| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2024-Aug-09 22:28:35 |
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
Embedded COFF debugging symbols
|
| Suspicious | PEiD Signature: |
UPX -> www.upx.sourceforge.net
UPX 2.00-3.0X -> Markus Oberhumer & Laszlo Molnar & John Reiser |
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to MD5 |
| Suspicious | The PE is packed with UPX |
Unusual section name found: UPX0
Section UPX0 is both writable and executable. Unusual section name found: UPX1 Section UPX1 is both writable and executable. The PE only has 6 import(s). |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Info | The PE's resources present abnormal characteristics. |
Resource 108 is possibly compressed or encrypted.
Resource 110 is possibly compressed or encrypted. Resource 113 is possibly compressed or encrypted. |
| Suspicious | The file contains overlay data. | 40602 bytes of data starting at offset 0x2f600. |
| Malicious | VirusTotal score: 46/70 (Scanned on 2026-07-30 13:28:17) |
ALYac:
Application.Generic.4264937
APEX: Malicious AVG: Win32:MalwareX-gen [Misc] AhnLab-V3: Unwanted/Win.Keygen.C5916558 Antiy-AVL: HackTool/Win32.KeyGen Arcabit: Application.Generic.D4113E9 Avast: Win32:MalwareX-gen [Misc] Avira: TR/W32.Agent BitDefender: Application.Generic.4264937 Bkav: W32.Malware.8A2F21A CTX: exe.hacktool.keygen CrowdStrike: win/malicious_confidence_90% (W) Cylance: Unsafe Cynet: Malicious (score: 100) Elastic: malicious (moderate confidence) Emsisoft: Application.Generic.4264937 (B) F-Secure: Trojan.TR/W32.Agent Fortinet: W32/PossibleThreat GData: Application.Generic.4264937 Google: Detected Gridinsoft: Hack.Win32.Patcher.cl Ikarus: PUA.HackTool.Win32.Keypz Lionic: Hacktool.Win32.Keygen.3!c Malwarebytes: Generic.Malware/Suspicious MaxSecure: Trojan.Malware.3405.susgen McAfeeD: Real Protect-LS!DFCFF72B1D31 MicroWorld-eScan: Application.Generic.4264937 Microsoft: HackTool:Win32/Keygen Paloalto: generic.ml Panda: PUP/Crack Rising: Hacktool.Keygen!8.B29 (CLOUD) SUPERAntiSpyware: Hack.Tool/Gen-KeyGen Sangfor: Hacktool.Win32.Keygen.V80s SentinelOne: Static AI - Suspicious PE Skyhigh: BehavesLike.Win32.Trojan.dc Sophos: Generic Reputation PUA (PUA) Symantec: ML.Attribute.HighConfidence Trapmine: malicious.moderate.ml.score TrellixENS: Artemis!DFCFF72B1D31 TrendMicro: Trojan.Win32.ZYX.USBLED26 TrendMicro-HouseCall: Trojan.Win32.ZYX.USBLED26 VBA32: BScope.Trojan.Click VIPRE: Application.Generic.4264937 Varist: W32/ABApplication.FOBQ-4713 ViRobot: HackTool.S.Keygen.234650 Xcitium: ApplicUnwnt@#8r9hjdubx7m4 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 3 |
| TimeDateStamp | 2024-Aug-09 22:28:35 |
| PointerToSymbolTable | 0x50c00 |
| NumberOfSymbols | 1856 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x2c000 |
| SizeOfInitializedData | 0x4000 |
| SizeOfUninitializedData | 0x31000 |
| AddressOfEntryPoint | 0x0005D610 (Section: UPX1) |
| BaseOfCode | 0x32000 |
| BaseOfData | 0x5e000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 1.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x62000 |
| SizeOfHeaders | 0x200 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.DLL |
LoadLibraryA
ExitProcess GetProcAddress VirtualProtect |
|---|---|
| msvcrt.dll |
atoi
|
| USER32.dll |
EndDialog
|
| StartAddressOfRawData | 0x45d820 |
|---|---|
| EndAddressOfRawData | 0x45d824 |
| AddressOfIndex | 0x40f084 |
| AddressOfCallbacks | 0x45d824 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x0045D7E9
|
No comments yet.