244ebafb50ea1708b977bce470e19dccb72086f2925f25b3631c2037a6fed83d

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Sep-26 12:18:15
Detected languages English - United States
TLS Callbacks 1 callback(s) detected.
CompanyName Lx
FileDescription Lx Aim
FileVersion 1.0
InternalName LxAim
OriginalFilename Lx Aim.exe
ProductName Lx Aim
ProductVersion 1.0

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
Info Cryptographic algorithms detected in the binary: Uses constants related to AES
Uses constants related to RC5 or RC6
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryExA
  • GetProcAddress
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • CheckRemoteDebuggerPresent
Possibly launches other programs:
  • CreateProcessW
Has Internet access capabilities:
  • WinHttpSendRequest
  • WinHttpOpenRequest
  • WinHttpSetOption
  • WinHttpReceiveResponse
  • WinHttpCloseHandle
  • WinHttpConnect
  • WinHttpSetTimeouts
  • WinHttpReadData
  • WinHttpOpen
  • WinHttpQueryHeaders
Can take screenshots:
  • BitBlt
  • CreateCompatibleDC
  • GetDC
Suspicious The file contains overlay data. 104 bytes of data starting at offset 0x8a9200.
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 941af64ba11af2e4187a22d2cdc35a94 🔍
SHA1 630985cb361363ae2c18e20e9279ea79e8ea256a 🔍
SHA256 244ebafb50ea1708b977bce470e19dccb72086f2925f25b3631c2037a6fed83d 🔍
SHA3 949dabb3852efdffa110987f5f80ed674ed325847ee471f9977f32c33ff919b0 🔍
SSDeep 49152:Ew7wfxepR5Y/esj8LLlm/8VaUkKaop53E4rcz0YEOjxF91DLytxdz8EaKGBcrWhS:AERvaBWYJTSh 🔍
Imports Hash c2f2dcdf2504314c143e7da5f9100d4d 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Sep-26 12:18:15
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x876000
SizeOfInitializedData 0x33a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000008729D0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x8ae000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 0403fe37866d8f0829469811eb43a6af 🔍
SHA1 8249dca03b34c141b91358b44c066ded17ff0cec 🔍
SHA256 322922e815ab374e25fb0e6a339e17b7b0f4c377eeea604fffc73593c3beb624 🔍
SHA3 7c8f641b6e7733858861c9d740567166d0413b9353a4628b55c35c293d7b026a 🔍
VirtualSize 0x875f31
VirtualAddress 0x1000
SizeOfRawData 0x876000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.19898

.rdata

MD5 50da8d8685e8f42cb543ce9bef8f0246 🔍
SHA1 8b13c12dc39ae9217c95b6b1fd3734ff3c9aebd4 🔍
SHA256 fff53140e2e46f618f6334ff6a9cb156bfbc544dcc1e37084a950cc7ce7db0b9 🔍
SHA3 5fbc16fd954057ba04b95ec999688cac10f541d737bd01da7e5d37b524eaafc7 🔍
VirtualSize 0x2a7ec
VirtualAddress 0x877000
SizeOfRawData 0x2a800
PointerToRawData 0x876400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.90026

.data

MD5 f2f232d7aa7e9569b3e0d2d45210813e 🔍
SHA1 c000482113afef2352e2150924518bd4f0fac932 🔍
SHA256 b44a5924102caa91719c587f7f9d5069bc426eafb42875d6566c5adaac1f9bf7 🔍
SHA3 d515b2374e45771b355bbda39c08718ffae238f7ad78a713ea9883cbb207f7b0 🔍
VirtualSize 0x1c60
VirtualAddress 0x8a2000
SizeOfRawData 0x1200
PointerToRawData 0x8a0c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.84519

.pdata

MD5 a0eb17f59a218cf740140d1154ffccf9 🔍
SHA1 9388b08613fab117254c96683222581a33b56c57 🔍
SHA256 8ac9de9d213085c3f18d49feed5bd71faa6deaeec72bb57688cabdb83e2058f2 🔍
SHA3 0c1ae3b88731ac41e0e10b043ef3919863a4fc92c6b7fcebce675d58959de69d 🔍
VirtualSize 0x54d8
VirtualAddress 0x8a4000
SizeOfRawData 0x5600
PointerToRawData 0x8a1e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.88852

.didat

MD5 8d192bb8f028b32c9656e3020f1e9ccc 🔍
SHA1 969f965146c582fea76a1d94773673ad0de4ae06 🔍
SHA256 d35d9b81197a653281980cb47e56f5aca6d257fd7596d29a6f6a44c2888cd3cb 🔍
SHA3 337f20394dcd27847c58780fa649d85bfee703d3b0f890d1bfed747f39389fe6 🔍
VirtualSize 0x18
VirtualAddress 0x8aa000
SizeOfRawData 0x200
PointerToRawData 0x8a7400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.188057

