13b402649be3f5f44e7324336532d1b2b75a8ef449ba71492d41ea3401757756

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Oct-10 14:57:48

Plugin Output

Suspicious The PE contains functions most legitimate programs don't use. Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Can take screenshots:
  • GetDC
  • CreateCompatibleDC
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 7f6358a75ea32d6879ce7bc9bb5db203 🔍
SHA1 4f788d7d36965313a6421315b9d5f80f0db60ab2 🔍
SHA256 13b402649be3f5f44e7324336532d1b2b75a8ef449ba71492d41ea3401757756 🔍
SHA3 2626a4dad7b4de5f02a7321296b66caae769b5c06620c661effff7f12830b416 🔍
SSDeep 1536:q2Lw0W4T6x9H3VSW/N4l+ZarCPQadOfCtmg3:rLwl4M3/N4lWarCPQadOfCtmg3 🔍
Imports Hash f8afe482c8c9fd4f5125d1feea87bac9 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2026-Oct-10 14:57:48
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 10.0
SizeOfCode 0xc800
SizeOfInitializedData 0x6000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000C60C (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xe000
ImageBase 0x10000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.1
ImageVersion 0.0
SubsystemVersion 5.1
Win32VersionValue 0
SizeOfImage 0x15000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 76efaf26081289e4dc908a658301ee08 🔍
SHA1 f4e88b03a075eb23821b43ed017c21eeae17df5d 🔍
SHA256 6d070c24f0f98824f192dfb7cd31141ef89b99e847dedea035ac12695d70d02e 🔍
SHA3 1ec1f61f30f3c9b745522bbeddd9e9dff436e7eb57bb21586dca155d8177e00e 🔍
VirtualSize 0xc6ec
VirtualAddress 0x1000
SizeOfRawData 0xc800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.52554

.rdata

MD5 6f643ef1fe922007318887296ae89152 🔍
SHA1 524c5a3345a118f665a33de77e714390907ac5ec 🔍
SHA256 c2fe41d386f7634920a23f8d059c640becb0ecae59ca3b1721457d45ea981a01 🔍
SHA3 dadee7d66485e7f2e00fa0b9f8206a106747a779e1989fcc2804fc7be4fe87d2 🔍
VirtualSize 0x3a56
VirtualAddress 0xe000
SizeOfRawData 0x3c00
PointerToRawData 0xcc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.13607

.data

MD5 606f1185b26fb5dca00f7e41ee27b8db 🔍
SHA1 503cfc5e55fe8f0a723c8b10cc81481db2c9addc 🔍
SHA256 c902f900e12e636d12a5552cb07e5d80f5f458bc976a8b0481298cdc3377c762 🔍
SHA3 5935272e5d2092bd33a36b400a6da2af2a28c1cd26e97e3415b34189302b7307 🔍
VirtualSize 0xc84
VirtualAddress 0x12000
SizeOfRawData 0x400
PointerToRawData 0x10800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.12824

.reloc

MD5 9feded56d404c224b9054fce6431ef34 🔍
SHA1 ba84016e9f0aea75c4ff71fe91ba79edfa6659aa 🔍
SHA256 7917c01c1c28bb6863b8b8f566e3480664fef98d5345c5c96dbb12a6c0b1518d 🔍
SHA3 56a8cc231a01591da6b411f8da0d8a6e2d3b775ef701a1411cd032a6f254bc43 🔍
VirtualSize 0x156e
VirtualAddress 0x13000
SizeOfRawData 0x1600
PointerToRawData 0x10c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.10348

Imports

d3d9.dll Direct3DCreate9
PSAPI.DLL GetModuleInformation
USER32.dll ReleaseDC
DefWindowProcA
GetDC
GetCursorPos
mouse_event
GetAsyncKeyState
RegisterClassA
CreateWindowExA
GDI32.dll SetTextColor
DeleteDC
CreateDIBSection
CreateFontA
SetBkColor
GdiFlush
DeleteObject
SelectObject
CreateCompatibleDC
ExtTextOutA
GetTextExtentPoint32A
MSVCP100.dll ?_Xlength_error@std@@YAXPBD@Z
?_Xout_of_range@std@@YAXPBD@Z
MSVCR100.dll _amsg_exit
__CppXcptFilter
_crt_debugger_hook
?terminate@@YAXXZ
?_type_info_dtor_internal_method@type_info@@QAEXXZ
_except_handler4_common
__clean_type_info_names_internal
_onexit
_lock
_unlock
_initterm_e
fclose
_vsnprintf
fprintf
fopen_s
__iob_func
??2@YAPAXI@Z
??3@YAXPAX@Z
memmove
??0exception@std@@QAE@ABV01@@Z
??0exception@std@@QAE@ABQBD@Z
??1exception@std@@UAE@XZ
?what@exception@std@@UBEPBDXZ
_initterm
_encoded_null
free
strtol
_malloc_crt
memset
memcpy
_CIsqrt
_CIsin
_CIcos
_CxxThrowException
__CxxFrameHandler3
__dllonexit
KERNEL32.dll GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
EncodePointer
DecodePointer
InterlockedExchange
InterlockedCompareExchange
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
QueryPerformanceCounter
IsProcessorFeaturePresent
VirtualProtect
GetModuleHandleA
FlushInstructionCache
GetCurrentProcess
VirtualQuery
OutputDebugStringA
DeleteCriticalSection
EnterCriticalSection
VirtualAlloc
LeaveCriticalSection
InitializeCriticalSection
GetPrivateProfileIntA
WideCharToMultiByte
ExitProcess
AddVectoredExceptionHandler
RemoveVectoredExceptionHandler
CreateThread
DisableThreadLibraryCalls
IsDebuggerPresent
Sleep
GetTickCount

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x10012018
SEHandlerTable 0x10010910
SEHandlerCount 26

RICH Header

XOR Key 0x5dc3f83a
Unmarked objects 0
152 (20115) 1
ASM objects (VS2010 build 30319) 3
C objects (VS2010 build 30319) 12
C++ objects (VS2010 build 30319) 4
Imports (VS2010 build 30319) 4
Imports (VS2008 SP1 build 30729) 11
Total imports 95
175 (VS2010 build 30319) 16
Linker (VS2010 build 30319) 1

Errors

Leave a comment

No comments yet.