| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Oct-01 19:30:22 |
| Detected languages |
English - United States
|
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA256 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| MD5 | 1b2cc3b937f063cd3f4bb38e0ad85025 🔍 |
|---|---|
| SHA1 | 98c3a9ae8265533f8d57e1662034b7b16598c3c8 🔍 |
| SHA256 | dfafbc3098d1ad219dda6aa1d944a1d76f9ea52bde1f2655ba8424fef1607ea0 🔍 |
| SHA3 | 33d68b4943aae5afbb8671f4f1a6e6d39f7420d1bc2903dfae620993410007f1 🔍 |
| SSDeep | 49152:xaGs7OKePOucC2wVWjqYP3vB5Qkf4MzIEOW:Ns7OHwfWEO 🔍 |
| Imports Hash | c051dbb90482b16373710603cdca1b43 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x130 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Oct-01 19:30:22 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x19a800 |
| SizeOfInitializedData | 0x2d8e00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000015ABD0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x478000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 74c6efbb44e1b8816446de04f54dff67 🔍 |
|---|---|
| SHA1 | f13b09c93b64394e41ee94256b257bce9c522ebb 🔍 |
| SHA256 | 7baf20b75d3b31cd2eb32237342158486237cb1d5ceb068eb5d72ae14cc651cd 🔍 |
| SHA3 | 8793fc6b5f9b33e6ff6e2f5cadb003416447f9c24f3acb81a883de88b0b3c380 🔍 |
| VirtualSize | 0x19a61c |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x19a800 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.58349 |
| MD5 | 742a63bbcbc14b4bdf2a2eb09c3ee948 🔍 |
|---|---|
| SHA1 | 255d7570fb42854a0e299c9017bde9a0958e0b29 🔍 |
| SHA256 | c27f985a618893098a4e88c7ae9b7b85cf101e027d44682c71d8841e2cff8704 🔍 |
| SHA3 | 48ec4ec79706f71994ebd5a3845006690c4fd733d1c6e4a7a6461a3d1db6b4c0 🔍 |
| VirtualSize | 0x62800 |
| VirtualAddress | 0x19c000 |
| SizeOfRawData | 0x62800 |
| PointerToRawData | 0x19ac00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.14554 |
| MD5 | 89b9f6ebf4eaf41c2aeccafd2afe06a1 🔍 |
|---|---|
| SHA1 | 2263ca3a8d27492f973053f133fca63a1d2fe695 🔍 |
| SHA256 | ad3c2b16f61298bee8c733cc355f5f9ac744b67cf9076f43d09eff837d70d075 🔍 |
| SHA3 | 62d9ed4f00212bc1ca0d4e07953da364d8cc1c5bd2eb480117acb22bdc9ceef6 🔍 |
| VirtualSize | 0x263248 |
| VirtualAddress | 0x1ff000 |
| SizeOfRawData | 0x20200 |
| PointerToRawData | 0x1fd400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 6.13254 |
| MD5 | 997ae7513e59a96034c224382b48de4a 🔍 |
|---|---|
| SHA1 | 20a732edd5b862dd28dbaaa0107c3e0f239d3193 🔍 |
| SHA256 | df57db6553c7d6fa7f852120eac7d8bde0fb42dd7b6c31f9d4c788602ad3e5ce 🔍 |
| SHA3 | 4d55ad3b04dd4f637acad4584fd225a9af3c3a77fe65deb7ac8435435af55309 🔍 |
| VirtualSize | 0xfd2c |
| VirtualAddress | 0x463000 |
| SizeOfRawData | 0xfe00 |
| PointerToRawData | 0x21d600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.21382 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x100 |
| VirtualAddress | 0x473000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x22d400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | c8f098755dc28188f404e197eefd3139 🔍 |
|---|---|
| SHA1 | 78333b139b84d5ebca00a6fa7f22c9cb5fcfb92b 🔍 |
