| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2022-Nov-29 10:54:19 |
| Detected languages |
Russian - Russia
Uzbek - Uzbekistan (Latin) |
| CompanyName | Helper |
| FileDescription | Helper |
| FileVersion | 4.5.4.3 |
| InternalName | Helper.exe |
| LegalCopyright | Help System (C) 1999-2021 |
| OriginalFilename | Helper.exe |
| ProductName | Helper |
| ProductVersion | 2.5.6.1 |
| Malicious | The PE contains functions mostly used by malware. |
Code injection capabilities (process hollowing):
|
| Malicious | VirusTotal score: 56/72 (Scanned on 2026-03-26 05:11:35) |
ALYac:
Trojan.GenericKD.64619706
APEX: Malicious AVG: Win32:Malware-gen AhnLab-V3: Trojan/Win.Injection.C5322037 Alibaba: TrojanBanker:Win32/Vidar.0cb359fd Antiy-AVL: Trojan/Win32.Wacatac Arcabit: Trojan.Generic.D3DA04BA Avast: Win32:Malware-gen BitDefender: Trojan.GenericKD.64619706 Bkav: W32.AIDetectMalware CAT-QuickHeal: Trojan.Ghanarava.1722589863f306d6 CTX: exe.trojan.vidar CrowdStrike: win/malicious_confidence_100% (W) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS DrWeb: Trojan.PWS.Steam.34227 ESET-NOD32: Win32/Vidar.A trojan Elastic: malicious (high confidence) Emsisoft: Trojan.GenericKD.64619706 (B) Fortinet: W32/PossibleThreat GData: Trojan.GenericKD.64619706 Google: Detected Gridinsoft: Trojan.Win32.Agent.sd!n Jiangmin: Trojan.Banker.Bandra.aaa K7AntiVirus: Password-Stealer ( 005f57c41 ) K7GW: Password-Stealer ( 005f57c41 ) Kaspersky: HEUR:Trojan-Banker.Win32.Bandra.gen Kingsoft: Win32.Troj.Unknown.a Lionic: Trojan.Win32.Vidar.7!c Malwarebytes: Malware.AI.3773022010 MaxSecure: Trojan.Malware.73934634.susgen McAfeeD: ti!2CC0BE582A35 MicroWorld-eScan: Trojan.GenericKD.64619706 Microsoft: Trojan:Win32/Vidar.A!MTB Paloalto: generic.ml Panda: Trj/Chgt.AB Rising: Stealer.Agent!8.C2 (TFE:5:7B7NryAuBQP) Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Suspicious PE Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence Tencent: Malware.Win32.Gencirc.13ae85b5 Trapmine: malicious.high.ml.score TrellixENS: Artemis!5367709F0A96 TrendMicro: TROJ_FRS.0NA103L623 TrendMicro-HouseCall: TROJ_FRS.0NA103L623 VBA32: TrojanPSW.Arkei VIPRE: Trojan.GenericKD.64619706 Varist: W32/ABlTrojan.WQXT-0289 ViRobot: Trojan.Win.Z.Agent.371200.L Xcitium: Malware@#30myttw0s7m0c Yandex: Trojan.PWS.Agent!qoLY6khBB2g Zillya: Trojan.Agent.Win32.3154995 alibabacloud: Trojan:Win/Vidar.A huorong: HEUR:VirTool/Obfuscator.gen!B |
| MD5 | 5367709f0a96713b5c9a518e13f306d6 🔍 |
|---|---|
| SHA1 | 244bdcc9a3548101cacc9c4f8912fb8631764b40 🔍 |
| SHA256 | 2cc0be582a350f1eafb6d3c6cc713393098a6936346a9070ba55abd346dfb090 🔍 |
| SHA3 | 2dae87f17815366380024b5889934bb25dfc1addf50d8eebf492baad8d8289a7 🔍 |
| SSDeep | 6144:/Xd9qQwRToa3lQZCsPuugr+mJ35AfpJW+0sZZLBO+jJJM9KSlAo8hV:fdEVBoOlQnuuG+k3efD6sjLelAdb 🔍 |
| Imports Hash | 6294a2f7da3a84900c7e91cad8ab870e 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2022-Nov-29 10:54:19 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x2200 |
