |
| VirtualAddress | 0x1de000 |
| SizeOfRawData | 0x78200 |
| PointerToRawData | 0x1200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.82258 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x4 |
| VirtualAddress | 0x257000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x79400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 51a763ef969fe7568497a95bcbe300a2 🔍 |
|---|---|
| SHA1 | b9c5cd58d68c70d297b945d2285ecc7cb8528f8b 🔍 |
| SHA256 | 6c592e18c7010d232cbdadecfff90efa10f9709fb3c0cf805583018146d47d4e 🔍 |
| SHA3 | d65fa7261c47b3b94e63c6dc70b8dca9f3f94ac8d0b42e6a6263d3d9b4871265 🔍 |
| VirtualSize | 0xd3a4 |
| VirtualAddress | 0x258000 |
| SizeOfRawData | 0xd400 |
| PointerToRawData | 0x79600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.30496 |
| MD5 | a50f1eb3c3f3519359302df5fbb51f14 🔍 |
|---|---|
| SHA1 | 58d7cbb0a09347403d53b6ffeff3c3e3bac5a339 🔍 |
| SHA256 | 927ccb7f4b5bd2b38fbf6e41e328355a5e9722c3d40f8a99be5bfc286b2dc297 🔍 |
| SHA3 | b940d055497b53ef4a974685bb3233795070d8b223e7f0e200ac267c48af1ba7 🔍 |
| VirtualSize | 0x11628 |
| VirtualAddress | 0x266000 |
| SizeOfRawData | 0x11800 |
| PointerToRawData | 0x86a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.97836 |
| MD5 | d41d8cd98f00b204e9800998ecf8427e 🔍 |
|---|---|
| SHA1 | da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍 |
| SHA256 | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍 |
| SHA3 | a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍 |
| VirtualSize | 0x2c0 |
| VirtualAddress | 0x278000 |
| SizeOfRawData | 0 |
| PointerToRawData | 0 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| MD5 | f4ff360aaa22f5a703996748823feab1 🔍 |
|---|---|
| SHA1 | d1b986b5f168d12dcf5f21193ec3f26f988315a7 🔍 |
| SHA256 | ee49ecc1866bcb0439e0981addca92fa858c38b248aec46cc8f5ebb22b1c7f74 🔍 |
| SHA3 | 6a4732797b527fc9f7449f0644f99b437af6966b806e489ace7058f29364b839 🔍 |
| VirtualSize | 0x2ef0 |
| VirtualAddress | 0x279000 |
| SizeOfRawData | 0x3000 |
| PointerToRawData | 0x98200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.67001 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x10 |
| VirtualAddress | 0x27c000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x9b200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 08f42852bf6f00bebcd7d0c3a1b0e729 🔍 |
|---|---|
| SHA1 | 89f8b47eb82e6901efb5e0136962f0463a8c7be5 🔍 |
| SHA256 | a6d9a6b66fe6c76dfe7461a6d72b11ca057aae697768347f8ace65f6adc88a5a 🔍 |
| SHA3 | a9682f4d024c8970274d06b9e3c29c179b478c8558ef4dc1166dcc890310040e 🔍 |
| VirtualSize | 0x2cd4 |
| VirtualAddress | 0x27d000 |
| SizeOfRawData | 0x2e00 |
| PointerToRawData | 0x9b400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.42023 |
| MD5 | f98bd7e14036ecf73d1b1e1dae0075ed 🔍 |
|---|---|
| SHA1 | 1f943184fc6dc8729a0f6834d7238e366c742130 🔍 |
| SHA256 | 9d4f8d244c74ae145a19d396513d6dfffe8c1c6e4ea3da5a6afc0874ad72f126 🔍 |
| SHA3 | 3c3c0af6508d18edda4395978d84e49ac313da05657ecd64a860a4596e1d169c 🔍 |
| VirtualSize | 0x13f7d0 |
| VirtualAddress | 0x280000 |
| SizeOfRawData | 0x13f800 |
| PointerToRawData | 0x9e200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 7.9792 |
| gdi32.dll |
BitBlt
CreateCompatibleBitmap CreateCompatibleDC CreateDCW DeleteDC DeleteObject GetDIBits GetDeviceCaps SelectObject |
|---|---|
| netapi32.dll |
NetApiBufferFree
NetUserEnum |
| oleaut32.dll |
