47a5e76de5e55da0739826d4d60b349c35e26029b5d1d80a10024121fa820123

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2019-Apr-04 21:13:43
Detected languages English - United States
FileVersion 1.1.30.03
ProductVersion 1.1.30.03

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Contains domain names:
  • .exe.bat.com
  • autohotkey.com
  • exe.bat.com
  • http://schemas.microsoft.com
  • http://schemas.microsoft.com/SMI/2005/WindowsSettings
  • http://www.w3.org
  • http://www.w3.org/2001/XMLSchema
  • http://www.w3.org/2001/XMLSchema-instance
  • https://autohotkey.com
  • microsoft.com
  • schemas.microsoft.com
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses known Mersenne Twister constants
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryW
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • FindWindowW
Code injection capabilities:
  • WriteProcessMemory
  • OpenProcess
  • VirtualAllocEx
Code injection capabilities (PowerLoader):
  • FindWindowW
  • GetWindowLongW
Can access the registry:
  • RegisterHotKey
  • RegDeleteKeyW
  • RegSetValueExW
  • RegCreateKeyExW
  • RegQueryValueExW
  • RegEnumKeyExW
  • RegEnumValueW
  • RegQueryInfoKeyW
  • RegOpenKeyExW
  • RegCloseKey
  • RegDeleteValueW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Uses functions commonly found in keyloggers:
  • MapVirtualKeyW
  • GetAsyncKeyState
  • AttachThreadInput
  • CallNextHookEx
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAllocEx
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Interacts with services:
  • OpenSCManagerW
Enumerates local disk drives:
  • GetDriveTypeW
  • GetVolumeInformationW
Manipulates other processes:
  • WriteProcessMemory
  • ReadProcessMemory
  • OpenProcess
Can take screenshots:
  • GetDC
  • FindWindowW
  • BitBlt
  • CreateCompatibleDC
Reads the contents of the clipboard:
  • GetClipboardData
Can shut the system down or lock the screen:
  • ExitWindowsEx
Malicious The PE is possibly a dropper. Resource AUTOHOTKEY.EXE detected as a PE Executable.
Malicious VirusTotal score: 5/69 (Scanned on 2024-03-18 09:07:59) Bkav: W64.AIDetectMalware
CrowdStrike: win/malicious_confidence_70% (D)
Jiangmin: Trojan.PSW.Predator.fk
SentinelOne: Static AI - Suspicious PE
VirIT: Trojan.Win64.Genus.DGW

Hashes

MD5 ae46c78389b890f86211882c1087bee6
SHA1 765098c583b6ed1436cfa2eeca238d614ed89347
SHA256 47a5e76de5e55da0739826d4d60b349c35e26029b5d1d80a10024121fa820123
SHA3 534302537566ac1635ba79880d63de668bf7e21b668ee29e1576ed1861a0dd3f
SSDeep 49152:ElOhBCfLUjME9UI7JJqWuQ8s3gt9LoHwjvTyXdC8fZOc:ECF9FtgMOvLMCzc
Imports Hash f9309fff2ca1987b729c2da5521e6655

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x120

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2019-Apr-04 21:13:43
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xc2c00
SizeOfInitializedData 0x17a000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000A5468 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.2
ImageVersion 0.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x247000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
SizeofStackReserve 0x400000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 0a54d0143031b1e74e8a76aa402ecef9
SHA1 5c4e90e5c717c442726a2167b07d3e5c85c23b27
SHA256 53566fb0caa932a241365cfa055199eef4d97d72931c869c157f76178181dbd1
SHA3 407e51a4465751ff9eceffe5f905adea393b8160fe18be0f28ac415bd085dbaa
VirtualSize 0xc2b6c
VirtualAddress 0x1000
SizeOfRawData 0xc2c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.52292

.rdata

MD5 85591764158a9e5826cd3fd8bcc92cfb
SHA1 a7fc12c5c37d4633df8df73976546c5da27f5ca0
SHA256 6bfe33a8fac0688b3de104af1533f4c3548d6d1e7b256d9334833ef48995d9b6
SHA3 76b3e2cc7452d0407984fdc7da4b956b967f16425518fc99e9213da2ad3a68f9
VirtualSize 0x38800
VirtualAddress 0xc4000
SizeOfRawData 0x38800
PointerToRawData 0xc3000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.12564

