eecbe23ee21ed0a1f513bcad8a31789f20cc61a88fd2a135a68869d0c232893c

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Mar-07 10:24:29
Detected languages English - United States

Plugin Output

Suspicious The PE is possibly packed. Unusual section name found: .fptable
Unusual section name found: .xn;
Unusual section name found: .x*<
Unusual section name found: ._Ib
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryA
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegCloseKey
  • RegOpenKeyExW
  • RegQueryValueExW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Has Internet access capabilities:
  • WinHttpReceiveResponse
  • WinHttpOpen
  • WinHttpReadData
  • WinHttpOpenRequest
  • WinHttpCloseHandle
  • WinHttpSendRequest
  • WinHttpQueryDataAvailable
  • WinHttpConnect
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Manipulates other processes:
  • Process32FirstW
  • Process32NextW
  • WriteProcessMemory
Malicious VirusTotal score: 45/71 (Scanned on 2026-06-10 21:33:41) ALYac: Trojan.GenericKD.80014895
APEX: Malicious
AVG: Win64:MalwareX-gen [Misc]
Alibaba: Packed:Win32/VMProtect.b0fb3f92
Arcabit: Trojan.Generic.D4C4EE2F
Avast: Win64:MalwareX-gen [Misc]
Avira: TR/W64.Agent
BitDefender: Trojan.GenericKD.80014895
Bkav: W32.Malware.919DE0F
CTX: exe.trojan.vmprotect
CrowdStrike: win/malicious_confidence_100% (W)
Cylance: Unsafe
Cynet: Malicious (score: 100)
DeepInstinct: MALICIOUS
ESET-NOD32: Win32/Packed.VMProtect.ACX trojan
Elastic: malicious (high confidence)
Emsisoft: Trojan.GenericKD.80014895 (B)
F-Secure: Trojan.TR/W64.Agent
Fortinet: W32/PossibleThreat
GData: Trojan.GenericKD.80014895
Google: Detected
Gridinsoft: Trojan.Heur!.02212023
Ikarus: Trojan.Win32.VMProtect
K7AntiVirus: Riskware ( 005cdde21 )
K7GW: Riskware ( 005cdde21 )
Lionic: Trojan.Win32.VMProtect.4!c
Malwarebytes: Malware.AI.1339289844
MaxSecure: Trojan.Malware.300983.susgen
McAfeeD: Real Protect-LS!F3E8F4300B5D
MicroWorld-eScan: Trojan.GenericKD.80014895
Microsoft: Trojan:Win32/Phonzy.A!ml
Paloalto: generic.ml
Sangfor: Trojan.Win32.Save.a
SentinelOne: Static AI - Malicious PE
Skyhigh: BehavesLike.Win64.Injector.tc
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
Trapmine: suspicious.low.ml.score
TrellixENS: Artemis!F3E8F4300B5D
TrendMicro: TROJ_FRS.VSNTDD26
TrendMicro-HouseCall: TROJ_FRS.VSNTDD26
VIPRE: Trojan.GenericKD.80014895
Varist: W64/ABTrojan.IIEG-4341
ViRobot: Trojan.Win.Z.Agent.9871360.E
alibabacloud: VirTool:Win/Wacatac.B9nj

Hashes

MD5 f3e8f4300b5dcd73139608c5f1ddf7c9
SHA1 7cb82e7a9b78de4e068757312858e708499e871b
SHA256 eecbe23ee21ed0a1f513bcad8a31789f20cc61a88fd2a135a68869d0c232893c
SHA3 c505a3a9b8924b8bb7c49421d7a27111607a515e8b54149a075a0376150df9e3
SSDeep 196608:WDUYJEMIKV+79gLd0Cd6ObhPvjxZ2a48v/MeL1Od7fnk:Qf9G9Md0Cdn93jH2a4s/Mu8
Imports Hash f8e374293f8ff0b6b04dd0824c2d979f

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 11
TimeDateStamp 2026-Mar-07 10:24:29
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x42a00
SizeOfInitializedData 0x1e400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000B361CB (Section: ._Ib)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xf8f000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x42810
VirtualAddress 0x1000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ

.rdata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x1639e
VirtualAddress 0x44000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ

