e8887b85b810e64b293fcff6919b1b6cc2eb61203799a17b89fc744aed62e32f

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Sep-19 11:54:31
Debug artifacts aircard.pdb

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • adobe.com
  • apple.com
  • blog.demofox.org
  • daltonmaag.com
  • demofox.org
  • device...com
  • github.com
  • google.com
  • http://ns.adobe.com
  • http://ns.adobe.com/xmp/extension/
  • http://ns.adobe.iso
  • http://scripts.sil.org
  • http://scripts.sil.org/OFL
  • http://www.apple.com
  • http://www.apple.com/DTDs/PropertyList-1.0.dtd
  • http://www.daltonmaag.com
  • http://www.daltonmaag.com/http
  • http://www.daltonmaag.comUbuntuLight
  • http://www.google.com
  • http://www.google.com/get/noto/http
  • http://www.monotype.com
  • http://www.monotype.com/studioThis
  • https://blog.demofox.org
  • https://blog.demofox.org/2022/01/01/interleaved-gradient-noise-a-different-kind-of-low-discrepancy-sequence/
  • https://docs.rs
  • https://github.com
  • https://www.shadertoy.com
  • https://www.shadertoy.com/view/llVGzG
  • monotype.com
  • ns.adobe.com
  • scripts.sil.org
  • shadertoy.com
  • www.apple.com
  • www.daltonmaag.com
  • www.google.com
  • www.monotype.com
  • www.shadertoy.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to RC5 or RC6
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExA
  • LoadLibraryExW
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Possibly launches other programs:
  • CreateProcessW
Uses Windows's Native API:
  • NtReadFile
  • NtCreateNamedPipeFile
  • NtOpenFile
  • NtWriteFile
Uses functions commonly found in keyloggers:
  • MapVirtualKeyW
  • GetForegroundWindow
  • GetAsyncKeyState
Leverages the raw socket API to access the Internet:
  • ws2_32.dll
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious VirusTotal score: 1/70 (Scanned on 2026-09-29 11:58:34) APEX: Malicious

Hashes

MD5 8a0b8b96c0863277dfb9a1f2fcc2ca29 🔍
SHA1 4cdb0e49ceeffe1e0b56a2a1eaf3b7beda733b75 🔍
SHA256 e8887b85b810e64b293fcff6919b1b6cc2eb61203799a17b89fc744aed62e32f 🔍
SHA3 1a637f0074565a57ac7608cb1b9c414b82e166bb77bf5adbd9fa998363a9f4ec 🔍
SSDeep 49152:kcokurHr2QC9nwQxtYVzcxcBDeRpRonMAos9w+zF655O336U3JDwcCnohVfcQN5:kHlC/VUoseUT3HSAN5+BbF6C 🔍
Imports Hash 7ccec30f46d05b6d74a84f572526872a 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 5
TimeDateStamp 2026-Sep-19 11:54:31
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x486e00
SizeOfInitializedData 0x2dfa00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000044CE80 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x769000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 6eebb0c047ba35e9e069a22687352e45 🔍
SHA1 c5a9e72869064703caa7618812afdc79d5b88404 🔍
SHA256 c8f3c37abcb1291dc08683e29c29c40c50adfe0d75d6e730e4619f031f1de86d 🔍
SHA3 0ddc7adc99d7a158257fe0ccae8357e9777b525b46b405a714f1dc82b028c842 🔍
VirtualSize 0x486d08
VirtualAddress 0x1000
SizeOfRawData 0x486e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.38203

.rdata

MD5 a50406df600da86cffad75f453b24b0d 🔍
SHA1 9a42ed93ea98dbfbe6faed863ded7e53628c3878 🔍
SHA256 16c2065efe6af12ad22dfd4828a744d368a9bee47d53d7bbd5bc014893fc233e 🔍
SHA3 5ad604f63ffa73f1b617c53cfcb62e74e605e1e210516cb5211fcb0bc4a136c1 🔍
VirtualSize 0x2b8b5e
VirtualAddress 0x488000
SizeOfRawData 0x2b8c00
PointerToRawData 0x487200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.28241

.data

MD5 a234b7aca29f89cc88937076c5c97f81 🔍
SHA1 997c94908a475034d5888246670e18c0230a3240 🔍
SHA256 d46ed81ad418298fc667a0bcf0d9d32e1a6246b9ee9c573d0d0ee090fa422622 🔍
SHA3 1d205a0fe3a11f2ff19eca85e8707d9857051961817c9c098e7a9c0314848e1f 🔍
VirtualSize 0xe40
VirtualAddress 0x741000
SizeOfRawData 0xc00
PointerToRawData 0x73fe00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.05912

