1bb250dc315015722ead4d3f0768f703c157e0d592c4c466cb7989eb629ac7a0

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Dec-21 11:21:46

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Looks for Qemu presence:
  • qemu
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Suspicious The PE is possibly packed. Unusual section name found: .fptable
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Functions related to the privilege level:
  • OpenProcessToken
Enumerates local disk drives:
  • GetDriveTypeW
Suspicious The file contains overlay data. 30594584 bytes of data starting at offset 0x50400.
The overlay data has an entropy of 7.99833 and is possibly compressed or encrypted.
Overlay data amounts for 98.937% of the executable.
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 85074be38291f0b7edbd5fb79eb84cf0
SHA1 262b7b450fa4f7b01e0c600125266b6895bca384
SHA256 1bb250dc315015722ead4d3f0768f703c157e0d592c4c466cb7989eb629ac7a0
SHA3 9e9b4cafe6d6731a6f1670f7168a88fad7036ab5d562531b9a0b448a0dc90ea5
SSDeep 786432:KPas/xJ2heCZW8eS0gCYLLsKMMo5ovsVuNwZHj+vV/M8+tVsQFRf4ADL4U:KPas/X2heCZWZgC7oeSqjr8+fFBtL4
Imports Hash dcaf48c1f10b0efa0a4472200f3850ed

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2025-Dec-21 11:21:46
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x2be00
SizeOfInitializedData 0x24200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000000DA30 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x59000
SizeOfHeaders 0x400
Checksum 0x1d80b92
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x1e8480
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 79078dae5994611672a1080749101869
SHA1 be9c7a11814f7e654435b7b2a858df7738f0241a
SHA256 1180a0bbf2679ba2720454c832cc6b01ea5bbeaee37609b47ddc1bf806e7d9da
SHA3 7de9be818a2c3f66ad004fa3e393e42ef976f3b4b7b6931e4953031ae23eb158
VirtualSize 0x2bd80
VirtualAddress 0x1000
SizeOfRawData 0x2be00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.47403

.rdata

MD5 7c083d4a5083eeb006ac7a055755dddf
SHA1 86867ca614712e6094a33ae09e68f5c3aeba6052
SHA256 e2f80749d5580829377fe78c7645cbffd000a75c2c0049c2c323777afe2c0159
SHA3 aa01849bce0e6020ec02e4bc838f2ce4a0757bc8a6b0842a72d52db418bc8e29
VirtualSize 0x13968
VirtualAddress 0x2d000
SizeOfRawData 0x13a00
PointerToRawData 0x2c200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.74441

.data

MD5 e0a74fb607d827b7f2943febfe00c7d1
SHA1 d20b33e2d420135a15643e84ab2baac0d80c55a5
SHA256 8148ddc2a533e179fc88c07354adf34ed86333daaebd0891e86993c082233de5
SHA3 55830dfaa0f7dcbdcc4b4a494eebc43dc5a9965a4efe4398e65026dbef32d5ec
VirtualSize 0x50b0
VirtualAddress 0x41000
SizeOfRawData 0xe00
PointerToRawData 0x3fc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.81901

.pdata

MD5 8de57d92d89fc5d4db9828c2663f55ee
SHA1 90f19cf10cbb12507a9ed4b275065147758888d6
SHA256 76d215d188c2739fa2991be73942f6552065d66409fd48a98c8ed6c84bbd12fd
SHA3 59af4ab2b1e601cc6818a4181762a6a0739d311ba69acaa2510fed60bfee1d0a
VirtualSize 0x23dc
VirtualAddress 0x47000
SizeOfRawData 0x2400
PointerToRawData 0x40a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.47251

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x100
VirtualAddress 0x4a000
SizeOfRawData 0x200
PointerToRawData 0x42e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 e6bcaa777ea840d504c6b5877b13e23c
SHA1 304430a975f56a6a8bd0124fc61c21497c2c6c23
SHA256 7b0f9b51c2f6d76da45a6741b3dd26666aa749b9950a4237d8f992c4f55d2816
SHA3 04c7fc8521a1db818e6293a7c42114da859910251a47d42011516c14a818cf98
VirtualSize 0xcb80
VirtualAddress 0x4b000
SizeOfRawData 0xcc00
PointerToRawData 0x43000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.97545