| SizeOfInitializedData | 0x58c00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00002851 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x4000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x5f000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 67b65a8d6fd2e7923fa352a04420c846 🔍 |
|---|---|
| SHA1 | 93f30a7caae9168c74c400d642f01b306edfc342 🔍 |
| SHA256 | 83d9b35649a895734dba09bed6eff736882c6083b36d074f4a7f9c170364e35c 🔍 |
| SHA3 | 7e2697cdbba2f7f3b00595ca18fbcf3935124196627e1bea895e20a8e5b3c217 🔍 |
| VirtualSize | 0x2144 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x2200 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.10974 |
| MD5 | 47e756e90d79f2bb0ce2e8acb94bd34c 🔍 |
|---|---|
| SHA1 | 034a5c61d594832f842c881d0e63f2d61fd17a2d 🔍 |
| SHA256 | 4a40b5a52b22f96e66b838c602e0fd3ff58c0de01e9963e4f31f7303a0e6f2d5 🔍 |
| SHA3 | 87c5606b18ebf214385f05b725d806d79a702a857324c5cdef98f3a7545e2f71 🔍 |
| VirtualSize | 0x10a6 |
| VirtualAddress | 0x4000 |
| SizeOfRawData | 0x1200 |
| PointerToRawData | 0x2600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.44065 |
| MD5 | 9f93c08c812f40fe675d88e380364f51 🔍 |
|---|---|
| SHA1 | ea366c3d7b0394aa9b90a216efb0197fc48dc8e1 🔍 |
| SHA256 | fbe1d6d134f6d813baba829f82e90571e4ae44c9a6a9c79de98ce87c810844fb 🔍 |
| SHA3 | 81a1149cec9ae54c1961ac5ad77be2da9f9017aacd251b1117c0cce065b58ab1 🔍 |
| VirtualSize | 0x497a8 |
| VirtualAddress | 0x6000 |
| SizeOfRawData | 0x49000 |
| PointerToRawData | 0x3800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 7.65813 |
| MD5 | bc5d50b41bc880596d1342515198dd39 🔍 |
|---|---|
| SHA1 | 135d1fe735ed4d17a3c5eb20af456b114f68b41f 🔍 |
| SHA256 | cd1afc5a6281faf5e0f784685a2cc298d696faf76ff22861c9fe81b686d435d8 🔍 |
| SHA3 | 19b87c2f11bd112f1d3edee142552d6bfca38d2a798f88bfff5ecd13026bc8c4 🔍 |
| VirtualSize | 0xddd8 |
| VirtualAddress | 0x50000 |
| SizeOfRawData | 0xde00 |
| PointerToRawData | 0x4c800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 3.17975 |
| MD5 | 791c16efc937029ec72eab88efe3040f 🔍 |
|---|---|
| SHA1 | b3da23416cc5533a6e94cfae5e88ee10d92b32b8 🔍 |
| SHA256 | a129ebf4d5ab66a39e012fbe5c6602191b0c6b8a9bdec9a825e45face56ea213 🔍 |
| SHA3 | b0c71432c21a6084ac1d3095856304a2021a42b785ace8bc66147042eb8622c4 🔍 |
| VirtualSize | 0x310 |
| VirtualAddress | 0x5e000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x5a600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.55081 |
| KERNEL32.dll |
GetModuleFileNameA
WriteProcessMemory ResumeThread GetModuleHandleA GetThreadContext GetProcAddress ExitProcess ReadProcessMemory CreateProcessA SetThreadContext IsDebuggerPresent SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent GetStartupInfoW GetModuleHandleW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead UnhandledExceptionFilter |
|---|---|
| MSVCP140.dll |
?_Xlength_error@std@@YAXPBD@Z
|
| VCRUNTIME140.dll |
_except_handler4_common
memset __current_exception_context memcpy _CxxThrowException __std_exception_copy __std_exception_destroy __CxxFrameHandler3 __current_exception memmove |
| api-ms-win-crt-runtime-l1-1-0.dll |
_crt_atexit