.pdata

MD5 6c2d2e6b7a82582090c772ebfa713bd6 🔍
SHA1 c9161f5e9cd86857de7b09b5598ecd89bd79af38 🔍
SHA256 6037c42f83378d0121e9abf0987d060e53a3a6f3603832b9753647fd00616cf9 🔍
SHA3 b17c9d1dd412e64bf8a84aba9ef0d5d11a9a0e14cd08f8ccffc66cfea94c2548 🔍
VirtualSize 0x20268
VirtualAddress 0x742000
SizeOfRawData 0x20400
PointerToRawData 0x740a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.41673

.reloc

MD5 048b5d86af0a974bae4461d3ac86547c 🔍
SHA1 b372f03394fb31f71c0800429fad3b7fe707d21a 🔍
SHA256 d5ea3e4477639b4e33ce5fc7c03298eb1f13fad73e9e4b41a8d3a3152de1875f 🔍
SHA3 9ac4bea2189ff776ccc54c36d0f6e2679295482171b1000328b3cd3352c2b39d 🔍
VirtualSize 0x5968
VirtualAddress 0x763000
SizeOfRawData 0x5a00
PointerToRawData 0x760e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.46214

Imports

bcrypt.dll BCryptGenRandom
kernel32.dll SetHandleInformation
GetModuleHandleW
GetProcessHeap
HeapFree
HeapAlloc
GlobalFree
FormatMessageW
SetDllDirectoryW
LoadLibraryExA
LoadLibraryExW
LoadLibraryA
GetModuleFileNameW
DuplicateHandle
GetModuleHandleA
GetModuleHandleExW
SetThreadErrorMode
FreeLibrary
GetProcAddress
GetLastError
Sleep
LoadLibraryW
CloseHandle
SetLastError
ntdll.dll NtReadFile
NtCreateNamedPipeFile
NtOpenFile
NtWriteFile
RtlNtStatusToDosError
oleaut32.dll GetErrorInfo
VariantClear
SysAllocStringLen
SysStringLen
SetErrorInfo
SysFreeString
SafeArrayCreateVector
SafeArrayPutElement
user32.dll MapVirtualKeyW
SendInput
SetForegroundWindow
LoadCursorW
SetCursor
GetClassNameW
GetClassInfoExW
RegisterWindowMessageA
ShowWindow
GetPropW
SetPropW
SetWindowLongPtrW
CallWindowProcW
ClientToScreen
DefWindowProcW
GetSystemMenu
EnableMenuItem
RemovePropW
RegisterClassExW
CreateWindowExW
SetWindowLongW
RegisterRawInputDevices
DestroyCursor
GetWindowLongPtrW
PeekMessageW
GetCursorPos
TranslateMessage
DispatchMessageW
DestroyWindow
RedrawWindow
PostMessageW
ReleaseDC
EnumDisplayMonitors
GetMonitorInfoW
MonitorFromPoint
GetDC
IsWindowVisible
SystemParametersInfoA
GetClientRect
GetActiveWindow
GetSystemMetrics
SendMessageW
CreateIconFromResourceEx
IsIconic
SetWindowPos
InvalidateRgn
CreateIcon
DestroyIcon
GetForegroundWindow
MonitorFromWindow
GetWindowTextLengthW
GetWindowTextW
SetCursorPos
SetWindowTextW
SetWindowDisplayAffinity
FlashWindowEx
ChangeDisplaySettingsExW
GetWindowPlacement
SetWindowPlacement
GetWindowRect
ReleaseCapture
ValidateRect
GetRawInputData
MsgWaitForMultipleObjectsEx
ToUnicodeEx
AdjustWindowRectEx
GetWindowLongW
ShowCursor
ClipCursor
GetClipCursor
TrackMouseEvent
SetCapture
MonitorFromRect
ScreenToClient
GetMenu
GetKeyboardLayout
MapVirtualKeyExW
IsProcessDPIAware
GetKeyState
GetAsyncKeyState
GetKeyboardState
uiautomationcore.dll UiaRaiseAutomationPropertyChangedEvent
UiaRaiseAutomationEvent
UiaLookupId
UiaGetReservedNotSupportedValue
UiaReturnRawElementProvider
UiaHostProviderFromHwnd
gdi32.dll DeleteObject
GetDeviceCaps
CreateRectRgn
ole32.dll CoCreateInstance
CoInitializeEx
OleInitialize
RegisterDragDrop
RevokeDragDrop
CoCreateFreeThreadedMarshaler
CoTaskMemFree
CoUninitialize
shlwapi.dll AssocQueryStringW
shell32.dll DragQueryFileW
SHCreateItemFromParsingName
DragFinish
bcryptprimitives.dll ProcessPrng
api-ms-win-core-synch-l1-2-0.dll WakeByAddressAll
WaitOnAddress
WakeByAddressSingle
OPENGL32.dll wglGetProcAddress
wglCreateContext
wglDeleteContext
wglShareLists
wglGetCurrentContext
wglGetCurrentDC
wglMakeCurrent
KERNEL32.dll InitializeSListHead
SetUnhandledExceptionFilter
GlobalLock
GetSystemTimeAsFileTime
SetWaitableTimer
CreateWaitableTimerExW