.reloc

MD5 66c54168d4d2ad0a461ee561d8a0c79d
SHA1 74d880349b51dce02fd33f4b07c9bc72fe3f7a60
SHA256 977618f629e78ac49a41fc8407054bc51db7413ba82183c901835b7731d2a79e
SHA3 c244ee7f42dd35f36c4a8182b272540e318fdd40c7b00a5f5676f735577a6c22
VirtualSize 0x774
VirtualAddress 0x58000
SizeOfRawData 0x800
PointerToRawData 0x4fc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.26264

Imports

USER32.dll CreateWindowExW
ShutdownBlockReasonCreate
MsgWaitForMultipleObjects
ShowWindow
DestroyWindow
RegisterClassW
DefWindowProcW
PeekMessageW
DispatchMessageW
TranslateMessage
PostMessageW
GetMessageW
MessageBoxW
MessageBoxA
SystemParametersInfoW
DestroyIcon
SetWindowLongPtrW
GetWindowLongPtrW
GetClientRect
InvalidateRect
ReleaseDC
GetDC
DrawTextW
GetDialogBaseUnits
EndDialog
DialogBoxIndirectParamW
MoveWindow
SendMessageW
COMCTL32.dll #380
KERNEL32.dll GetACP
IsValidCodePage
GetStringTypeW
GetFileAttributesExW
SetEnvironmentVariableW
FlushFileBuffers
LCMapStringW
CompareStringW
VirtualProtect
InitializeCriticalSectionEx
GetOEMCP
GetCPInfo
GetLastError
FreeLibrary
GetProcAddress
LoadLibraryExW
GetModuleHandleW
MulDiv
FormatMessageW
GetModuleFileNameW
SetDllDirectoryW
GetEnvironmentStringsW
SetErrorMode
CreateDirectoryW
GetCommandLineW
GetEnvironmentVariableW
ExpandEnvironmentStringsW
DeleteFileW
FindClose
FindFirstFileW
FindNextFileW
GetDriveTypeW
RemoveDirectoryW
GetTempPathW
CloseHandle
QueryPerformanceCounter
QueryPerformanceFrequency
WaitForSingleObject
Sleep
GetCurrentProcess
TerminateProcess
GetExitCodeProcess
CreateProcessW
GetStartupInfoW
LocalFree
SetConsoleCtrlHandler
K32EnumProcessModules
K32GetModuleFileNameExW
CreateFileW
FindFirstFileExW
GetFinalPathNameByHandleW
MultiByteToWideChar
WideCharToMultiByte
FlsFree
FreeEnvironmentStringsW
GetProcessHeap
GetTimeZoneInformation
HeapSize
HeapReAlloc
WriteConsoleW
SetEndOfFile
CreateSymbolicLinkW
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
RtlUnwindEx
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
EncodePointer
RaiseException
RtlPcToFileHeader
GetCommandLineA
GetFileInformationByHandle
GetFileType
PeekNamedPipe
SystemTimeToTzSpecificLocalTime
FileTimeToSystemTime
ReadFile
GetFullPathNameW
SetStdHandle
GetStdHandle
WriteFile
ExitProcess
GetModuleHandleExW
HeapFree
GetConsoleMode
ReadConsoleW
SetFilePointerEx
GetConsoleOutputCP
GetFileSizeEx
HeapAlloc
GetCurrentDirectoryW
FlsAlloc
FlsGetValue
FlsSetValue
ADVAPI32.dll OpenProcessToken
GetTokenInformation
ConvertStringSecurityDescriptorToSecurityDescriptorW
ConvertSidToStringSidW
GDI32.dll SelectObject
DeleteObject
CreateFontIndirectW

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.46867
Detected Filetype PNG graphic file
MD5 1750ff55b9ed9408ff43dc71c8886068
SHA1 2e94bc7b8f2162104078354c56e05e9e8a09efcb
SHA256 3ae2f96166add01e86e7c3ded12d38da43dfdc58c9f86f4aebaf4851d5035a6b
SHA3 8e7391e270bd7b15dceaebd23019e6fb05193099c1b520a3f41aa532e5c49034