.data

MD5 571634d8ff5b74f1ab7e4bb0c37dd710
SHA1 33c7660fe3f05beb89ffc8a6da4023f8ebba54cd
SHA256 c2142eaf978bab502928c5a7117b6dcadca50f7dc27e75648767b77b02070c5e
SHA3 562a8515953393cf2a7a485f35c6de4d5970b011374f07631f422d869f320e19
VirtualSize 0x9f64
VirtualAddress 0xfd000
SizeOfRawData 0x3a00
PointerToRawData 0xfb800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.23131

.pdata

MD5 423bc6ba8632b83f497f2e6bdc44f18d
SHA1 3c191c3f62043081d2c988bfe7d0d08e013bddc2
SHA256 f1da85aa68ab8ccf85540440e7f19fdafcb31e99dbef8e1990292be645efea90
SHA3 8147327a777ba55487ca861274f029ef1b720727960ff0a04038fd5e417ee610
VirtualSize 0x6f9c
VirtualAddress 0x107000
SizeOfRawData 0x7000
PointerToRawData 0xff200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.96098

.gfids

MD5 2e5016f24776d6980a8d173cf7168714
SHA1 62f9d2f81bc134111a2115d5d1517522361abcd6
SHA256 5c20a0f4899d9fe94a90016ea563189c2878b2b4930045c9cd3911cc93b9da2a
SHA3 7adf2a822aaf409615dbd5dc87ac6c9c292c75c46c2e21f725d700973093042f
VirtualSize 0xec
VirtualAddress 0x10e000
SizeOfRawData 0x200
PointerToRawData 0x106200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.03933

.tls

MD5 1f354d76203061bfdd5a53dae48d5435
SHA1 aa0d33a0c854e073439067876e932688b65cb6a9
SHA256 4c6474903705cb450bb6434c29e8854f17d8324efca1fdb9ee9008599060883a
SHA3 991fbbd46bbd69198269fe6c247d440e0f8a7d38259b7a1e04b74790301d1d2b
VirtualSize 0x9
VirtualAddress 0x10f000
SizeOfRawData 0x200
PointerToRawData 0x106400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.0203931

.rsrc

MD5 cc8596e1c9ee352e36fab5d8400798db
SHA1 ade127ff8794f5049eb344bdb07968309378a4a8
SHA256 604ac517c5c6ea96d9fe769f02fbea55ff780e860ee0bd1096079ea1b069c880
SHA3 db4767cafa2206d2434586e5b2aaaca9867863346a5e852b64c45e67963e7492
VirtualSize 0x1369e8
VirtualAddress 0x110000
SizeOfRawData 0x136a00
PointerToRawData 0x106600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.5004

