45a0fc414ad366a202d8940542a1ed9ac6f369893c8cf2d90586bf7e780fdd3b

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2023-Apr-18 22:40:23

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++
Microsoft Visual C++ v6.0
Microsoft Visual C++ v5.0/v6.0 (MFC)
Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • command.com
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • FindWindowA
Possibly launches other programs:
  • CreateProcessA
Can create temporary files:
  • GetTempPathA
  • CreateFileA
Enumerates local disk drives:
  • GetVolumeInformationA
Suspicious The file contains overlay data. 333142 bytes of data starting at offset 0x14000.
Overlay data amounts for 80.2632% of the executable.
Malicious VirusTotal score: 14/57 (Scanned on 2026-08-07 04:51:08) CrowdStrike: win/malicious_confidence_90% (W)
Cylance: Unsafe
Cynet: Malicious (score: 100)
Fortinet: W32/PossibleThreat
Gridinsoft: Trojan.Win32.Wacatac.oa!s1
Jiangmin: Trojan.BAT.azx
Malwarebytes: Malware.Heuristic.2062
McAfeeD: ti!45A0FC414AD3
Paloalto: generic.ml
SentinelOne: Static AI - Suspicious PE
Tencent: Trojan-Dropper.Win32.Agent.hcb
Trapmine: malicious.high.ml.score
Varist: W32/Trojan.PAIE-8642
huorong: TrojanDropper/Agent.amc

Hashes

MD5 78596645849c6d75aa42338cac0ba318
SHA1 97b5fccdee5fed197ec85b6c01e3d5568d81c29a
SHA256 45a0fc414ad366a202d8940542a1ed9ac6f369893c8cf2d90586bf7e780fdd3b
SHA3 80707d7d21d18f2af70990c27498ac0140ca82fd43bec2ec42067ae569776a60
SSDeep 3072:o23rbZi/8GprF3jg/oaudkw9zVAHveBVYBY+gvTQhUBVY:oKr1i/8UFmubAPeBO
Imports Hash c29ab370ed500debe05d495f2d8c12c2

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2023-Apr-18 22:40:23
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0xf000
SizeOfInitializedData 0xb04000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000090C6 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x10000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x1000
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0xb14000
SizeOfHeaders 0x1000
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 a8784bbf74a4f67f820ca8ca14d6893d
SHA1 0549e3c1bbb2e2fac4a900eeab1a797e40754f4f
SHA256 dd7ad4e866f95c6deeebb34c64772a4f6328df2da53448072520f2e81e0ced38
SHA3 46cd0f374627888dcbfb05d92fd8246f6e8cd975cd51c2d8f517090a1d09b60a
VirtualSize 0xec66
VirtualAddress 0x1000
SizeOfRawData 0xf000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.39452

.rdata

MD5 7de9cd21a659de4e55e38eb82065b6dd
SHA1 9161c80edb01ce3081aa02628d54eb0a406385b2
SHA256 b66a510ae1de3aeeda69a59465e8a554f60e6690e9f2cd8245b4263a9b9448dd
SHA3 f2df5b0f762212f73d590f2d4dd20c698676b813508641054f36990f9f08d6cd
VirtualSize 0xc0a
VirtualAddress 0x10000
SizeOfRawData 0x1000
PointerToRawData 0x10000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.55816

.data

MD5 b5bfe112ed2907f93d5310a7dfc430cb
SHA1 23b803821e944d928cd412548a709256f5250646
SHA256 5c945ab46cbde7b9829795f8e31beaaa0bd2f72c65a65ff93b0cb75be6766f2f
SHA3 30cdd2921206c200bc2bf28b9f9e2562815e48e398badd194ba8137f6c22d816
VirtualSize 0xb010d8
VirtualAddress 0x11000
SizeOfRawData 0x2000
PointerToRawData 0x11000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.77287

.rsrc

MD5 620f0b67a91f7f74151bc5be745b7110
SHA1 1ceaf73df40e531df3bfb26b4fb7cd95fb7bff1d
SHA256 ad7facb2586fc6e966c004d7d1d16b024f5805ff7cb47c7a85dabd8b48892ca7
SHA3 a99f9ed58079237f7f0275887f0c03a0c9d7d8de4443842297fceea67e423563
VirtualSize 0x10
VirtualAddress 0xb13000
SizeOfRawData 0x1000
PointerToRawData 0x13000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0

Imports

KERNEL32.dll GetTempPathA
GetModuleFileNameA
GetStdHandle
SetConsoleMode
GetConsoleMode
Sleep
SetConsoleTextAttribute
GetTickCount
SetConsoleCursorInfo
SetConsoleCursorPosition
GetVolumeInformationA
ReadConsoleInputA
WriteConsoleA
LCMapStringW
LCMapStringA
SetEnvironmentVariableA
CompareStringW
ExitProcess
TerminateProcess
GetCurrentProcess
GetCommandLineA
GetVersion
SetHandleCount
GetFileType
GetStartupInfoA
GetLastError
ReadFile
SetFilePointer
HeapFree
CloseHandle
GetFileAttributesA
GetProcAddress
GetModuleHandleA
WriteFile
UnhandledExceptionFilter
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStrings
GetEnvironmentStringsW
HeapDestroy
HeapCreate
VirtualFree
RtlUnwind
HeapAlloc
SetStdHandle
FlushFileBuffers
VirtualAlloc
HeapReAlloc
CreateFileA
GetExitCodeProcess
WaitForSingleObject
CreateProcessA
MultiByteToWideChar
GetStringTypeA
GetStringTypeW
GetCPInfo
GetACP
GetOEMCP
LoadLibraryA
SetEndOfFile
CompareStringA
USER32.dll FindWindowA
GetDesktopWindow
GetWindowRect
SetWindowPos
WINMM.dll timeGetTime

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0xa0b83448
Unmarked objects 0
12 (7291) 2
C++ objects (VS98 build 8168) 1
14 (7299) 15
19 (8034) 7
Total imports 70
C objects (VS98 build 8168) 95
Resource objects (VS98 cvtres build 1720) 1

Errors

Leave a comment

No comments yet.