2

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x328
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.71027
Detected Filetype PNG graphic file
MD5 2167bc890244dfc242ae42bd20433cd8
SHA1 96ef058633ac9d7db514b27a2949e31a45262da2
SHA256 b28aaf58e5d0dec317e941a93082f06b4335854807d3f9f0752214eebdf27044
SHA3 34cd254b1371b3795165307e06c4e9f4d39a279963ac2aa8c5d1708df7c032e1

3

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4c9
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.81112
Detected Filetype PNG graphic file
MD5 7ab145895fa355734089a70ebe896efb
SHA1 8de18c1e15892a167e1d92825e62d48a7e26e000
SHA256 5e6ec6843298e06efbdf5306dbb26d649447b4e53d310846484b3f7b43798ee5
SHA3 7b669bb83f51b73f73b80510df67d787c632e6e1f45db8d7ce097dfca2b0145b

4

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x8b5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.89302
Detected Filetype PNG graphic file
MD5 b7c78e5cf12dd497a66a4bdc6010edc1
SHA1 4ebed2569ab0a53d05faeca7f37912a51984aa15
SHA256 a06bb984d478f2aa35b197d2899c04e20da3ab6ba96f59604630708b3614282f
SHA3 fdc4d2c26a2310ce30e3bd1c53d82d4c3cb34879cec787bbac62a58337087434

5

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xdba
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.93581
Detected Filetype PNG graphic file
MD5 5add91d6a308d93541a4aadab0859807
SHA1 ff1ea2ce4d7c36662cb8fd78cda22ebdec0676b7
SHA256 f1190481146be9d907d8b1e23ecd5516e7e21c9c040493d3eb2211bac555e33b
SHA3 81166e73815df0c7e8426b0f942ad5c338aebaf5d15f5724a8f651a1224da5e2

6

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x28fd
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97387
Detected Filetype PNG graphic file
MD5 f04b45390fce9b40b45a92b5d9aa254b
SHA1 3412735cb8aeb0528cbe0e30b3a8105415efa0e1
SHA256 b6507fefb2ccd57fbfcdc02c474e0909dd92da17c3d2b8784a903d8cc127d28b
SHA3 b12afffcdf2497dff3ae23194fe081b97c7a7005285c8e61c018636097212fdf

7

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x7ac1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99047
Detected Filetype PNG graphic file
MD5 378b52aec15779a4c38715c27ff703f3
SHA1 36e46acc2dbb26322869d4e9a70cc48c539489d5
SHA256 708e5dfa1bd70b9c55d4e3247eb416989d90bce2f946e19f0d7d3000201a1b00
SHA3 c144368e907ec6ac93c1fe26b7af2f3575497c7783fe6eab968b9af0e4550e9b

1 (#2)

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.65771
Detected Filetype Icon file
MD5 493a1cd786e8a70140225ffeff700f6b
SHA1 b0288494d46823f3b946ac0c93649ded60723a0c
SHA256 27430aa48fe417f576f0ba7b62fe8588aa7dfd6129f20963f14b9095b04fc615
SHA3 d8fd57bb9a38a6e5e1317303041dfa838766b526c77f26ef4fdd6d4addcc872d

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x50d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.25791
MD5 84da8dee6b319ea0b10b6de5489c6aae
SHA1 5f8991f3e065fd95614859a293f88b9c70e4bb23
SHA256 abf8f2022f12f350789d961aceaf9ccfd53e7ec58d8c9934cfce77779b4eac11
SHA3 08f0562915b54bedce5a84e9d32cb2efcc538268785103b1852338e20a3b4606

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Dec-21 11:21:46
Version 0.0
SizeofData 816
AddressOfRawData 0x3cff8
PointerToRawData 0x3c1f8

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140041040
GuardCFCheckFunctionPointer 5368894648
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x461d01ab
Unmarked objects 0
C++ objects (33140) 183
C objects (33140) 12
ASM objects (33140) 10
253 (35207) 3
ASM objects (35207) 9
C objects (35207) 17
C++ objects (35207) 40
Imports (33140) 11
Total imports 159
C objects (35215) 27
Linker (35215) 1

Errors

Leave a comment

No comments yet.