31349d61da780d59a8a27e2762405632726d88135a08ac5dda05849c62dfd551

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Mar-26 17:17:22
Detected languages English - United States
TLS Callbacks 1 callback(s) detected.
Debug artifacts TReload.pdb
ProductName Windows TReloader Service
CompanyName Microsoft Corporation
FileDescription Windows TReloader System Service
FileVersion 420174c
ProductVersion 420174c
InternalName TReload.exe
OriginalFilename TReload.exe
LegalCopyright В© 2024-2026 Microsoft Corporation
LegalTrademarks Microsoft Corporation
Comments Windows TReloader System Service
GitHash 420174c5
CommitDate 26.03.2026

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • 0www.entrust.net
  • GoDaddy.com
  • entrust.net
  • https://docs.rs
  • https://tg4service.com
  • openssl.org
  • tg4service.com
  • www.entrust.net
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegCloseKey
  • RegOpenKeyExW
  • RegQueryValueExW
Possibly launches other programs:
  • CreateProcessW
Uses Windows's Native API:
  • NtCreateFile
  • NtDeviceIoControlFile
  • NtReadFile
  • NtOpenFile
  • NtCreateNamedPipeFile
  • NtWriteFile
  • NtCancelIoFileEx
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Leverages the raw socket API to access the Internet:
  • ws2_32.dll
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Enumerates local disk drives:
  • GetVolumeInformationW
  • GetDriveTypeW
Malicious VirusTotal score: 30/71 (Scanned on 2026-08-14 06:00:58) ALYac: Trojan.GenericKD.81041004
AVG: Win64:MalwareX-gen [Misc]
Antiy-AVL: Trojan/Win32.APosT
Arcabit: Trojan.Generic.D4D4966C
Avast: Win64:MalwareX-gen [Misc]
Avira: TR/W64.Agent
BitDefender: Trojan.GenericKD.81041004
CTX: exe.trojan.apost
DeepInstinct: MALICIOUS
DrWeb: BackDoor.Siggen2.5979
ESET-NOD32: Win64/PSW.Agent.ARA trojan
Emsisoft: Trojan.GenericKD.81041004 (B)
F-Secure: Trojan.TR/W64.Agent
GData: Trojan.GenericKD.81041004
Google: Detected
Ikarus: Trojan.Stealer
Kaspersky: Trojan.Win32.APosT.bmtg
Kingsoft: Win32.Hack.Generic.a
Lionic: Trojan.Win32.APosT.4!c
MicroWorld-eScan: Trojan.GenericKD.81041004
Paloalto: generic.ml
Rising: Trojan.APosT!8.E271 (CLOUD)
Sophos: Mal/Generic-S
Symantec: Trojan.Gen.MBT
TrellixENS: Artemis!68F0365D2FA8
TrendMicro: Trojan.Win32.GENERICKD.USBLH726
TrendMicro-HouseCall: Trojan.Win32.GENERICKD.USBLH726
VIPRE: Trojan.GenericKD.81041004
Varist: W64/ABTrojan.NXMC-6289
alibabacloud: Trojan:Win/APosT.btlz

Hashes

MD5 68f0365d2fa8c828d012d8859e52a773 🔍
SHA1 17b6f4984930165939680a09d91989ad82bc57e2 🔍
SHA256 31349d61da780d59a8a27e2762405632726d88135a08ac5dda05849c62dfd551 🔍
SHA3 3fa29e7ab5c9425e549a930dd77c1a0943d137382642917a23611076b74f95ba 🔍
SSDeep 98304:bi7C1kRBfEIfHHIZJXuY5ZScDiAg9b8+7n5JTVYnl3m:BefEIfHHITuYbGgQn5Kl3m 🔍
Imports Hash 38bb893dcb8f714b097699a5261f1558 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Mar-26 17:17:22
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x6a3400
SizeOfInitializedData 0x287a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000067EEAC (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x92f000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 762d3363695c57145828fc2dc2dfb401 🔍
SHA1 696282a5a281f2c599c1eaf7990619e9dc4453d2 🔍
SHA256 635fc40bf760606b757375a9bf0a489cd5436aee0013f50cd9b32c3ed6e77b70 🔍
SHA3 4faa26d2c477a9e6c84d83f7988ffdaf9c5a5f06376c54602810cbf4cf162b60 🔍
VirtualSize 0x6a3370
VirtualAddress 0x1000
SizeOfRawData 0x6a3400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.20841

.rdata

MD5 5d091cf4108c51fa4d9fc4d2756167ea 🔍
SHA1 5ecc6a2a25c8df90a8b87b5c85f990260a7ccfcb 🔍
SHA256 1d94c01e9bf33a0f53192513cec0956766245d12f00e4bba39b02de721b3dc1c 🔍
SHA3 614b46895b1f8dff2b0293109d72e10d824ef6c762f4ff7dd7fda99b3b214611 🔍
VirtualSize 0x229b06
VirtualAddress 0x6a5000
SizeOfRawData 0x229c00
PointerToRawData 0x6a3800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.97602

