dfafbc3098d1ad219dda6aa1d944a1d76f9ea52bde1f2655ba8424fef1607ea0

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Oct-01 19:30:22
Detected languages English - United States

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • fontello.com
  • http://fontello.com
  • http://www.metype.co.uk
  • http://www.metype.co.ukStolzlMedium
  • http://www.thenorthernblock.co.ukhttp
  • metype.co.uk
  • www.metype.co.uk
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA256
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
  • CreateToolhelp32Snapshot
Code injection capabilities:
  • CreateRemoteThread
  • OpenProcess
  • VirtualAlloc
Code injection capabilities (mapping injection):
  • CreateRemoteThread
  • MapViewOfFile
  • CreateFileMappingA
Possibly launches other programs:
  • ShellExecuteA
  • ShellExecuteW
Uses functions commonly found in keyloggers:
  • CallNextHookEx
  • GetAsyncKeyState
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Has Internet access capabilities:
  • WinHttpQueryDataAvailable
  • WinHttpConnect
  • WinHttpSendRequest
  • WinHttpCloseHandle
  • WinHttpOpenRequest
  • WinHttpReadData
  • WinHttpQueryHeaders
  • WinHttpAddRequestHeaders
  • WinHttpOpen
  • WinHttpReceiveResponse
  • WinHttpSetOption
  • WinHttpSetTimeouts
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Manipulates other processes:
  • Process32NextW
  • Process32FirstW
  • OpenProcess
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 1b2cc3b937f063cd3f4bb38e0ad85025 🔍
SHA1 98c3a9ae8265533f8d57e1662034b7b16598c3c8 🔍
SHA256 dfafbc3098d1ad219dda6aa1d944a1d76f9ea52bde1f2655ba8424fef1607ea0 🔍
SHA3 33d68b4943aae5afbb8671f4f1a6e6d39f7420d1bc2903dfae620993410007f1 🔍
SSDeep 49152:xaGs7OKePOucC2wVWjqYP3vB5Qkf4MzIEOW:Ns7OHwfWEO 🔍
Imports Hash c051dbb90482b16373710603cdca1b43 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x130

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Oct-01 19:30:22
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x19a800
SizeOfInitializedData 0x2d8e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000015ABD0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x478000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 74c6efbb44e1b8816446de04f54dff67 🔍
SHA1 f13b09c93b64394e41ee94256b257bce9c522ebb 🔍
SHA256 7baf20b75d3b31cd2eb32237342158486237cb1d5ceb068eb5d72ae14cc651cd 🔍
SHA3 8793fc6b5f9b33e6ff6e2f5cadb003416447f9c24f3acb81a883de88b0b3c380 🔍
VirtualSize 0x19a61c
VirtualAddress 0x1000
SizeOfRawData 0x19a800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.58349

.rdata

MD5 742a63bbcbc14b4bdf2a2eb09c3ee948 🔍
SHA1 255d7570fb42854a0e299c9017bde9a0958e0b29 🔍
SHA256 c27f985a618893098a4e88c7ae9b7b85cf101e027d44682c71d8841e2cff8704 🔍
SHA3 48ec4ec79706f71994ebd5a3845006690c4fd733d1c6e4a7a6461a3d1db6b4c0 🔍
VirtualSize 0x62800
VirtualAddress 0x19c000
SizeOfRawData 0x62800
PointerToRawData 0x19ac00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.14554

.data

MD5 89b9f6ebf4eaf41c2aeccafd2afe06a1 🔍
SHA1 2263ca3a8d27492f973053f133fca63a1d2fe695 🔍
SHA256 ad3c2b16f61298bee8c733cc355f5f9ac744b67cf9076f43d09eff837d70d075 🔍
SHA3 62d9ed4f00212bc1ca0d4e07953da364d8cc1c5bd2eb480117acb22bdc9ceef6 🔍
VirtualSize 0x263248
VirtualAddress 0x1ff000
SizeOfRawData 0x20200
PointerToRawData 0x1fd400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.13254

