3739d09c6ae40f1791526c281e7c4bea3c6925bc396d56e8dbeb6002417fd0c0

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2025-Dec-13 22:43:15
FileDescription
FileVersion 0.0.0.0
InternalName GPMPatcher.exe
LegalCopyright
OriginalFilename GPMPatcher.exe
ProductVersion 0.0.0.0
Assembly Version 0.0.0.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C# v7.0 / Basic .NET
.NET executable -> Microsoft
Suspicious The PE is possibly a dropper. Resources amount for 91.528% of the executable.
Malicious VirusTotal score: 30/59 (Scanned on 2026-02-08 05:14:54) APEX: Malicious
Antiy-AVL: Trojan[Miner]/MSIL.CoinMiner
Arcabit: Trojan.Generic.D4A8927A
Bkav: W32.AIDetectMalware.CS
CTX: exe.trojan.msil
CrowdStrike: win/malicious_confidence_90% (W)
Cylance: Unsafe
DeepInstinct: MALICIOUS
DrWeb: Trojan.Siggen32.16527
Elastic: malicious (high confidence)
Emsisoft: Trojan.GenericKD.78156410 (B)
Fortinet: PossibleThreat
GData: Trojan.GenericKD.78156410
Google: Detected
Kingsoft: MSIL.Trojan.CoinMiner.gen
Lionic: Trojan.Win32.CoinMiner.4!c
Malwarebytes: Generic.Malware/Suspicious
McAfeeD: Real Protect-LS!E67DD5DE721F
MicroWorld-eScan: Trojan.GenericKD.78156410
Microsoft: Trojan:Win32/Wacatac.B!ml
Paloalto: generic.ml
Sangfor: Trojan.Win32.Save.a
SentinelOne: Static AI - Suspicious PE
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
Trapmine: suspicious.low.ml.score
TrellixENS: Artemis!E67DD5DE721F
VIPRE: Trojan.GenericKD.78156410
Varist: W32/ABTrojan.EMVC-2119
alibabacloud: Trojan:MSIL/CoinMiner.gyf

Hashes

MD5 e67dd5de721f0ee12de0f05fddc7e267
SHA1 d785c174e88cf9b49998355f432805f6fe63d7ac
SHA256 3739d09c6ae40f1791526c281e7c4bea3c6925bc396d56e8dbeb6002417fd0c0
SHA3 9ea01ff5fd544194906264211d3aef53b8736872e10ccf862017ac101a7a638c
SSDeep 1536:j8uPRHMUM3AzHmtK20pNBJZXATa6LUIMWOVn5BSNFnWPVXpfjn3wXQQtVinm3rx:guPs4d6gnk
Imports Hash f34d5f2d4577ed6d9ceec516c1f5a744

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 3
TimeDateStamp 2025-Dec-13 22:43:15
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 11.0
SizeOfCode 0x1e00
SizeOfInitializedData 0x18e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00003DCE (Section: .text)
BaseOfCode 0x2000
BaseOfData 0x4000
ImageBase 0x400000
SectionAlignment 0x2000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x20000
SizeOfHeaders 0x200
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 7d4e40b457dc4bd60ce5166175749cd8
SHA1 d129cef29fbbd279bac42f0dc6373990d19ad053
SHA256 b8949f1dcc2e315ff655e51d8eabfc9ad0d14cad1a6d664ce83004a8362b395a
SHA3 c772646a43bd1d5a4744c801559f83104496cde322108c755ca9e5463e3be0f2
VirtualSize 0x1dd4
VirtualAddress 0x2000
SizeOfRawData 0x1e00
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.30263

.rsrc

MD5 c45eb7c0665cfe26551acdeeb2cb1616
SHA1 cf93f172063dc16874bc3fd063a30123a1c095a9
SHA256 4f8576b3fed4179abe300ff56423866c3e27be5d7f0d367ad546a3c81706c30a
SHA3 4a6780058389d2c7b873bba9b21b2731ce729fc0607a6b4160db5ed553ac269a
VirtualSize 0x18b90
VirtualAddress 0x4000
SizeOfRawData 0x18c00
PointerToRawData 0x2000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.98657