.rsrc

MD5 847be5b0202a93f9aed4110285951e05 🔍
SHA1 0e0ae415a1b59b8a4f5829bebf6cbd6521d0b0c7 🔍
SHA256 f86b63274bf2c8d2076338e9ca1b523796358d59f65802dcbeb03baa71cfc8bc 🔍
SHA3 3c0d622b8bc63f9d4f12f2a89bec7d785e4d6fc1bc985a63b7e249d60a36795b 🔍
VirtualSize 0x450
VirtualAddress 0x8ab000
SizeOfRawData 0x600
PointerToRawData 0x8a7600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.31686

.reloc

MD5 92b6819344eefb388e679ee69ad5ba13 🔍
SHA1 d758ed269741eca6dd2b48b815448d3d872b95f7 🔍
SHA256 e0125ae63fa479e8bac19841ee7b63f38ebec8f90efec778a63ac811d3cb82df 🔍
SHA3 24cb7751009cb5a4b24836805f15fbbfd99976116ed12f5f42b6173a653483e0 🔍
VirtualSize 0x1438
VirtualAddress 0x8ac000
SizeOfRawData 0x1600
PointerToRawData 0x8a7c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.30416

Imports

SHELL32.dll SHGetKnownFolderPath
ole32.dll CoTaskMemFree
d3d11.dll D3D11CreateDevice
dxgi.dll CreateDXGIFactory1
GDI32.dll BitBlt
CreateDIBSection
DeleteObject
SelectObject
CreateCompatibleDC
DeleteDC
USER32.dll RegisterRawInputDevices
SetWindowLongPtrW
RegisterClassExW
MsgWaitForMultipleObjectsEx
DispatchMessageW
TranslateMessage
GetAsyncKeyState
PeekMessageW
UnregisterClassW
GetDC
DestroyWindow
GetWindowLongPtrW
SetProcessDpiAwarenessContext
GetRawInputData
EnumDisplayMonitors
DefWindowProcW
ReleaseDC
CreateWindowExW
SETUPAPI.dll SetupDiEnumDeviceInfo
SetupDiDestroyDeviceInfoList
SetupDiGetDeviceRegistryPropertyW
SetupDiGetClassDevsW
SetupDiGetDeviceInstanceIdW
WINHTTP.dll WinHttpSendRequest
WinHttpOpenRequest
WinHttpSetOption
WinHttpReceiveResponse
WinHttpCloseHandle
WinHttpConnect
WinHttpSetTimeouts
WinHttpReadData
WinHttpOpen
WinHttpQueryHeaders
bcrypt.dll BCryptOpenAlgorithmProvider
BCryptImportKeyPair
BCryptFinishHash
BCryptDestroyHash
BCryptHash
BCryptGenRandom
BCryptDestroyKey
BCryptVerifySignature
BCryptHashData
BCryptCloseAlgorithmProvider
BCryptCreateHash
KERNEL32.dll RaiseException
GetSystemInfo
VirtualProtect
VirtualQuery
LoadLibraryExA
GetLocaleInfoEx
FormatMessageA
LocalFree
MultiByteToWideChar
GetFileInformationByHandleEx
AreFileApisANSI
CreateFile2
SetFileInformationByHandle
GetFullPathNameW
GetFileInformationByHandle
GetFileAttributesExW
FindNextFileW
FindFirstFileExW
FindFirstFileW
FindClose
CreateDirectoryW
SetUnhandledExceptionFilter
InitializeSListHead
GetSystemTimeAsFileTime
GetCurrentThreadId
GetCurrentProcessId
QueryPerformanceCounter
SleepConditionVariableSRW
WakeAllConditionVariable
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
MoveFileExW
GetProcAddress
GetModuleHandleA
CheckRemoteDebuggerPresent
GetCurrentProcess
IsDebuggerPresent
SetDefaultDllDirectories
SetConsoleOutputCP
SetConsoleCP
GetModuleFileNameW
SetConsoleCtrlHandler
GetConsoleProcessList
GetStdHandle
GetConsoleMode
GetSystemDirectoryW
CreateProcessW
CloseHandle
WaitForSingleObject
TerminateProcess
GetExitCodeProcess
WideCharToMultiByte
SetConsoleMode
ReadConsoleW
GetModuleHandleW
GetConsoleScreenBufferInfo
CreateFileW
GetFileSizeEx
ReadFile
SetFilePointerEx
GetLastError
LoadLibraryExW
FreeLibrary
WriteFile
CreateFileA
GetCommState
SetCommState
SetCommTimeouts
PurgeComm
Sleep
MSVCP140.dll ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?init@?$basic_ios@DU?$char_traits@D@std@@@std@@IEAAXPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@_N@Z
??0ios_base@std@@IEAA@XZ
?_Xbad_alloc@std@@YAXXZ
?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?__ExceptionPtrCreate@@YAXPEAX@Z
?__ExceptionPtrToBool@@YA_NPEBX@Z
?__ExceptionPtrDestroy@@YAXPEAX@Z
?__ExceptionPtrCopy@@YAXPEAXPEBX@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?good@ios_base@std@@QEBA_NXZ
?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?uncaught_exceptions@std@@YAHXZ
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
?get@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAHXZ
_Query_perf_frequency
_Query_perf_counter
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z
?_Throw_Cpp_error@std@@YAXH@Z
_Thrd_id
_Thrd_join
?__ExceptionPtrRethrow@@YAXPEBX@Z
?_Xlength_error@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z
?_Syserror_map@std@@YAPEBDH@Z
?_Winerror_map@std@@YAHH@Z
_Cnd_do_broadcast_at_thread_exit
?__ExceptionPtrCurrentException@@YAXPEAX@Z
?__ExceptionPtrAssign@@YAXPEAXPEBX@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?_Xinvalid_argument@std@@YAXPEBD@Z
?_Xbad_function_call@std@@YAXXZ
_Mtx_lock
_Mtx_unlock
_Cnd_broadcast
_Xtime_get_ticks
?fail@ios_base@std@@QEBA_NXZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1ios_base@std@@UEAA@XZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
??0_Lockit@std@@QEAA@H@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Id_cnt@id@locale@std@@0HA
??1_Lockit@std@@QEAA@XZ
MSVCP140_ATOMIC_WAIT.dll __std_atomic_wait_direct
__std_atomic_notify_all_direct
VCRUNTIME140.dll __current_exception
__C_specific_handler
__current_exception_context
memmove
memcmp
__std_terminate
__CxxFrameHandler3
__std_exception_destroy
_CxxThrowException
memcpy
__std_exception_copy
memset
VCRUNTIME140_1.dll __CxxFrameHandler4
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
malloc
_callnewh
free
api-ms-win-crt-string-l1-1-0.dll towlower
strlen
isalpha
isalnum
isspace
toupper
strcmp
tolower
wcsnlen
wcslen
api-ms-win-crt-runtime-l1-1-0.dll _cexit
_c_exit
__p___argc
_exit
exit
_initterm_e
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_get_initial_wide_environment
abort
_errno
_initialize_wide_environment
terminate
_beginthreadex
_configure_wide_argv
_set_app_type
_seh_filter_exe
__p___wargv
_register_thread_local_exe_atexit_callback
_initterm
api-ms-win-crt-convert-l1-1-0.dll strtoll
strtod
strtoul
strtoull
api-ms-win-crt-locale-l1-1-0.dll localeconv
___lc_codepage_func
_configthreadlocale
api-ms-win-crt-stdio-l1-1-0.dll fclose
fputc
ungetc
fgetc
fwrite
__stdio_common_vsprintf
fread
fgetpos
__p__commode
_set_fmode
fflush
_get_stream_buffer_pointers
setvbuf
fsetpos
_fseeki64
api-ms-win-crt-math-l1-1-0.dll roundf
_hypotf
fmod
expf
truncf
round
__setusermatherr
_dsign
powf
api-ms-win-crt-filesystem-l1-1-0.dll _unlock_file
_lock_file
onnxruntime.dll (delay-loaded) #4
#1

