| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
| Compilation Date | 2026-Apr-24 15:13:31 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA1
Uses constants related to SHA256 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: PAGE
Unusual section name found: .cod0 |
| Suspicious | The PE contains functions most legitimate programs don't use. |
Functions which can be used for anti-debugging purposes:
|
| Info | The PE is digitally signed. |
Signer: Microsoft Windows Hardware Compatibility Publisher
Issuer: Microsoft Windows Third Party Component CA 2014 |
| Suspicious | VirusTotal score: 2/64 (Scanned on 2026-09-15 18:18:16) |
APEX:
Malicious
McAfeeD: ti!ED38C3387157 |
| MD5 | 9fedb8e2d3edf2e67dfea9815cb7f8c6 🔍 |
|---|---|
| SHA1 | 40dc6681cfd5dfe64dfadac1bada797002e2d455 🔍 |
| SHA256 | ed38c3387157776faa5848e63bde2b6af60858b73381216791bf0ebd5f5fa998 🔍 |
| SHA3 | 9ec44459a4371e5fa04dff9d218d3643d163267bd54b6c6f139d3ddb05cf7577 🔍 |
| SSDeep | 196608:fzTEGgSXdLSxAPV7Kj3fE4htNvUbyl6aTpPYKijSUHGVVu0VpDUiZPKp:fzTEGgcdL8APVmM4tBvPriBHOoaPKp 🔍 |
| Imports Hash | c79eb0f05cfa627d03b7bb11dc9e1315 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 8 |
| TimeDateStamp | 2026-Apr-24 15:13:31 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x35a00 |
| SizeOfInitializedData | 0x11cb400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000001201000 (Section: INIT) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | A.0 |
| ImageVersion | A.0 |
| SubsystemVersion | 6.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1c12000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xa75ee9 |
| Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_FORCE_INTEGRITY
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | f931b4f11eeb18ae1fde660b22d72d96 🔍 |
|---|---|
| SHA1 | 311f55e5ada50a61e04a314334924d4573f4ba76 🔍 |
| SHA256 | b4afa825bf02a6ec8e033b88ab6e306f5622b384c214d5d57bb8f5d5b9199013 🔍 |
| SHA3 | 8e3db783a80917f290332622ff3db361cfc5c60409a619604683c01e144345cd 🔍 |
| VirtualSize | 0x32895 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x32a00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
|
| Entropy | 7.33891 |
| MD5 | 6ebce7234191bcfd7f7c13c8f0a774eb 🔍 |
|---|---|
| SHA1 | d79fe2eb47755d1619115965cead88da1f771ec8 🔍 |
| SHA256 | b22e15c69b44d1e8e550f37909d7dfccf0d43f5398044b0f7cab1d24d1e1d7c5 🔍 |
| SHA3 | 2a07cfcbcc23d79ed34c216c39d2da4ca1a5264aa91e78f85d50122c14dbb260 🔍 |
| VirtualSize | 0x9594 |
| VirtualAddress | 0x34000 |
| SizeOfRawData | 0x9600 |
| PointerToRawData | 0x32e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
|
| Entropy | 5.21442 |
| MD5 | c64577e4f41113c60b59e69723e1afaf 🔍 |
|---|---|
| SHA1 | 4231365af2b6d09f229fc36f80933878aaa9527a 🔍 |
| SHA256 | 86dd2cbc10ed2c46625dc0f21a11cca73de1db547cce65e321ffe2c9e28b734b 🔍 |
| SHA3 | 866806640fe6cd8dc3df67d305bffd85390ca901d2fd08237f38d5d1bcd75819 🔍 |
| VirtualSize | 0x11bdfbc |
| VirtualAddress | 0x3e000 |
| SizeOfRawData | 0x14400 |
| PointerToRawData | 0x3c400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 2.61012 |
| MD5 | 656441ea9098473a49fc6f86c09a0251 🔍 |
|---|---|
| SHA1 | dc802d95900683199569870ae6a37e4733efadb8 🔍 |
| SHA256 | 81559b8a7eda895cd588b6f2afc4cea2e9acb7d821972e3a9ffd6e5e763f98c1 🔍 |
| SHA3 | 80e68a0340109219a3c79726ac9abf9b31b8c637e1b1ce9f676aa09dd6a6e804 🔍 |
| VirtualSize | 0x2280 |
| VirtualAddress | 0x11fc000 |
| SizeOfRawData | 0x2400 |
| PointerToRawData | 0x50800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
|
| Entropy | 7.77914 |
| MD5 | 18a06b708c93947290da45080d0d8e71 🔍 |
|---|---|
| SHA1 | 5de4962403e4c93a0aedc6538ebdca687b717228 🔍 |
| SHA256 | a192bf451ee13b2030831a57e7793ce6438ab2cf0868ca5b8fc490a1ce533bd3 🔍 |
| SHA3 | 5f3bb8df2b2d9ae1a8328a4212b206d28c7d6b84314a483d8698ac687303a4b6 🔍 |
| VirtualSize | 0x1f67 |
| VirtualAddress | 0x11ff000 |
| SizeOfRawData | 0x2000 |
| PointerToRawData | 0x52c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.25982 |