| SHA256 | 53b07e301256b4caa536a4a58e764f64a5e17677aca6578f5b68bbce7838dfd0 🔍 |
| SHA3 | efa5c198f6d6454b2919e2a37a0c4f3a5dcdaaddeeff5d3c889a4164285ca7fc 🔍 |
| VirtualSize | 0x1330 |
| VirtualAddress | 0x474000 |
| SizeOfRawData | 0x1400 |
| PointerToRawData | 0x22d600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.16397 |
| MD5 | 93c0acb016d77f3739549eeefab2cc09 🔍 |
|---|---|
| SHA1 | e500534731fb46e396e559bfadd3bc00ef5afd47 🔍 |
| SHA256 | ad16e838043f2295d293127859f70a6505c80c8f4edf2fae862e5758950bfa64 🔍 |
| SHA3 | 4db302dd8fd5b5da7f7cfa9b7c0d44673ee2398ed2cc86e2feff03abebff205c 🔍 |
| VirtualSize | 0x1c14 |
| VirtualAddress | 0x476000 |
| SizeOfRawData | 0x1e00 |
| PointerToRawData | 0x22ea00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.34581 |
| d3dx9_43.dll |
D3DXMatrixTranspose
D3DXVec3Transform |
|---|---|
| KERNEL32.dll |
CloseHandle
GlobalLock LocalFree GetCurrentProcessId K32EnumProcessModules IsBadReadPtr GlobalUnlock VirtualQueryEx VirtualProtect GetCurrentProcess FreeLibraryAndExitThread Sleep DisableThreadLibraryCalls QueryPerformanceFrequency CreateThread SwitchToThread GetProcAddress GetModuleHandleW FlushInstructionCache QueryPerformanceCounter DeleteFiber SwitchToFiber GetTickCount64 HeapCreate HeapFree Thread32Next Thread32First GetCurrentThreadId SuspendThread ResumeThread GetLastError HeapReAlloc HeapAlloc GetThreadContext SetThreadContext OpenThread EnterCriticalSection LeaveCriticalSection InitializeCriticalSection GetTickCount MultiByteToWideChar GlobalFree WideCharToMultiByte LoadLibraryA FreeLibrary TerminateProcess Process32NextW Process32FirstW CreateRemoteThread IsThreadAFiber ConvertThreadToFiber CreateFiber CreateFileA GetFileSizeEx ReadFile GlobalAlloc MapViewOfFile UnmapViewOfFile CreateFileMappingA FlushFileBuffers EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW GetTimeFormatW GetDateFormatW LoadLibraryExW ReadConsoleW GetConsoleMode SetFilePointerEx OutputDebugStringW WriteFile UnhandledExceptionFilter IsDebuggerPresent RtlVirtualUnwind RtlCaptureContext IsProcessorFeaturePresent ExitProcess ExitThread WriteConsoleW GetModuleHandleExW GetModuleFileNameW GetFileType GetStdHandle RtlUnwind FlsFree FlsSetValue CreateToolhelp32Snapshot OpenProcess GetModuleHandleA Module32First LocalAlloc IsBadStringPtrA FlsGetValue FlsAlloc SetLastError RaiseException SetStdHandle SetEnvironmentVariableW RtlPcToFileHeader InterlockedFlushSList GetConsoleOutputCP RtlUnwindEx RtlLookupFunctionEntry GetStringTypeW GetCPInfo CompareStringEx LCMapStringEx DecodePointer FreeEnvironmentStringsW Module32Next GetModuleFileNameA VirtualQuery GetSystemInfo VirtualAlloc VirtualFree CreateFileW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetOEMCP HeapSize GetProcessHeap SetEndOfFile GetACP IsValidCodePage GetTimeZoneInformation ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW SetUnhandledExceptionFilter GetStartupInfoW GetSystemTimeAsFileTime InitializeSListHead FormatMessageA GetSystemTimePreciseAsFileTime GetCurrentDirectoryW CreateDirectoryW FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesExW SetFileInformationByHandle CreateFile2 AreFileApisANSI GetFileInformationByHandleEx GetLocaleInfoEx WaitForSingleObjectEx GetExitCodeThread InitializeCriticalSectionEx DeleteCriticalSection EncodePointer |