.data

MD5 45dfae6c2ce1ea14702e2763ab8803c1 🔍
SHA1 4667467f19bdcae57f27e498eb21b38e214ec7dd 🔍
SHA256 bc79c4767a611243d746fc7972bea086ef67b8b085b69437fd45ae3fc6193f2e 🔍
SHA3 c4bc6c8194c24aaaa0c2a4335447fb6fc56f8eaf21e1c9081fb479b947c77a11 🔍
VirtualSize 0x6928
VirtualAddress 0x8cf000
SizeOfRawData 0x3600
PointerToRawData 0x8cd400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.1923

.pdata

MD5 9e1867a4bc008e742b20feebc2dc035e 🔍
SHA1 206fa7fb9581886064d88d316c76aec5764aaf32 🔍
SHA256 388a7a8112dc008d214d91fda66800bb06675dd02a047fb30ad8026869288f43 🔍
SHA3 7e01062a03fa2fa49012fd7501527eb285b05d9a8d7901b7b05be2fa0dbdecde 🔍
VirtualSize 0x4ebc4
VirtualAddress 0x8d6000
SizeOfRawData 0x4ec00
PointerToRawData 0x8d0a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.5177

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x925000
SizeOfRawData 0x200
PointerToRawData 0x91f600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 f8f277330401e9c014b8ec5add063bf1 🔍
SHA1 04049155482339059a9ec7d6d87cd5869f08b33e 🔍
SHA256 a751c9528f3c0da40aadea7b2bd04d76f8a7752f2e3d967870acc4e10bb6c5db 🔍
SHA3 06b0d6c30a9df3248139d97bc213341a8c68e73043fb840f65d532466e881097 🔍
VirtualSize 0x4a0
VirtualAddress 0x926000
SizeOfRawData 0x600
PointerToRawData 0x91f800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.69674

.reloc

MD5 b50bdd187dfbfaeaf16962ebfa1a0cda 🔍
SHA1 4f2c9298a16420f733ebcd668f8ba2e99bbd6b8e 🔍
SHA256 e50fc94641cb47c094be547ad942f77bac89faf59364b0bf8831413941e29cec 🔍
SHA3 97cdb5a88de126833363aa7c94256ad4cd8d29e4d3fcf1f3e45b6ef5fa0989d6 🔍
VirtualSize 0x7e94
VirtualAddress 0x927000
SizeOfRawData 0x8000
PointerToRawData 0x91fe00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.4538