| MD5 | 52ea08995119d94b6535cfbd517b2a93 🔍 |
|---|---|
| SHA1 | 0d9d81cb13a0c6fddad038d1d867906c8da1efec 🔍 |
| SHA256 | e02213ed839ab4834b84f5572c0c3a0e65693f1befdc83e944f5786d8639ed5c 🔍 |
| SHA3 | 0f13ea89ccd63db8a2de3e4ac4d67e45ab826feb4c95d6854530709a26c180e5 🔍 |
| VirtualSize | 0xfdc |
| VirtualAddress | 0x1201000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0x54c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.45807 |
| MD5 | 001f7b5d36ec55b84c614b532531626c 🔍 |
|---|---|
| SHA1 | f04f9cbbff7ad52b2aa61c2f595bfb329df0911b 🔍 |
| SHA256 | f5063b5da7cb869a9bff03b7a0aaa0f1017a7d9d351ddfda30930fda5c725893 🔍 |
| SHA3 | 35406e4aed90c2a5d03ccf09969e216110d5de8c070d1c7c35d6c4d216406d1d 🔍 |
| VirtualSize | 0xa0db48 |
| VirtualAddress | 0x1202000 |
| SizeOfRawData | 0xa0dc00 |
| PointerToRawData | 0x55c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
|
| Entropy | 7.61827 |
| MD5 | b59fdce7869d401fb1094c88573c850a 🔍 |
|---|---|
| SHA1 | 3f242893dc5855986eb10b6b8a97238d64fbacf6 🔍 |
| SHA256 | cff3390f0239636d82a9887845eb8ab992903c8a65bc86fd6044c787d4e7174d 🔍 |
| SHA3 | 22ad1eb1761f9f68fd92e528db79d78ca445e50ff7fae53e1bdf5ba0f18fa767 🔍 |
| VirtualSize | 0x1990 |
| VirtualAddress | 0x1c10000 |
| SizeOfRawData | 0x1a00 |
| PointerToRawData | 0xa63800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.49286 |
| ntoskrnl.exe |
ExAllocatePoolWithTag
ExFreePoolWithTag ZwCreateFile ZwQueryInformationFile ZwReadFile ZwClose RtlInitUnicodeString KeGetCurrentIrql KeDelayExecutionThread KeWaitForSingleObject PsCreateSystemThread ObReferenceObjectByHandle ObfReferenceObject ObReferenceObjectByPointer ObfDereferenceObject MmIsAddressValid PsGetCurrentProcessId IoGetRequestorSessionId __chkstk PsThreadType IoDriverObjectType ExAcquireFastMutex ExReleaseFastMutex IoGetCurrentProcess KeStackAttachProcess KeUnstackDetachProcess RtlEqualUnicodeString PsLookupProcessByProcessId MmGetSystemRoutineAddress PsLookupThreadByThreadId ZwAllocateVirtualMemory ZwFreeVirtualMemory RtlRandomEx __C_specific_handler wcsnlen KeInitializeEvent IoBuildDeviceIoControlRequest IofCallDriver ZwOpenFile ZwQueryDirectoryFile ZwFsControlFile RtlInitAnsiString RtlAnsiStringToUnicodeString RtlFreeUnicodeString ZwOpenProcess ObQueryNameString strcmp IoFileObjectType ZwDeviceIoControlFile ZwCreateEvent ZwWaitForSingleObject _stricmp ExGetPreviousMode IoThreadToProcess PsProcessType IofCompleteRequest ProbeForRead ProbeForWrite MmMapIoSpace MmUnmapIoSpace MmGetPhysicalAddress sprintf ExAllocatePool ExFreePool strlen KeSetEvent PsGetProcessId ObOpenObjectByPointer RtlIsNtDdiVersionAvailable KeClearEvent KeResetEvent KeQueryTimeIncrement PsTerminateSystemThread IoCreateNotificationEvent IoCreateSymbolicLink IoDeleteDevice IoDeleteSymbolicLink ZwOpenKey ZwQueryValueKey ZwSetValueKey ExUuidCreate PsSetCreateProcessNotifyRoutine PsSetCreateThreadNotifyRoutine PsRemoveCreateThreadNotifyRoutine PsSetLoadImageNotifyRoutine PsRemoveLoadImageNotifyRoutine IoGetRequestorProcessId IoGetRequestorProcess MmHighestUserAddress MmSystemRangeStart NtBuildNumber toupper towupper _wcsnicmp RtlAppendUnicodeStringToString RtlAppendUnicodeToString ZwSetInformationThread ZwOpenDirectoryObject PsGetProcessSectionBaseAddress ZwQueryInformationProcess ZwQueryInformationThread ZwQueryDirectoryObject _vsnwprintf wcslen _vsnprintf RtlImageDirectoryEntryToData ZwSetSecurityObject IoDeviceObjectType IoCreateDevice RtlGetDaclSecurityDescriptor RtlGetGroupSecurityDescriptor RtlGetOwnerSecurityDescriptor RtlGetSaclSecurityDescriptor SeCaptureSecurityDescriptor _snwprintf RtlLengthSecurityDescriptor SeExports RtlCreateSecurityDescriptor wcschr RtlAbsoluteToSelfRelativeSD RtlAddAccessAllowedAce RtlLengthSid IoIsWdmVersionAvailable RtlSetDaclSecurityDescriptor ZwCreateKey PsGetVersion ExAllocatePoolWithQuotaTag ZwQuerySystemInformation KeBugCheckEx |
|---|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140052380 |
No comments yet.