.reloc

MD5 519b4205cc1387107af2fdd76aba8bf8
SHA1 d030098d11a1f335a6b65a3ff0babe1f625e6818
SHA256 29e1a8f25d938f173d3b97dc3fca830261bcb157078ed16b5a9ec5a2fe5609dd
SHA3 6019f5f2710119ba2f50a1a181282d985d3e2343d26a4a3f3dbed6a5457067c2
VirtualSize 0xc
VirtualAddress 0x1e000
SizeOfRawData 0x200
PointerToRawData 0x1ac00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.0815394

Imports

mscoree.dll _CorExeMain

Delayed Imports

2

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.84386
MD5 404537776585ae4ddf73540fbf62c69a
SHA1 e47bad1a705fa76d7b8c4ee6713a67c25a9c3700
SHA256 7a6b06e4907e3adfd381e0d53bbc905e2f90f675bf66f952a200d41ec068422c
SHA3 066a6a3117f3c21aa2ddbb3187f804dfe3711d320ffb55d45fe423d24398e200

3

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.06078
MD5 2ccb2cc974e642b851873925a16fd6a9
SHA1 e463f89e5eeb43061092e0fc6555ce22f02342ec
SHA256 b6be867025dd100c68496f85fe76680d00e39b0d3eb15e8804fcb4561296bc62
SHA3 e2b484637392da710e1fb38d761fa967bda584ee3cd10e58db2f5a0e8d6f5c04

4

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.23369
MD5 da440318684f5a8139214013ec7984ea
SHA1 7915abf8117d07b2514ca455794bbbd56861a707
SHA256 cb45d747be1d9d619efd119e40d05046777124bfbdea32cfe643b3f3d1a39839
SHA3 5544a3dda83fbe36a6faec9e9a82cdf4d8805d31e0085a670c4416167aac078b

5

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.47371
MD5 bd953b047e26aa8031b8bc8dd366b631
SHA1 c451cbb96ed5b5f56c3e552cac5d2ee3e819fa1d
SHA256 e6eb52d045b74a3a25c960b8c7d157fe752bd13b384d63278d8d6ec5d2764c32
SHA3 34b3cfdd3324ec6d2d383d21f85cdb195a11795b6818571e5bd4760c5e4dc297

6

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.90336
MD5 ccaebf224cf7211f3eb43336ffdda68a
SHA1 73e61ec0e95e1543202ce42adadfdd50283e21f9
SHA256 c163278e36b17f3824c3b6c4d13fd52f8497e4d032d142e9021130dc8ee5936d
SHA3 8b25a969541fe14a3d4d94e01dacd0f8a315c7bd4ba8463e4bfeeeebc45475de

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.86004
Detected Filetype Icon file
MD5 7b4fe5b6f58596c1451fae4e47a11e5e
SHA1 36c2de65b054e2c0e7cc8d43a52af9a210189bc5
SHA256 e617bc58f9199690dfc40b566d8e9bfb311a16186104d436ba8548bc21ad72d7
SHA3 56fe496247b02123034ec994f84077c579986857b4d6a20869ad38d3d4fdde49

1

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x254
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.18962
MD5 4ae34548f692153c80bce173959eb864
SHA1 61cd3e3442caa89fc1edf24f14908f16c9825ee6
SHA256 ac4aa4b677d7ee34068e6ab76fc3384789616051d46cfeaaf93dc39402594a9e
SHA3 0c0f6fd7be4b4a4c0894525f30cf08e00518a77c8acb2d0b43098f7f8b643aa7

1 (#2)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x1ea
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.00112
MD5 a19a2658ba69030c6ac9d11fd7d7e3c1
SHA1 879dcf690e5bf1941b27cf13c8bcf72f8356c650
SHA256 c0085eb467d2fc9c9f395047e057183b3cd1503a4087d0db565161c13527a76f
SHA3 93cbaf236d2d3870c1052716416ddf1c34f21532e56dd70144e9a01efcd0ce34

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.0.0.0
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
FileDescription
FileVersion (#2) 0.0.0.0
InternalName GPMPatcher.exe
LegalCopyright
OriginalFilename GPMPatcher.exe
ProductVersion (#2) 0.0.0.0
Assembly Version 0.0.0.0
Resource LangID UNKNOWN

TLS Callbacks

Load Configuration

RICH Header

Errors

Leave a comment

No comments yet.