18c2c1f172bb531162e07c83009fd3aea77b748f6bf6cfa5184797075d3fafb5

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2025-Oct-13 02:50:25

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryExW
Can access the registry:
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegCloseKey
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 005e6fb50572e6e43e7490f6d6037d8d
SHA1 002d6e79852c8faa0e8bc6ca5d8d0c709183a320
SHA256 18c2c1f172bb531162e07c83009fd3aea77b748f6bf6cfa5184797075d3fafb5
SHA3 d8d0f9ae6c0eafa30c4be5e284b15babca56fb00442704812a73a81d0ca10607
SSDeep 3072:Plu4UvXvuH41/RmNrDOsSxCceUKi1kc6bMbNVSbOtAbIUo+o8FBItIsSpmke7Uf:P8Lf+ompBSxCceUKxbwRaoL9Uf
Imports Hash e678fa6bedeb9652fb992778e0ed10c0

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xd8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2025-Oct-13 02:50:25
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 12.0
SizeOfCode 0x34600
SizeOfInitializedData 0x12a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0001F65C (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x36000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x4a000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 258541586f37fd34660a1a5eebb40f75
SHA1 6b757ec00547f52bcf598e330b621540ccd0f24f
SHA256 21888b7b4a7db8f832d3ae48e41c2fc22353e454a516e15b4b2c7dd930f63983
SHA3 d6053bbe550e316da129f7717c710c6a76ad9d7b8fa5696d6448e0a8d585e20f
VirtualSize 0x3455b
VirtualAddress 0x1000
SizeOfRawData 0x34600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.44752

.rdata

MD5 19beaa7330eedb6f0b2660e218995ede
SHA1 fd7dc3b5fc7fe52fe81088aa032ce8b1461e7b4e
SHA256 5c58a06f392f7794d63e5aa0fc9ad586eeecf995ea1af2cc521c5830f47583da
SHA3 ecf45f1197d8e7c161bb4dfde51f777b1e573e57a1576b6c353e9b60d63f8c55
VirtualSize 0xbffa
VirtualAddress 0x36000
SizeOfRawData 0xc000
PointerToRawData 0x34a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.6965

.data

MD5 2549ba48310c62de7d850c2e8fbd16ca
SHA1 f2346de1705f9084bcbf53ce8548ad9d3245e2d5
SHA256 669bed05ce02b6a3f8c3681b463698f537354bbd1053809e81df7b666d132a91
SHA3 ae4a5a2ddf628b4477c8c554a0f98ea7272919017d052ac4645ce0c4e14cee35
VirtualSize 0x4008
VirtualAddress 0x42000
SizeOfRawData 0x1e00
PointerToRawData 0x40a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.84472

.reloc

MD5 2ee83e78a127867b98bdac7c8c20d3b4
SHA1 9e8174fef3bbbb2bebdde55c85fc13a8be819602
SHA256 75cee5fad0d1a28068b404149a4811476b077757055949c35b98af7e3f4b2ac6
SHA3 564a9327d4a861f3879377c4c8a66a76b50e7aae86ba449cee9aecdeae7c174c
VirtualSize 0x266c
VirtualAddress 0x47000
SizeOfRawData 0x2800
PointerToRawData 0x42800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.48778

Imports

ADVAPI32.dll RegOpenKeyExW
RegQueryValueExW
RegCloseKey
KERNEL32.dll FindClose
FindFirstFileA
FindNextFileA
GetFileAttributesA
GetCurrentProcessId
FreeLibrary
GetProcAddress
LoadLibraryW
SetDllDirectoryW
MultiByteToWideChar
WideCharToMultiByte
GetStringTypeW
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
EncodePointer
DecodePointer
IsDebuggerPresent
IsProcessorFeaturePresent
GetLastError
ExitProcess
GetModuleHandleExW
AreFileApisANSI
HeapFree
HeapAlloc
HeapReAlloc
GetStdHandle
GetFileType
GetModuleFileNameW
WriteConsoleW
RaiseException
RtlUnwind
GetCommandLineA
GetCPInfo
UnhandledExceptionFilter
SetUnhandledExceptionFilter
SetLastError
InitializeCriticalSectionAndSpinCount
Sleep
GetCurrentProcess
TerminateProcess
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetStartupInfoW
GetModuleHandleW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
HeapSize
CloseHandle
FlushFileBuffers
WriteFile
GetConsoleCP
GetConsoleMode
ReadFile
SetFilePointerEx
LoadLibraryExW
IsValidCodePage
GetACP
GetOEMCP
GetProcessHeap
GetCurrentThreadId
OutputDebugStringW
GetModuleFileNameA
QueryPerformanceCounter
GetSystemTimeAsFileTime
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
ReadConsoleW
CreateFileW
SetEndOfFile

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x442500
SEHandlerTable 0x43f800
SEHandlerCount 89

RICH Header

XOR Key 0x4df366ad
Unmarked objects 0
ASM objects (VS2013 build 21005) 29
C++ objects (VS2013 build 21005) 74
C objects (VS2013 build 21005) 214
Imports (65501) 5
Total imports 90
C++ objects (VS2013 UPD2 build 30501) 1
Linker (VS2013 UPD2 build 30501) 1

Errors

Leave a comment

No comments yet.