fb9614d6bd09f4f7b56b5e3148a8a209b198de24b1dcedf30950990814665803

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2013-Jun-28 14:45:44
Detected languages English - United States

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • virus
Info Cryptographic algorithms detected in the binary: Uses known Mersenne Twister constants
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Possibly launches other programs:
  • CreateProcessA
Can create temporary files:
  • GetTempPathA
  • CreateFileA
Malicious The PE is possibly a dropper. Resource ARCHIVE is possibly compressed or encrypted.
Resource DECOMPRESSOR detected as a PE Executable.
Resources amount for 99.0882% of the executable.
Malicious VirusTotal score: 42/69 (Scanned on 2026-08-16 20:39:34) ALYac: Application.Generic.4038761
Antiy-AVL: HackTool/Win32.CheatEngine
Arcabit: Application.Generic.D3DA069
BitDefender: Application.Generic.4038761
Bkav: W32.Malware.C90539D6
CTX: exe.hacktool.cheatengine
CrowdStrike: win/grayware_confidence_100% (W)
Cylance: Unsafe
Cynet: Malicious (score: 100)
DeepInstinct: MALICIOUS
ESET-NOD32: Win32/HackTool.CheatEngine.AF potentially unsafe application
Elastic: malicious (high confidence)
Fortinet: Riskware/CheatEngine
GData: Win32.Riskware.Hacktool.D
K7AntiVirus: Unwanted-Program ( 004b8a131 )
K7GW: Unwanted-Program ( 004ba1a41 )
Kaspersky: VHO:Backdoor.Win32.Zegost.gen
Kingsoft: Win32.Riskware.Keygen.f
Lionic: Trojan.Win64.Cobalt.tpMn
Malwarebytes: GameHack.HackTool.RiskWare.DDS
MaxSecure: Trojan.Malware.325280622.susgen
McAfeeD: Real Protect-LS!7461AB61E8CC
MicroWorld-eScan: Application.Generic.4038761
Microsoft: HackTool:Win32/Keygen!MSR
Paloalto: generic.ml
Panda: Hacktool/CheatEngine
Rising: Backdoor.Zegost!8.177 (CLOUD)
Sangfor: Worm.Win32.Save.a
SentinelOne: Static AI - Suspicious PE
Skyhigh: BehavesLike.Win32.PUP.tc
Sophos: Generic Reputation PUA (PUA)
Symantec: ML.Attribute.HighConfidence
Trapmine: malicious.high.ml.score
TrellixENS: GenericRXWU-YA!7461AB61E8CC
TrendMicro: Backdoor.Win32.KEYGEN.USBLH526
TrendMicro-HouseCall: Backdoor.Win32.KEYGEN.USBLH526
VBA32: Backdoor.Zegost
VIPRE: Application.Generic.4038761
Varist: W32/ABApplication.GVQT-6686
Zillya: Tool.CheatEngine.Win32.8931
alibabacloud: Backdoor:Win/CheatEngine.A#
tehtris: Generic.Malware

Hashes

MD5 7461ab61e8cc46c194804b201b5e964b 🔍
SHA1 ef1058d5e8accfe51c21b76970b97a6092fa7bc4 🔍
SHA256 fb9614d6bd09f4f7b56b5e3148a8a209b198de24b1dcedf30950990814665803 🔍
SHA3 1fe2d03d1c121b0ad3458d18fca644ae398d18878afc0f2f5146ccf836506c98 🔍
SSDeep 98304:p+1UM7rUoFSl24Zw8u5srVK/j4uRzrT6p2vuojYCkUu4u6cW8+52ViqXdpfQwTG:c17AoKpL2jLx6p2vuojYLUE6cW8pdpf 🔍
Imports Hash 8d92fa1956a6a631c642190121740197 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2013-Jun-28 14:45:44
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 9.0
SizeOfCode 0x8e00
SizeOfInitializedData 0x5aee00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000015EB (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xa000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x5bc000
SizeOfHeaders 0x400
Checksum 0x11163
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 40b6c3ad804db9bc09242ade61fb6ea3 🔍
SHA1 19c269f7859f50a7ec90df4637ebd448d9256893 🔍
SHA256 bfc577c4b1e79be13461642e8f12bae2d8a8b172ec4ddc285e46c6eee2e8d14b 🔍
SHA3 b4d3ea20bb6bba895183f6ae88b849f90e8913fff3e30c0292295c72565f1e00 🔍
VirtualSize 0x8d54
VirtualAddress 0x1000
SizeOfRawData 0x8e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.56215

.rdata

MD5 33d023d2d6213e1f615883e5e3160e76 🔍
SHA1 42495099f48591f1a8efbba21c576c97f0f82aff 🔍
SHA256 36c989b74abd069ce8b310806e897d309f7040e4c58dd32d8af1b73d9ba87b2c 🔍
SHA3 38b506b37ac219d3dca849823a8de2ccd3bbaa02d179778dd6ea54937cdb8b3d 🔍
VirtualSize 0x2114
VirtualAddress 0xa000
SizeOfRawData 0x2200
PointerToRawData 0x9200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.44357

.data

MD5 3254d8738887635ac7c58c51f4e91adf 🔍
SHA1 358ba73f2f73183dc0bb1e36bcd5531cb4afb52a 🔍
SHA256 b7c82c609946c4510f84c3fc78fdb5005cb52d289aebb5cccf25d72ec0c243d9 🔍
SHA3 8a9f4a20d88b19dbc56d5a8d10c90d519831cd4e636c1c777f1d5581d44abb40 🔍
VirtualSize 0x2adc
VirtualAddress 0xd000
SizeOfRawData 0x1000
PointerToRawData 0xb400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.1026