Delayed Imports

Attributes 0x1
Name onnxruntime.dll
ModuleHandle 0x8a3b88
DelayImportAddressTable 0x8aa000
DelayImportNameTable 0x89f130
BoundDelayImportTable 0x89f148
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x22c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.21061
MD5 8739b656972d5128dfd49af3474d0819 🔍
SHA1 fe416365085844f25669dc59fe14a39c31ad8a56 🔍
SHA256 286415bc005fd70bc02386da50d92c5683db7c5897848139313c85d1bb7e7a57 🔍
SHA3 a90ccb0324364923212310c07640ae160e7153992d8e3725d5b0819d7e16a135 🔍

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Lx
FileDescription Lx Aim
FileVersion (#2) 1.0
InternalName LxAim
OriginalFilename Lx Aim.exe
ProductName Lx Aim
ProductVersion (#2) 1.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Sep-26 12:18:15
Version 0.0
SizeofData 1072
AddressOfRawData 0x88aed8
PointerToRawData 0x88a2d8

UNKNOWN

Characteristics 0
TimeDateStamp 2026-Sep-26 12:18:15
Version 0.0
SizeofData 4
AddressOfRawData 0x88b308
PointerToRawData 0x88a708

TLS Callbacks

StartAddressOfRawData 0x14088b330
EndAddressOfRawData 0x14088b470
AddressOfIndex 0x1408a3b90
AddressOfCallbacks 0x140877a20
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks 0x0000000140872DE0

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1408a2fc0
GuardCFCheckFunctionPointer 5377587448
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x4f93bd27
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 18
Imports (35721) 8
ASM objects (35721) 4
C objects (35721) 10
C objects (33145) 1
C objects (CVTCIL) (33145) 1
Imports (33145) 21
Total imports 299
C++ objects (35721) 39
Unmarked objects (#2) 10
Resource objects (36260) 1
151 1
Linker (36260) 1

Errors

Leave a comment

No comments yet.