.data

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x3554
VirtualAddress 0x5b000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.pdata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x375c
VirtualAddress 0x5f000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ

_RDATA

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x1f4
VirtualAddress 0x63000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ

.fptable

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x100
VirtualAddress 0x64000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.xn;

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x5bd94c
VirtualAddress 0x65000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ

.x*<

MD5 a007ef08c6e909d3b97d827efc56238f
SHA1 29c09fb3616e200aebe99cc54215ffc19ca2706a
SHA256 b4cd9f1068a21805054668550d1d687d201a002c1342e8651a82c638f5219873
SHA3 392e8199579f7f0d9527c1fa7f7288b0fad88748b46402b261022d8b00dad621
VirtualSize 0xbe0
VirtualAddress 0x623000
SizeOfRawData 0xc00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.60465

._Ib

MD5 e57719c38d12587da1abe5b688b067b9
SHA1 1008619625cab8ec4d5f3e454b795184b1480d01
SHA256 238115461603a252f9d8104650771bfbf2aa0536a6a318bd1becbaa5de020263
SHA3 b375478dee05d8c29d69404fd7f53c9ea91d0759e59f285857dfdb7fecc1b515
VirtualSize 0x968a44
VirtualAddress 0x624000
SizeOfRawData 0x968c00
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
Entropy 7.81806

.reloc

MD5 0460748c426ae907086cb0a3625d7434
SHA1 366269f223fd96a9d850475e902e4fc9ff70955f
SHA256 021a0b478f47e2adc832bb09423465f9b02ff9f7eee744cedf5d84c40ecacb2e
SHA3 9b97dc3e57e2d1a318471b1048216268fe68254c68b5512f7c98f03eb185cf84
VirtualSize 0x100
VirtualAddress 0xf8d000
SizeOfRawData 0x200
PointerToRawData 0x969c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.33278

.rsrc

MD5 a87728580a92a222e10b6654e24a94d7
SHA1 405020b51b07929b3ae9ae8e8d5f316f91cf4797
SHA256 3920dc6c03ae1962dd7b7ac300983327566db96f9f26c9d1bd9f3362e7c20bee
SHA3 5140132f41ed96b82d5deed8c2c4ee15ec012cc4b3908537d184ae1d5a1c5b8d
VirtualSize 0x1e0
VirtualAddress 0xf8e000
SizeOfRawData 0x200
PointerToRawData 0x969e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.77204

