00097be682ae4adfa3e15b0ddd148dc5d9a2dbf03224a9a5d7d25d09a4d9b024

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Oct-11 00:59:34
CompanyName Emanuel Bernardes Rodrigues Santana
FileDescription Instalador do Escala Novel
FileVersion 3.9.0.0
InternalName EscaletaSetup.exe
LegalCopyright Copyright (c) 2026 Emanuel Bernardes Rodrigues Santana. Todos os direitos reservados.
OriginalFilename EscaletaSetup.exe
ProductName Escala Novel
ProductVersion 3.9.0.0
Assembly Version 3.9.0.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C# v7.0 / Basic .NET
.NET DLL -> Microsoft
.NET executable -> Microsoft
Suspicious Strings found in the binary may indicate undesirable behavior: Looks for Qemu presence:
  • QeMU
Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • .cv-t.top
  • .pn-chip.ch
  • .r-num.br
  • .reader.top
  • api.languagetool.org
  • api.languagetoolplus.com
  • b.style.top
  • bar.style.top
  • box.style.top
  • crl.microsoft.com
  • d.el.style.top
  • dataset.ch
  • dataset.it
  • docs.google.com
  • docs.microsoft.com
  • el.dataset.ch
  • el.dataset.it
  • el.style.top
  • github.com
  • go.microsoft.com
  • google.com
  • h.dataset.ch
  • h.style.top
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0
  • http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
  • http://purl.org
  • http://schemas.microsoft.com
  • http://schemas.microsoft.com/SMI/2005/WindowsSettings
  • http://schemas.openxmlformats.org
  • http://schemas.openxmlformats.org/drawingml/2006/main
  • http://schemas.openxmlformats.org/drawingml/2006/picture
  • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
  • http://schemas.openxmlformats.org/officeDocument/2006/relationships
  • http://schemas.openxmlformats.org/officeDocument/2006/relationships/comments
  • http://schemas.openxmlformats.org/officeDocument/2006/relationships/image
  • http://schemas.openxmlformats.org/officeDocument/2006/relationships/officeDocument
  • http://schemas.openxmlformats.org/officeDocument/2006/relationships/styles
  • http://schemas.openxmlformats.org/package/2006/content-types
  • http://schemas.openxmlformats.org/package/2006/metadata/core-properties
  • http://schemas.openxmlformats.org/package/2006/relationships
  • http://schemas.openxmlformats.org/package/2006/relationships/metadata/core-properties
  • http://schemas.openxmlformats.org/wordprocessingml/2006/main
  • http://www.idpf.org
  • http://www.idpf.org/2007/opf
  • http://www.idpf.org/2007/ops
  • http://www.microsoft.com
  • http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0
  • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
  • http://www.microsoft.com/pkiops/Docs/Repository.htm0
  • http://www.microsoft.com/pkiops/certs/Microsoft%20Code%20Signing%20PCA%202024.crt0
  • http://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010
  • http://www.microsoft.com/pkiops/crl/Microsoft%20Code%20Signing%20PCA%202024.crl0m
  • http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010
  • http://www.w3.org
  • http://www.w3.org/1999/xhtml
  • http://www.w3.org/2000/svg'
  • https://aka.ms
  • https://api.languagetool.org
  • https://api.languagetool.org/v2/check
  • https://api.languagetoolplus.com
  • https://api.languagetoolplus.com/v2/check
  • https://docs.google.com
  • https://docs.google.com/document/
  • https://docs.google.com/document/d/
  • https://docs.microsoft.com
  • https://docs.microsoft.com/en-us/dotnet/api/microsoft.web.webview2.core.corewebview2.processfailed
  • https://escaleta.example
  • https://github.com
  • https://go.microsoft.com
  • https://go.microsoft.com/fwlink/p/?LinkId
  • https://learn.microsoft.com
  • https://learn.microsoft.com/microsoft-edge/webview2/concepts/versioning
  • https://openfontlicense.org
  • https://script.google.com
  • https://script.google.com/macros/s/AKfycbzTmr8THzzxeZBrx7Ha49VPhw6RZ9K2O4bY6895gzRGEESm8ClKxBnAeC9TLK1j8zU9/exec
  • https://www.microsoft.com
  • languagetool.org
  • languagetoolplus.com
  • learn.microsoft.com
  • line.style.top
  • links.ch
  • microsoft.com
  • n.links.ch
  • openfontlicense.org
  • openxmlformats.org
  • pn-chip.ch
  • pop.style.top
  • r-num.br
  • reader.top
  • rule.style.top
  • schemas.microsoft.com
  • schemas.openxmlformats.org
  • script.google.com
  • style.top
  • t.ctx.ch
  • t.dataset.ch
  • www.idpf.org
  • www.microsoft.com
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA256
Malicious VirusTotal score: 5/71 (Scanned on 2026-10-11 02:14:03) APEX: Malicious
Cylance: Unsafe
Elastic: malicious (moderate confidence)
Kingsoft: malware.kb.c.691
Trapmine: malicious.moderate.ml.score