| USER32.dll |
CloseClipboard
CallWindowProcA GetWindowLongPtrW CallNextHookEx GetAsyncKeyState OpenClipboard EmptyClipboard SetClipboardData DefWindowProcA SetWindowLongPtrW GetKeyState LoadCursorA ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetClipboardData SetCapture SetCursor GetClientRect IsWindowUnicode ReleaseCapture SetCursorPos GetCursorPos GetForegroundWindow |
| COMDLG32.dll |
GetOpenFileNameW
|
| SHELL32.dll |
ShellExecuteA
SHGetKnownFolderPath ShellExecuteW |
| ole32.dll |
CoTaskMemFree
|
| WINHTTP.dll |
WinHttpQueryDataAvailable
WinHttpConnect WinHttpSendRequest WinHttpCloseHandle WinHttpOpenRequest WinHttpReadData WinHttpQueryHeaders WinHttpAddRequestHeaders WinHttpOpen WinHttpReceiveResponse WinHttpSetOption WinHttpSetTimeouts |
| IMM32.dll |
ImmSetCompositionWindow
ImmGetContext ImmReleaseContext ImmSetCandidateWindow |
| D3DCOMPILER_47.dll |
D3DCompile
|
| IPHLPAPI.DLL |
GetExtendedTcpTable
GetExtendedUdpTable |
| WS2_32.dll |
inet_ntop
ntohs |
| Ordinal | 1 |
|---|---|
| Address | 0x1e040 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x10a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.03119 |
| MD5 | dd9a1f01bf1527a40af17b68195c401b 🔍 |
| SHA1 | 901449ca922ab5a17946c11725902659810edb0b 🔍 |
| SHA256 | 1f1064347da9d16cb808c0b4c2df914ecc7d22959e4e5fa2075d9eecf7041553 🔍 |
| SHA3 | 73b4a17ab9aaa6018b751b1a1e2e8fb9d726fe0c3257d5ec0078817039514de4 🔍 |
| Type |
RT_GROUP_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x14 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 1.7815 |
| Detected Filetype | Icon file |
| MD5 | 3c68f77c35c26ff079a1c410ee44fa62 🔍 |
| SHA1 | 0b40150c95fc2c6414c90d44ee78b8d8814b3393 🔍 |
| SHA256 | a14e70ed824f3f17d3a51136aa08839954d6d3ccadaa067415c7bfc08e6636b0 🔍 |
| SHA3 | 590dcbf2ec3f485a6c24e3e627f383ee7588eb49978321f12c07d8190a6c1396 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Oct-01 19:30:22 |
| Version | 0.0 |
| SizeofData | 1008 |
| AddressOfRawData | 0x1e3428 |
| PointerToRawData | 0x1e2028 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Oct-01 19:30:22 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1801e3870 |
|---|---|
| EndAddressOfRawData | 0x1801e3878 |
| AddressOfIndex | 0x18021f104 |
| AddressOfCallbacks | 0x18019c838 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1801ff040 |
| XOR Key | 0x560764bb |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 184 |
| C objects (33145) | 33 |
| ASM objects (33145) | 26 |
| 253 (35721) | 1 |
| ASM objects (35721) | 12 |
| C objects (35721) | 16 |
| C++ objects (35721) | 88 |
| C objects (CVTCIL) (33145) | 1 |
| Imports (33145) | 24 |
| C objects (36260) | 26 |
| Imports (21202) | 3 |
| Total imports | 246 |
| C objects (LTCG) (36260) | 35 |
| Exports (36260) | 1 |
| Resource objects (36260) | 1 |
| 151 | 1 |
| Linker (36260) | 1 |
No comments yet.