GetFileAttributesW
CreateProcessW
GetWindowsDirectoryW
GetSystemDirectoryW
FreeEnvironmentStringsW
GetEnvironmentStringsW
CompareStringOrdinal
ExitProcess
CreateDirectoryW
GetFileInformationByHandleEx
GetFileInformationByHandle
FindClose
FindFirstFileExW
SetFileInformationByHandle
SetFileTime
CreateFileW
GetFullPathNameW
QueryPerformanceCounter
QueryPerformanceFrequency
WriteFileEx
ReadFileEx
SleepEx
GetEnvironmentVariableW
IsThreadAFiber
FlsSetValue
FlsFree
FlsAlloc
WriteConsoleW
GetConsoleOutputCP
GetConsoleMode
GetStdHandle
ReleaseMutex
CreateMutexA
GetCurrentProcessId
lstrlenW
GetCurrentProcess
WaitForSingleObjectEx
GetCurrentDirectoryW
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
GetSystemInfo
WideCharToMultiByte
GlobalSize
GetCurrentThreadId
MultiByteToWideChar
GlobalUnlock
GlobalAlloc
GetCurrentThread
SetThreadStackGuarantee
AddVectoredExceptionHandler
WaitForSingleObject
HeapReAlloc
CreateThread
SwitchToThread
SetFilePointerEx
GetLocalTime
USER32.dll CloseTouchInputHandle
IsClipboardFormatAvailable
RegisterClipboardFormatW
CloseClipboard
SetClipboardData
EmptyClipboard
GetClipboardData
GetTouchInputInfo
RegisterTouchWindow
OpenClipboard
GDI32.dll SwapBuffers
SetPixelFormat
DescribePixelFormat
ChoosePixelFormat
ADVAPI32.dll RevertToSelf
ImpersonateAnonymousToken
ws2_32.dll setsockopt
WSACleanup
WSAStartup
send
recv
getsockopt
select
closesocket
connect
ioctlsocket
WSASocketW
WSAGetLastError
imm32.dll ImmAssociateContextEx
ImmSetCompositionWindow
ImmGetContext
ImmGetCompositionStringW
ImmReleaseContext
ImmSetCandidateWindow
dwmapi.dll DwmEnableBlurBehindWindow
DwmSetWindowAttribute
uxtheme.dll SetWindowTheme
VCRUNTIME140.dll memcmp
memset
_CxxThrowException
memmove
__current_exception_context
memcpy
__current_exception
__C_specific_handler
__CxxFrameHandler3
api-ms-win-crt-math-l1-1-0.dll exp2f
cbrtf
acosf
floor
atan2f
truncf
cosf
fmod
cos
sin
powf
_hypotf
sinf
expf
__setusermatherr
floorf
roundf
round
ceilf
trunc
api-ms-win-crt-string-l1-1-0.dll wcslen
strlen
api-ms-win-crt-runtime-l1-1-0.dll _seh_filter_exe
_set_app_type
strerror
_configure_narrow_argv
_initialize_narrow_environment
_get_initial_narrow_environment
_initterm
_initterm_e
exit
_exit
_register_thread_local_exe_atexit_callback
__p___argv
_cexit
_c_exit
__p___argc
terminate
_initialize_onexit_table
_register_onexit_function
_crt_atexit
api-ms-win-crt-stdio-l1-1-0.dll _set_fmode
__p__commode
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
api-ms-win-crt-heap-l1-1-0.dll free
_set_new_mode

Delayed Imports

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Sep-19 11:54:31
Version 0.0
SizeofData 36
AddressOfRawData 0x6c1e70
PointerToRawData 0x6c1070
Referenced File aircard.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Sep-19 11:54:31
Version 0.0
SizeofData 20
AddressOfRawData 0x6c1e94
PointerToRawData 0x6c1094

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Sep-19 11:54:31
Version 0.0
SizeofData 816
AddressOfRawData 0x6c1ea8
PointerToRawData 0x6c10a8

TLS Callbacks

StartAddressOfRawData 0x1406c21f8
EndAddressOfRawData 0x1406c2390
AddressOfIndex 0x140741db0
AddressOfCallbacks 0x140488ae8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140741b40

RICH Header

XOR Key 0xcbbe1efd
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 12
Imports (35721) 2
ASM objects (35721) 3
C objects (35721) 9
C++ objects (35721) 23
Imports (33145) 13
Total imports 310
Unmarked objects (#2) 44
Linker (36256) 1

Errors

Leave a comment

No comments yet.