Hashes

MD5 39ead98b281085126026e0fcca99cf6b 🔍
SHA1 ed1eb9c1f1e89c76d39a159bd38be3091d6a7152 🔍
SHA256 00097be682ae4adfa3e15b0ddd148dc5d9a2dbf03224a9a5d7d25d09a4d9b024 🔍
SHA3 b5377fbf8f91f3845fc4af08047583d22d89134ca6eebaf0170c0cb40477748f 🔍
SSDeep 49152:iCJON3hAW/2H0f3f5YK1P/CU28ipZ20EHKpqSSWRQW:NJOeb 🔍
Imports Hash f34d5f2d4577ed6d9ceec516c1f5a744 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 3
TimeDateStamp 2026-Oct-11 00:59:34
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 11.0
SizeOfCode 0x4cb600
SizeOfInitializedData 0x11600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x004CD5BE (Section: .text)
BaseOfCode 0x2000
BaseOfData 0x4ce000
ImageBase 0x400000
SectionAlignment 0x2000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x4e2000
SizeOfHeaders 0x200
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 8fa2fc84110f3eb480a7020775697be9 🔍
SHA1 84a6d48f8af5f4341ce1bb35f2ae46c859a77a58 🔍
SHA256 662ebb1c29132c636ce889587030ef29049f3737d14c949c6cd0ed6f109654c8 🔍
SHA3 6359a9cbfdb548d0a838943bc03e71d6a73079be4a6b9d7d995b11a8416dd4b6 🔍
VirtualSize 0x4cb5c4
VirtualAddress 0x2000
SizeOfRawData 0x4cb600
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.54872

.rsrc

MD5 32840d6d8bf71c6a98d00edda19d3472 🔍
SHA1 e8209b72a19966db4dc758ac3cc27c87d9509b9d 🔍
SHA256 9b3b28159b1a1f0df7f687bc624aa7b064c4f31215949335526c1f59800e7b33 🔍
SHA3 b0f00562895157f299e5c84c4524a7c68ab9399e1058acb6948308a9690c2e40 🔍
VirtualSize 0x11398
VirtualAddress 0x4ce000
SizeOfRawData 0x11400
PointerToRawData 0x4cb800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.93912

.reloc

MD5 95b54748538a08323722a63fb6b3dffe 🔍
SHA1 3e679443fd8689fa275273987b9ce02cc4d36428 🔍
SHA256 f16a24ec1ee699cc28e68df650ab0584e3961741ebc5d838915519cea95fab27 🔍
SHA3 cc85638856df295d0d3f1f447c56784b164158a27cf89e631c0acb0ab6561b6d 🔍
VirtualSize 0xc
VirtualAddress 0x4e0000
SizeOfRawData 0x200
PointerToRawData 0x4dcc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.10191

Imports

mscoree.dll _CorExeMain

Delayed Imports

2

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x3fb
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.7548
Detected Filetype PNG graphic file
MD5 ccb808c995aa3dc79d34334af61d9524 🔍
SHA1 4a94abfa164e04021fa881d67442a85f8db633a2 🔍
SHA256 85f93d463989d4a1daf9a4b148a99317ef8de9e89e41e5789db46e1787f29f40 🔍
SHA3 d61be9ce37ea0e1abe84c0ddabc90df7153e2ac04cbcf0a4092fa50d8a0aa5ec 🔍

3

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x72b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87122
Detected Filetype PNG graphic file
MD5 d1b3ee43bcb3577987bf8870db99ac75 🔍
SHA1 7e81ba20467f3ca570f13af6444ce95cc91c2f2f 🔍
SHA256 f047c55bfe882b6551de26e7822d562866ceb36b34c2f5e899ee0673dfbcbfab 🔍
SHA3 e063ba9d768a2b3ba48ca08c6d0e8e6eef51c778281ae963912d4473f43a71fd 🔍