.pdata

MD5 997ae7513e59a96034c224382b48de4a 🔍
SHA1 20a732edd5b862dd28dbaaa0107c3e0f239d3193 🔍
SHA256 df57db6553c7d6fa7f852120eac7d8bde0fb42dd7b6c31f9d4c788602ad3e5ce 🔍
SHA3 4d55ad3b04dd4f637acad4584fd225a9af3c3a77fe65deb7ac8435435af55309 🔍
VirtualSize 0xfd2c
VirtualAddress 0x463000
SizeOfRawData 0xfe00
PointerToRawData 0x21d600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.21382

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x473000
SizeOfRawData 0x200
PointerToRawData 0x22d400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 c8f098755dc28188f404e197eefd3139 🔍
SHA1 78333b139b84d5ebca00a6fa7f22c9cb5fcfb92b 🔍
SHA256 53b07e301256b4caa536a4a58e764f64a5e17677aca6578f5b68bbce7838dfd0 🔍
SHA3 efa5c198f6d6454b2919e2a37a0c4f3a5dcdaaddeeff5d3c889a4164285ca7fc 🔍
VirtualSize 0x1330
VirtualAddress 0x474000
SizeOfRawData 0x1400
PointerToRawData 0x22d600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.16397

.reloc

MD5 93c0acb016d77f3739549eeefab2cc09 🔍
SHA1 e500534731fb46e396e559bfadd3bc00ef5afd47 🔍
SHA256 ad16e838043f2295d293127859f70a6505c80c8f4edf2fae862e5758950bfa64 🔍
SHA3 4db302dd8fd5b5da7f7cfa9b7c0d44673ee2398ed2cc86e2feff03abebff205c 🔍
VirtualSize 0x1c14
VirtualAddress 0x476000
SizeOfRawData 0x1e00
PointerToRawData 0x22ea00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.34581

Imports

d3dx9_43.dll D3DXMatrixTranspose
D3DXVec3Transform
KERNEL32.dll CloseHandle
GlobalLock
LocalFree
GetCurrentProcessId
K32EnumProcessModules
IsBadReadPtr
GlobalUnlock
VirtualQueryEx
VirtualProtect
GetCurrentProcess
FreeLibraryAndExitThread
Sleep
DisableThreadLibraryCalls
QueryPerformanceFrequency
CreateThread
SwitchToThread
GetProcAddress
GetModuleHandleW
FlushInstructionCache
QueryPerformanceCounter
DeleteFiber
SwitchToFiber
GetTickCount64
HeapCreate
HeapFree
Thread32Next
Thread32First
GetCurrentThreadId
SuspendThread
ResumeThread
GetLastError
HeapReAlloc
HeapAlloc
GetThreadContext
SetThreadContext
OpenThread
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSection
GetTickCount
MultiByteToWideChar
GlobalFree
WideCharToMultiByte
LoadLibraryA
FreeLibrary
TerminateProcess
Process32NextW
Process32FirstW
CreateRemoteThread
IsThreadAFiber
ConvertThreadToFiber
CreateFiber
CreateFileA
GetFileSizeEx
ReadFile
GlobalAlloc
MapViewOfFile
UnmapViewOfFile
CreateFileMappingA
FlushFileBuffers
EnumSystemLocalesW
GetUserDefaultLCID
IsValidLocale
GetLocaleInfoW
LCMapStringW
CompareStringW
GetTimeFormatW
GetDateFormatW
LoadLibraryExW
ReadConsoleW
GetConsoleMode
SetFilePointerEx
OutputDebugStringW
WriteFile
UnhandledExceptionFilter
IsDebuggerPresent
RtlVirtualUnwind
RtlCaptureContext
IsProcessorFeaturePresent
ExitProcess
ExitThread
WriteConsoleW
GetModuleHandleExW
GetModuleFileNameW
GetFileType
GetStdHandle
RtlUnwind
FlsFree
FlsSetValue
CreateToolhelp32Snapshot
OpenProcess
GetModuleHandleA
Module32First
LocalAlloc
IsBadStringPtrA
FlsGetValue
FlsAlloc
SetLastError
RaiseException
SetStdHandle
SetEnvironmentVariableW
RtlPcToFileHeader
InterlockedFlushSList
GetConsoleOutputCP
RtlUnwindEx
RtlLookupFunctionEntry
GetStringTypeW
GetCPInfo
CompareStringEx
LCMapStringEx
DecodePointer
FreeEnvironmentStringsW
Module32Next
GetModuleFileNameA
VirtualQuery
GetSystemInfo
VirtualAlloc
VirtualFree
CreateFileW
GetEnvironmentStringsW
GetCommandLineW
GetCommandLineA
GetOEMCP
HeapSize
GetProcessHeap
SetEndOfFile
GetACP
IsValidCodePage
GetTimeZoneInformation
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
SetUnhandledExceptionFilter
GetStartupInfoW
GetSystemTimeAsFileTime
InitializeSListHead
FormatMessageA
GetSystemTimePreciseAsFileTime
GetCurrentDirectoryW
CreateDirectoryW
FindClose
FindFirstFileW
FindFirstFileExW
FindNextFileW
GetFileAttributesExW
SetFileInformationByHandle
CreateFile2
AreFileApisANSI
GetFileInformationByHandleEx
GetLocaleInfoEx
WaitForSingleObjectEx
GetExitCodeThread
InitializeCriticalSectionEx
DeleteCriticalSection
EncodePointer
USER32.dll CloseClipboard
CallWindowProcA
GetWindowLongPtrW
CallNextHookEx
GetAsyncKeyState
OpenClipboard
EmptyClipboard
SetClipboardData
DefWindowProcA
SetWindowLongPtrW
GetKeyState
LoadCursorA
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetClipboardData
SetCapture
SetCursor
GetClientRect
IsWindowUnicode
ReleaseCapture
SetCursorPos
GetCursorPos
GetForegroundWindow
COMDLG32.dll GetOpenFileNameW
SHELL32.dll ShellExecuteA
SHGetKnownFolderPath
ShellExecuteW
ole32.dll CoTaskMemFree
WINHTTP.dll WinHttpQueryDataAvailable
WinHttpConnect
WinHttpSendRequest
WinHttpCloseHandle
WinHttpOpenRequest
WinHttpReadData
WinHttpQueryHeaders
WinHttpAddRequestHeaders
WinHttpOpen
WinHttpReceiveResponse
WinHttpSetOption
WinHttpSetTimeouts
IMM32.dll ImmSetCompositionWindow
ImmGetContext
ImmReleaseContext
ImmSetCandidateWindow
D3DCOMPILER_47.dll D3DCompile
IPHLPAPI.DLL GetExtendedTcpTable
GetExtendedUdpTable
WS2_32.dll inet_ntop
ntohs