.rsrc

MD5 f80a8cb10810df040571f939c9979358 🔍
SHA1 9f3120652eb7b60989346980c7aa1f3ac06d4988 🔍
SHA256 8a07d1d3cc2197232ab8cfd90c21472af5b91f68af5cd2ade01042fc9228e9aa 🔍
SHA3 b5fad3f0c43c130c7f134ed68131d81d0bbe7ab291c7c909c757d8e47c63f3c7 🔍
VirtualSize 0x5aac00
VirtualAddress 0x10000
SizeOfRawData 0x5aac00
PointerToRawData 0xc400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.98652

.reloc

MD5 65aac020a14aa9271485b36b38ac2718 🔍
SHA1 5623197bb662e9e89cfc1745ab5e5ee18b7cf2df 🔍
SHA256 1d3b7708419789a013f22609c85194943b07e823ee6a865a3f9f9ce43fe30597 🔍
SHA3 66c06a8e28937246e4054bbd03026b02fb5e70aa366a87d29dec4855bd7a27b7 🔍
VirtualSize 0xeea
VirtualAddress 0x5bb000
SizeOfRawData 0x1000
PointerToRawData 0x5b7000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.32883

Imports

SHLWAPI.dll PathAddBackslashA
PathStripPathA
PathRemoveFileSpecA
KERNEL32.dll GetModuleFileNameA
FindResourceA
GetModuleHandleA
SizeofResource
LoadResource
GetTempPathA
CreateDirectoryA
DeleteFileA
CreateFileA
WriteFile
CloseHandle
CreateProcessA
WaitForSingleObject
RemoveDirectoryA
FlushFileBuffers
GetTempFileNameA
GetCurrentThreadId
GetCommandLineA
GetStartupInfoA
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetModuleHandleW
Sleep
GetProcAddress
ExitProcess
GetStdHandle
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetLastError
GetEnvironmentStringsW
SetHandleCount
GetFileType
DeleteCriticalSection
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
InterlockedDecrement
HeapCreate
VirtualFree
HeapFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
SetFilePointer
GetConsoleCP
GetConsoleMode
EnterCriticalSection
LeaveCriticalSection
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
LoadLibraryA
InitializeCriticalSectionAndSpinCount
HeapAlloc
VirtualAlloc
HeapReAlloc
RtlUnwind
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
HeapSize
USER32.dll MessageBoxA
ADVAPI32.dll ConvertStringSecurityDescriptorToSecurityDescriptorA

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x9284
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92038
Detected Filetype PNG graphic file
MD5 c2c1c27a8e8216c157ebe45239bfcf5b 🔍
SHA1 ea5923ded9ea3b7b195448fdfb1536d65b6f9716 🔍
SHA256 69513359d923554804275800b824c19116f2eba084103bd0fe5b4e282862f49d 🔍
SHA3 5289d8f3c71dbaae7fabbea4c834c02f3a48a62a6e2d3ea4a3eb7ae241244641 🔍

ARCHIVE

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x57106e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9928
MD5 92f4623675d290c737f491f3d1a38c08 🔍
SHA1 0aa34fc88f346303f370c2fa1c05f91b068a49a9 🔍
SHA256 f519c842312629d760fd22a8d876035d1857acef65bd85b7d910f593d4330866 🔍
SHA3 faf99b36af185f0a93cad7e87caf42d8be1429c75b63003eee9ebf76a9d446c4 🔍

DECOMPRESSOR

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2f600
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.11488
Detected Filetype PE Executable
MD5 a65c29111a4cf5a7fdd5a9d79f77bcab 🔍
SHA1 c0c59b1f792c975558c33a3b7cf0d94adc636660 🔍
SHA256 dab3003436b6861ae220cc5fdcb97970fc05afdf114c2f91e46eed627ce3d6af 🔍
SHA3 e4e1436cfab72b94daf67a44913cfa7f114e226acae1792f1f262cf82e87e372 🔍

101

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x1016
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.85691
Detected Filetype Icon file
MD5 e30996177611186c11dde80517e8f493 🔍
SHA1 5a632a7cf796fea81822a41c67caec1320ab2a94 🔍
SHA256 bd877b189c60f87740d5046114d27943ca80d368ae090d4e76a0e769338c4d53 🔍
SHA3 e39ea2932fc5fece4450f78592fb8295e6caa30a37e8134755ee9903bc001f40 🔍

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x165
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.77792
MD5 b9b507d6297b2d514477db4ae0d55ea6 🔍
SHA1 e8c4b4e815c1788b3bab96fc44560d7282282fe1 🔍
SHA256 ec5d04c8ef3fe0e571c8e604bf146b393108cee11f1ad3d665b7501ec20d37d0 🔍
SHA3 85e8c59b71094f3ffe0990fe28a56df78d58756dc3a423284dff50f92ed7fa6f 🔍

Version Info

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x40db60
SEHandlerTable 0x40b550
SEHandlerCount 3

RICH Header

XOR Key 0xd73b8ed3
Unmarked objects 0
C++ objects (VS2008 build 21022) 31
ASM objects (VS2008 build 21022) 16
C objects (VS2008 build 21022) 96
Imports (VS2012 build 50727 / VS2005 build 50727) 9
Total imports 99
138 (VS2008 build 21022) 2
Linker (VS2008 build 21022) 1
Resource objects (VS2008 build 21022) 1

Errors

Leave a comment
📊 New Message from Coinbase. OPEN → graph.org/YOU-HAVE-A-NEW-BIT 9 hours ago
📊 New Message from Coinbase. OPEN → graph.org/YOU-HAVE-A-NEW-BITCOIN-TRANSFER-FROM-COINBASE-08-27?hs=e958fa39f2248dab1ef9fc9ac73cf9b7& #SL6053 📊