4

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0xad4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91262
Detected Filetype PNG graphic file
MD5 6d6976571036dde381957abf93c8af1e 🔍
SHA1 8a98fce84c4ad150fdb3df814c6429cd4e9c646e 🔍
SHA256 1377898c5121dc16af290fd4048dba9e37496c43b6c6ba46d72f492f5ed540b5 🔍
SHA3 d56daf7917d5bcf5558ac94853e8c027feff7c6e2bc186a7f5f61a716d7d5c76 🔍

5

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x1226
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9457
Detected Filetype PNG graphic file
MD5 1f149766d76b67bc9d7f0f5819a3f114 🔍
SHA1 2a845bb4c1996545ac30654df5ea17f49cd9f628 🔍
SHA256 6c0d9aabf00a77f2cb40c068f00c645d9f6a11c5fe622c3be700b3eceffeaa39 🔍
SHA3 026bafafb0c9760ebf356c75030e015d90a99a3b3a6012f42e2f6339a56cdcd3 🔍

6

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x1996
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.95569
Detected Filetype PNG graphic file
MD5 f56be46ff9d8074d9b2547141b4b8c04 🔍
SHA1 f398056c08caa4d485a65e2c2522450a67b175a3 🔍
SHA256 18d32da0f83c0570baa8499c86405db539d7d2fe5edbc7f255e309f0d0eba03a 🔍
SHA3 2f1a99d494cb5928691926bb475338ba0743aa3862bbd02db62ee852d66c2d1c 🔍

7

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x3b6e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97305
Detected Filetype PNG graphic file
MD5 9a5bd97cad4d2636dbb60b259e25e63f 🔍
SHA1 f6902773ae7f8e4bf9e39bbb4736bc7405629265 🔍
SHA256 1225350acca0cb0bbd4c4afb1008e7465370d8429b33f695c4be3f0646572e1d 🔍
SHA3 eaf05944cf2d5bf1223fc35a90caf68b0cea86da6128a7bd6c5d4945118a4bee 🔍

8

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x8c6c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.95754
Detected Filetype PNG graphic file
MD5 0adf31d3fd9dd34d6b1f21c74876b968 🔍
SHA1 c986ab358bbe4d3328375340c06244832638aa1b 🔍
SHA256 1795ce9ca90091da18e39e4b9970c716a72f8b6524bcc85bb8dfa38e1bd0c2bd 🔍
SHA3 dc3b16a6393bb56576edb36c25dafceaef5a935e318ba7e41344be18de580ed2 🔍

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.9768
Detected Filetype Icon file
MD5 8f58fa14e3a65080cf249280950b5709 🔍
SHA1 8d577dc902475deb5e8d9789a635820897efd7c3 🔍
SHA256 22ff7b8622124541bd2409db097271066b1c9018b433234a2672e41b44fc62f5 🔍
SHA3 3fcde8fd17209a3227049249eaf2c8f2995962270efe28cdedb01cce552a58af 🔍

1

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x3dc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3729
MD5 fdf671ab5ef385e61a56ce30818dbdbb 🔍
SHA1 9670292a824fb55bd125c9afed8f86926b07bd5d 🔍
SHA256 1b9e7e34d73c00d65f1ab73b244a99a749886e86787fdb0ee0c21cc4ca3d1adf 🔍
SHA3 f6ee4a67fefc30e03c0825b9bc71310623f5b5f48e03d0f8ab70c1ec526960c3 🔍

1 (#2)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x355
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.04679
MD5 74ba053ea856acf4d5e9fb8d67ce8e05 🔍
SHA1 08fc5f2ec02b70fa48cfae12e595560182e99666 🔍
SHA256 ee6263c9ebe20c7db3f248dbc2a4d964995df77f84715961a6268c0772075aa4 🔍
SHA3 b897c962310c2977f4c87961fd56ac672356b7c95d18e1a332ae354236ef2d92 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 3.9.0.0
ProductVersion 3.9.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName Emanuel Bernardes Rodrigues Santana
FileDescription Instalador do Escala Novel
FileVersion (#2) 3.9.0.0
InternalName EscaletaSetup.exe
LegalCopyright Copyright (c) 2026 Emanuel Bernardes Rodrigues Santana. Todos os direitos reservados.
OriginalFilename EscaletaSetup.exe
ProductName Escala Novel
ProductVersion (#2) 3.9.0.0
Assembly Version 3.9.0.0
Resource LangID UNKNOWN

TLS Callbacks

Load Configuration

RICH Header

Errors

Leave a comment

No comments yet.