Imports

bcryptprimitives.dll ProcessPrng
kernel32.dll LeaveCriticalSection
SetHandleInformation
EnterCriticalSection
EncodePointer
GetConsoleMode
RaiseException
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
HeapAlloc
SetConsoleCtrlHandler
CreateIoCompletionPort
PostQueuedCompletionStatus
GetQueuedCompletionStatusEx
GetModuleHandleA
GetOverlappedResult
ReadFile
WriteFile
TlsSetValue
FormatMessageW
GetExitCodeProcess
SetFileCompletionNotificationModes
RtlPcToFileHeader
RtlUnwindEx
HeapFree
GetProcessHeap
TlsFree
FlsAlloc
FlsGetValue
FlsSetValue
GetDiskFreeSpaceExW
DeviceIoControl
GetVolumeInformationW
GetDriveTypeW
GetVolumePathNamesForVolumeNameW
FindVolumeClose
FindNextVolumeW
FindFirstVolumeW
FlsFree
InitializeCriticalSectionEx
VirtualProtect
HeapSize
LoadLibraryExW
GetModuleHandleExW
SetStdHandle
IsProcessorFeaturePresent
GetStartupInfoW
GetCurrentProcessId
FreeLibrary
GetNativeSystemInfo
GetSystemInfo
GetProcAddress
SetUnhandledExceptionFilter
SetLastError
GetLastError
UnhandledExceptionFilter
GetSystemTimeAsFileTime
InitializeSListHead
GetCurrentProcess
BackupRead
CreateFileW
CloseHandle
GetComputerNameExW
IsDebuggerPresent
ws2_32.dll bind
WSASocketW
recv
WSASend
send
WSAStartup
freeaddrinfo
getaddrinfo
shutdown
socket
WSAGetLastError
getsockopt
setsockopt
ioctlsocket
connect
WSAIoctl
closesocket
WSACleanup
advapi32.dll OpenProcessToken
LookupPrivilegeValueW
AdjustTokenPrivileges
RegCloseKey
RegOpenKeyExW
RegQueryValueExW
api-ms-win-core-synch-l1-2-0.dll WakeByAddressAll
WaitOnAddress
WakeByAddressSingle
ntdll.dll NtCreateFile
RtlVirtualUnwind
RtlNtStatusToDosError
NtDeviceIoControlFile
NtReadFile
NtOpenFile
NtCreateNamedPipeFile
NtWriteFile
RtlCaptureContext
NtCancelIoFileEx
RtlLookupFunctionEntry
user32.dll GetSystemMetrics
ADVAPI32.dll StartServiceCtrlDispatcherW
SetServiceStatus
SystemFunction036
RegisterServiceCtrlHandlerExW
KERNEL32.dll AddVectoredExceptionHandler
WaitForSingleObject
DuplicateHandle
FlushFileBuffers
SetFileInformationByHandle
SetFilePointerEx
ReleaseMutex
CreateMutexA
GetCurrentThread
LoadLibraryA
WaitForSingleObjectEx
GetStringTypeW
WideCharToMultiByte
GetCPInfo
GetOEMCP
GetACP
lstrlenW
HeapReAlloc
IsValidCodePage
GetCommandLineA
GetSystemDefaultLocaleName
GetUserDefaultLocaleName
SetThreadStackGuarantee
GetCurrentDirectoryW
GetEnvironmentStringsW
GetEnvironmentVariableW
GetCommandLineW
CompareStringW
LCMapStringW
FindNextFileW
GetFileInformationByHandleEx
SwitchToThread
CreateEventW
GetFileInformationByHandle
GetFinalPathNameByHandleW
FindFirstFileExW
FindClose
GetFileType
SetEnvironmentVariableW
GetFullPathNameW
GetCurrentThreadId
GetTempPathW
GetModuleFileNameW
GetModuleHandleW
ExitProcess
WaitForMultipleObjects
ReadFileEx
SleepEx
QueryPerformanceFrequency
CancelIo
MultiByteToWideChar
WriteConsoleW
GetStdHandle
GetConsoleOutputCP
CreateWaitableTimerExW
SetWaitableTimer
Sleep
CreateThread
FreeEnvironmentStringsW
GetFileAttributesW
CompareStringOrdinal
GetSystemDirectoryW
GetWindowsDirectoryW
CreateProcessW
WriteFileEx
GetSystemTimePreciseAsFileTime
QueryPerformanceCounter
TerminateProcess
CreateDirectoryW
bcrypt.dll BCryptGenRandom

Delayed Imports

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x440
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.39497
MD5 526f7cb47808c17c643fa564aaffa9af 🔍
SHA1 46d7eac4dba13a5bfd9f9ed1493cce00e02f1c7d 🔍
SHA256 c2bf89f7799f947c24c8fdf9fca55f0944127a43529f69cac021716e35d941ac 🔍
SHA3 f6c6029a0b2904789559c3ce262369de707a8d0208d5276a2edf90de91822679 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.1.0.0
ProductVersion 0.1.0.0
FileFlags (EMPTY)
FileOs (EMPTY)
FileType VFT_UNKNOWN
Language English - United States
ProductName Windows TReloader Service
CompanyName Microsoft Corporation
FileDescription Windows TReloader System Service
FileVersion (#2) 420174c
ProductVersion (#2) 420174c
InternalName TReload.exe
OriginalFilename TReload.exe
LegalCopyright В© 2024-2026 Microsoft Corporation
LegalTrademarks Microsoft Corporation
Comments Windows TReloader System Service
GitHash 420174c5
CommitDate 26.03.2026
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Mar-26 17:17:22
Version 0.0
SizeofData 36
AddressOfRawData 0x7c7b90
PointerToRawData 0x7c6390
Referenced File TReload.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Mar-26 17:17:22
Version 0.0
SizeofData 20
AddressOfRawData 0x7c7bb4
PointerToRawData 0x7c63b4

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Mar-26 17:17:22
Version 0.0
SizeofData 1012
AddressOfRawData 0x7c7bc8
PointerToRawData 0x7c63c8

TLS Callbacks

StartAddressOfRawData 0x1407c8008
EndAddressOfRawData 0x1407c81e0
AddressOfIndex 0x1408d4880
AddressOfCallbacks 0x1406a5680
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x000000014063A5E0

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1408d1a00

RICH Header

XOR Key 0x53597214
Unmarked objects 0
C++ objects (33145) 142
C objects (33145) 25
ASM objects (33145) 13
ASM objects (35207) 9
C objects (35207) 16
C++ objects (35207) 41
Imports (33145) 5
C objects (35222) 12
Total imports 313
Unmarked objects (#2) 628
Resource objects (35222) 1
Linker (35222) 1

Errors

Leave a comment

No comments yet.