Imports

KERNEL32.dll CreateFileA
GetSystemDirectoryA
Process32FirstW
CloseHandle
Module32FirstW
GetProcAddress
LocalFree
ExitProcess
GetModuleHandleW
Module32NextW
CreateFileMappingW
MapViewOfFile
GetExitCodeProcess
VirtualQueryEx
GetCurrentProcessId
HeapSize
SetStdHandle
GetProcessHeap
SetEnvironmentVariableW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
GetCommandLineA
GetOEMCP
GetACP
IsValidCodePage
HeapReAlloc
CreateProcessW
WaitForSingleObject
ReadConsoleW
ReadFile
GetConsoleMode
Process32NextW
GetLastError
FormatMessageW
CreateToolhelp32Snapshot
Sleep
SetProcessMitigationPolicy
GetModuleHandleA
UnmapViewOfFile
GetCurrentProcess
VirtualProtect
WriteConsoleW
GetModuleFileNameA
GetConsoleOutputCP
FlushFileBuffers
SetFilePointerEx
GetFileSizeEx
GetFileType
EnumSystemLocalesW
GetUserDefaultLCID
IsValidLocale
GetLocaleInfoW
LCMapStringW
CompareStringW
FlsFree
FlsSetValue
FormatMessageA
MultiByteToWideChar
GetLocaleInfoEx
CreateFileW
FindClose
FindFirstFileW
FindFirstFileExW
FindNextFileW
GetFileAttributesExW
AreFileApisANSI
GetFileInformationByHandleEx
WideCharToMultiByte
GetStringTypeW
GetCurrentThreadId
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
EncodePointer
DecodePointer
LCMapStringEx
ReleaseSRWLockExclusive
WakeAllConditionVariable
QueryPerformanceCounter
GetSystemTimeAsFileTime
GetCPInfo
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
InitializeSListHead
RtlUnwindEx
RtlPcToFileHeader
RaiseException
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
CreateThread
ExitThread
FreeLibraryAndExitThread
GetModuleHandleExW
GetModuleFileNameW
GetStdHandle
WriteFile
HeapAlloc
HeapFree
FlsAlloc
FlsGetValue
RtlUnwind
USER32.dll PostQuitMessage
TranslateMessage
SetFocus
MessageBoxA
GetWindowTextW
DispatchMessageW
ShowWindow
SetWindowTextW
SendMessageW
CreateWindowExW
PostMessageW
EnableWindow
RegisterClassW
DefWindowProcW
GetWindowThreadProcessId
GetWindow
IsWindowVisible
EnumWindows
GetWindowTextLengthW
GetMessageW
GDI32.dll SetTextColor
SetBkMode
CreateSolidBrush
GetStockObject
ADVAPI32.dll AdjustTokenPrivileges
RegCloseKey
OpenProcessToken
RegOpenKeyExW
RegQueryValueExW
LookupPrivilegeValueW
SHELL32.dll ShellExecuteW
ntdll.dll RtlLookupFunctionEntry
RtlCaptureContext
RtlVirtualUnwind
WINHTTP.dll WinHttpReceiveResponse
WinHttpOpen
WinHttpReadData
WinHttpOpenRequest
WinHttpCloseHandle
WinHttpSendRequest
WinHttpQueryDataAvailable
WinHttpConnect
KERNEL32.dll (#2) CreateFileA
GetSystemDirectoryA
Process32FirstW
CloseHandle
Module32FirstW
GetProcAddress
LocalFree
ExitProcess
GetModuleHandleW
Module32NextW
CreateFileMappingW
MapViewOfFile
GetExitCodeProcess
VirtualQueryEx
GetCurrentProcessId
HeapSize
SetStdHandle
GetProcessHeap
SetEnvironmentVariableW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
GetCommandLineA
GetOEMCP
GetACP
IsValidCodePage
HeapReAlloc
CreateProcessW
WaitForSingleObject
ReadConsoleW
ReadFile
GetConsoleMode
Process32NextW
GetLastError
FormatMessageW
CreateToolhelp32Snapshot
Sleep
SetProcessMitigationPolicy
GetModuleHandleA
UnmapViewOfFile
GetCurrentProcess
VirtualProtect
WriteConsoleW
GetModuleFileNameA
GetConsoleOutputCP
FlushFileBuffers
SetFilePointerEx
GetFileSizeEx
GetFileType
EnumSystemLocalesW
GetUserDefaultLCID
IsValidLocale
GetLocaleInfoW
LCMapStringW
CompareStringW
FlsFree
FlsSetValue
FormatMessageA
MultiByteToWideChar
GetLocaleInfoEx
CreateFileW
FindClose
FindFirstFileW
FindFirstFileExW
FindNextFileW
GetFileAttributesExW
AreFileApisANSI
GetFileInformationByHandleEx
WideCharToMultiByte
GetStringTypeW
GetCurrentThreadId
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
EncodePointer
DecodePointer
LCMapStringEx
ReleaseSRWLockExclusive
WakeAllConditionVariable
QueryPerformanceCounter
GetSystemTimeAsFileTime
GetCPInfo
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
InitializeSListHead
RtlUnwindEx
RtlPcToFileHeader
RaiseException
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
CreateThread
ExitThread
FreeLibraryAndExitThread
GetModuleHandleExW
GetModuleFileNameW
GetStdHandle
WriteFile
HeapAlloc
HeapFree
FlsAlloc
FlsGetValue
RtlUnwind

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd

Version Info

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14005b040

RICH Header

Errors

[*] Warning: Section .text has a size of 0! [*] Warning: Section .rdata has a size of 0! [*] Warning: Section .data has a size of 0! [*] Warning: Section .pdata has a size of 0! [*] Warning: Section _RDATA has a size of 0! [*] Warning: Section .fptable has a size of 0! [*] Warning: Section .xn; has a size of 0!
Leave a comment

No comments yet.