Delayed Imports

UhqHook

Ordinal 1
Address 0x1e040

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.03119
MD5 dd9a1f01bf1527a40af17b68195c401b 🔍
SHA1 901449ca922ab5a17946c11725902659810edb0b 🔍
SHA256 1f1064347da9d16cb808c0b4c2df914ecc7d22959e4e5fa2075d9eecf7041553 🔍
SHA3 73b4a17ab9aaa6018b751b1a1e2e8fb9d726fe0c3257d5ec0078817039514de4 🔍

101

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.7815
Detected Filetype Icon file
MD5 3c68f77c35c26ff079a1c410ee44fa62 🔍
SHA1 0b40150c95fc2c6414c90d44ee78b8d8814b3393 🔍
SHA256 a14e70ed824f3f17d3a51136aa08839954d6d3ccadaa067415c7bfc08e6636b0 🔍
SHA3 590dcbf2ec3f485a6c24e3e627f383ee7588eb49978321f12c07d8190a6c1396 🔍

2

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Oct-01 19:30:22
Version 0.0
SizeofData 1008
AddressOfRawData 0x1e3428
PointerToRawData 0x1e2028

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Oct-01 19:30:22
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1801e3870
EndAddressOfRawData 0x1801e3878
AddressOfIndex 0x18021f104
AddressOfCallbacks 0x18019c838
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1801ff040

RICH Header

XOR Key 0x560764bb
Unmarked objects 0
C++ objects (33145) 184
C objects (33145) 33
ASM objects (33145) 26
253 (35721) 1
ASM objects (35721) 12
C objects (35721) 16
C++ objects (35721) 88
C objects (CVTCIL) (33145) 1
Imports (33145) 24
C objects (36260) 26
Imports (21202) 3
Total imports 246
C objects (LTCG) (36260) 35
Exports (36260) 1
Resource objects (36260) 1
151 1
Linker (36260) 1

Errors

Leave a comment

No comments yet.