GetErrorInfo
|
| pdh.dll |
PdhAddEnglishCounterW
PdhCloseQuery PdhCollectQueryData PdhEnumObjectsA PdhGetFormattedCounterValue PdhOpenQueryA PdhRemoveCounter |
| powrprof.dll |
CallNtPowerInformation
|
| psapi.dll |
GetModuleFileNameExW
|
| shell32.dll |
CommandLineToArgvW
ShellExecuteW |
| user32.dll |
EnumDisplayMonitors
EnumDisplaySettingsW GetDesktopWindow GetMonitorInfoW GetSystemMetrics GetWindowDC MessageBoxW ReleaseDC SetCursorPos keybd_event mouse_event |
| wlanapi.dll |
WlanCloseHandle
WlanEnumInterfaces WlanFreeMemory WlanGetAvailableNetworkList WlanGetProfileList WlanOpenHandle |
| kernel32.dll |
GetComputerNameExW
|
| kernel32.dll (#2) |
GetComputerNameExW
|
| bcryptprimitives.dll |
ProcessPrng
|
| advapi32.dll |
CopySid
GetLengthSid GetTokenInformation GetUserNameW IsValidSid OpenProcessToken |
| api-ms-win-core-synch-l1-2-0.dll |
WaitOnAddress
WakeByAddressAll WakeByAddressSingle |
| iphlpapi.dll |
GetAdaptersAddresses
GetIpForwardTable |
| kernel32.dll (#3) |
GetComputerNameExW
|
| oleaut32.dll (#2) |
GetErrorInfo
|
| ws2_32.dll |
WSACleanup
WSAGetLastError WSAIoctl WSASend WSASocketW WSAStartup bind closesocket connect freeaddrinfo getaddrinfo getsockopt ioctlsocket recv send setsockopt shutdown |
| ADVAPI32.dll |
CloseServiceHandle
ControlService CreateServiceW DeleteService EnumServicesStatusExW OpenSCManagerW OpenServiceW QueryServiceStatusEx RegCloseKey RegCreateKeyExW RegDeleteValueW RegEnumKeyExW RegEnumValueW RegOpenKeyExW RegQueryValueExW RegSetValueExW RegisterServiceCtrlHandlerExW SetServiceStatus StartServiceCtrlDispatcherW StartServiceW SystemFunction036 |
| bcrypt.dll |
BCryptGenRandom
|
| KERNEL32.dll |
AddVectoredExceptionHandler
CompareStringOrdinal CreateToolhelp32Snapshot DeleteCriticalSection EnterCriticalSection FreeEnvironmentStringsW GetCommandLineW GetCurrentDirectoryW GetEnvironmentStringsW GetEnvironmentVariableW GetModuleFileNameW GetModuleHandleW GetSystemDirectoryW GetSystemInfo GetSystemTimePreciseAsFileTime GetTickCount64 GetWindowsDirectoryW GlobalMemoryStatusEx InitializeCriticalSection K32GetPerformanceInfo LeaveCriticalSection LoadLibraryA LoadLibraryExA Module32FirstW Module32NextW MultiByteToWideChar QueryPerformanceCounter QueryPerformanceFrequency RaiseException RtlUnwindEx SetUnhandledExceptionFilter Thread32First Thread32Next VirtualProtect VirtualQuery __C_specific_handler |
| api-ms-win-crt-environment-l1-1-0.dll |
__p__environ
|
| api-ms-win-crt-heap-l1-1-0.dll |
_set_new_mode
calloc free malloc |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
pow roundf |
| api-ms-win-crt-private-l1-1-0.dll |
memcmp
memcpy memmove |
| api-ms-win-crt-runtime-l1-1-0.dll |
_set_app_type
__p___argc __p___argv _cexit _configure_narrow_argv _crt_atexit _exit _fpreset _initialize_narrow_environment _initterm _initterm_e _set_invalid_parameter_handler abort exit signal |
| api-ms-win-crt-stdio-l1-1-0.dll |
__acrt_iob_func
__p__commode __p__fmode __stdio_common_vfprintf fflush setvbuf |
| api-ms-win-crt-string-l1-1-0.dll |
memset
strlen strncmp wcslen |
| ntdll.dll |
NtCancelIoFileEx
NtCreateFile NtCreateNamedPipeFile NtDeviceIoControlFile NtOpenFile NtQueryInformationProcess NtQuerySystemInformation NtReadFile NtWriteFile RtlCaptureContext RtlGetVersion RtlLookupFunctionEntry RtlNtStatusToDosError RtlVirtualUnwind |
No comments yet.