_cexit _seh_filter_exe _set_app_type _register_onexit_function _initterm _initterm_e _exit exit _c_exit _register_thread_local_exe_atexit_callback _initialize_narrow_environment _configure_narrow_argv _get_narrow_winmain_command_line terminate _controlfp_s _initialize_onexit_table _invalid_parameter_noinfo_noreturn |
| api-ms-win-crt-stdio-l1-1-0.dll |
_set_fmode
__p__commode |
| api-ms-win-crt-utility-l1-1-0.dll |
rand
srand |
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
malloc free _set_new_mode |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Type |
RT_ICON
|
|---|---|
| Language | Russian - Russia |
| Codepage | UNKNOWN |
| Size | 0xda28 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.13909 |
| MD5 | 5bb21684cb09fcaf8792d5d4165b4bb1 🔍 |
| SHA1 | b4dc1519c829652d2bdbcdbb6274cd2638cc635c 🔍 |
| SHA256 | 2f842a659ec81d16366ebc1aa550966a10245baa501ff11061acfb693d467bed 🔍 |
| SHA3 | d254669818196bf7e3b8045d564f412181205a9f6107edbb4f5b98a295ee461b 🔍 |
| Type |
RT_GROUP_ICON
|
|---|---|
| Language | Russian - Russia |
| Codepage | UNKNOWN |
| Size | 0x14 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 2.01924 |
| Detected Filetype | Icon file |
| MD5 | e54dce95599a37c765c741f4f74d1fdc 🔍 |
| SHA1 | 5b6fdff3d0949b34f7be0b774349f1be930fe462 🔍 |
| SHA256 | 2e17127cbc27f694b1652e508988d0d95f69e3dd3f0c03ec4d65d05c429596ef 🔍 |
| SHA3 | a22385c3ac06a8160ed71407a84c2bc11730314360292e067031aa5f14c1ee06 🔍 |
| Type |
RT_VERSION
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x2a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.38007 |
| MD5 | 2a7fb568d5c28ce04a57dd272cbefcf6 🔍 |
| SHA1 | 45807dd921ca9617bfebfc0cdb97a0a70a7b6dbc 🔍 |
| SHA256 | 041a4e2bcccc3904e687a4f764021955a16d7a8a409ba19b42101cd0b5bc7121 🔍 |
| SHA3 | 40c961768418fea65f89e7bd6edd438c370ad59678a2ec626ca29166007c57a8 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 4.5.4.3 |
| ProductVersion | 2.5.6.1 |
| FileFlags |
VS_FF_PRERELEASE
VS_FF_PRIVATEBUILD
VS_FF_SPECIALBUILD
|
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | Uzbek - Uzbekistan (Latin) |
| CompanyName | Helper |
| FileDescription | Helper |
| FileVersion (#2) | 4.5.4.3 |
| InternalName | Helper.exe |
| LegalCopyright | Help System (C) 1999-2021 |
| OriginalFilename | Helper.exe |
| ProductName | Helper |
| ProductVersion (#2) | 2.5.6.1 |
| Resource LangID | UNKNOWN |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Nov-29 10:54:19 |
| Version | 0.0 |
| SizeofData | 772 |
| AddressOfRawData | 0x44e0 |
| PointerToRawData | 0x2ae0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Nov-29 10:54:19 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x406004 |
| SEHandlerTable | 0x40446c |
| SEHandlerCount | 2 |
| XOR Key | 0x6c5979e9 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 14 |
| C objects (VS 2015-2022 runtime 31823) | 12 |
| ASM objects (VS 2015-2022 runtime 31823) | 1 |
| C++ objects (VS 2015-2022 runtime 31823) | 25 |
| Imports (VS 2015-2022 runtime 31823) | 4 |
| Imports (27412) | 3 |
| Total imports | 123 |
| C++ objects (LTCG) (VS2022 Update 4 (17.4.0-1) compiler 31933) | 1 |
| Resource objects (VS2022 Update 4 (17.4.0-1) compiler 31933) | 1 |
| Linker (VS2022 Update 4 (17.4.0-1) compiler 31933) | 1 |
No comments yet.