Imports

WSOCK32.dll WSACleanup
inet_addr
gethostbyname
gethostname
WSAStartup
WINMM.dll mixerSetControlDetails
waveOutGetVolume
joyGetPosEx
mixerGetControlDetailsW
mixerOpen
mixerGetDevCapsW
mixerGetLineControlsW
waveOutSetVolume
mixerClose
mciSendStringW
joyGetDevCapsW
mixerGetLineInfoW
VERSION.dll VerQueryValueW
GetFileVersionInfoW
GetFileVersionInfoSizeW
COMCTL32.dll ImageList_Create
CreateStatusWindowW
ImageList_ReplaceIcon
ImageList_GetIconSize
ImageList_Destroy
ImageList_AddMasked
PSAPI.DLL GetModuleFileNameExW
GetProcessImageFileNameW
GetModuleBaseNameW
KERNEL32.dll LockResource
FindFirstFileW
FindNextFileW
FindClose
FileTimeToLocalFileTime
SetEnvironmentVariableW
Beep
MoveFileW
OutputDebugStringW
CreateProcessW
GetFileAttributesW
WideCharToMultiByte
MultiByteToWideChar
GetExitCodeProcess
WriteProcessMemory
ReadProcessMemory
GetCurrentProcessId
OpenProcess
TerminateProcess
SetPriorityClass
SetLastError
GetEnvironmentVariableW
GetLocalTime
GetDateFormatW
GetTimeFormatW
GetDiskFreeSpaceW
SetVolumeLabelW
CreateFileW
DeviceIoControl
GetDriveTypeW
GetVolumeInformationW
CreateDirectoryW
ReadFile
WriteFile
DeleteFileW
SetFileAttributesW
LocalFileTimeToFileTime
SetFileTime
GetFileSizeEx
GetSystemTime
GetSystemDefaultUILanguage
GetComputerNameW
GetWindowsDirectoryW
GetTempPathW
GetFullPathNameW
GetShortPathNameW
EnterCriticalSection
LeaveCriticalSection
VirtualProtect
LoadResource
CompareStringW
RemoveDirectoryW
CopyFileW
GetCurrentProcess
FormatMessageW
GetPrivateProfileStringW
GetPrivateProfileSectionW
GetPrivateProfileSectionNamesW
WritePrivateProfileStringW
WritePrivateProfileSectionW
SetEndOfFile
GetACP
GetFileType
GetStdHandle
SetFilePointerEx
SystemTimeToFileTime
FileTimeToSystemTime
GetFileSize
IsWow64Process
VirtualAllocEx
VirtualFreeEx
EnumResourceNamesW
LoadLibraryExW
GlobalSize
TlsGetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
RtlUnwindEx
RaiseException
EncodePointer
RtlPcToFileHeader
InitializeSListHead
QueryPerformanceCounter
IsProcessorFeaturePresent
GetStartupInfoW
SetUnhandledExceptionFilter
UnhandledExceptionFilter
IsDebuggerPresent
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
CreateEventW
WaitForSingleObjectEx
ResetEvent
SetEvent
GetCommandLineW
ExitProcess
GetModuleHandleExW
HeapSize
HeapReAlloc
HeapQueryInformation
HeapFree
HeapAlloc
SizeofResource
FindResourceW
GetSystemTimeAsFileTime
GetModuleFileNameW
DeleteCriticalSection
GetCPInfo
GetVersionExW
FreeLibrary
LoadLibraryW
GetModuleHandleW
GetProcAddress
GetLastError
CreateMutexW
CloseHandle
GetExitCodeThread
SetThreadPriority
CreateThread
GetStringTypeExW
lstrcmpiW
GetCurrentThreadId
GlobalUnlock
GlobalFree
GlobalAlloc
GlobalLock
GetCurrentDirectoryW
SetErrorMode
InitializeCriticalSection
SetCurrentDirectoryW
Sleep
GetTickCount
MulDiv
TlsSetValue
TlsFree
LCMapStringW
GetStringTypeW
GetConsoleCP
GetConsoleMode
GetProcessHeap
FindFirstFileExW
IsValidCodePage
GetCommandLineA
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
FlushFileBuffers
WriteConsoleW
QueryDosDeviceW
ReadConsoleW
USER32.dll RedrawWindow
SetWindowLongPtrW
SetParent
GetClassInfoExW
GetAncestor
UpdateWindow
GetMessagePos
GetClassLongPtrW
DefDlgProcW
CallWindowProcW
CheckRadioButton
IntersectRect
GetUpdateRect
PtInRect
CreateDialogIndirectParamW
GetWindowLongPtrW
CreateAcceleratorTableW
DestroyAcceleratorTable
InsertMenuItemW
SetMenuDefaultItem
RemoveMenu
SetMenuItemInfoW
IsMenu
GetMenuItemInfoW
CreateMenu
CreatePopupMenu
SetMenuInfo
AppendMenuW
DestroyMenu
TrackPopupMenuEx
GetDesktopWindow
CopyImage
CreateIconIndirect
CreateIconFromResourceEx
EnumClipboardFormats
GetWindow
BringWindowToTop
MessageBoxW
GetTopWindow
MoveWindow
GetQueueStatus
GetWindowRect
GetClientRect
SystemParametersInfoW
AdjustWindowRectEx
DrawTextW
SetRect
GetIconInfo
MapWindowPoints
IsWindowVisible
LoadImageW
ChangeClipboardChain
SetClipboardViewer
LoadAcceleratorsW
EnableMenuItem
GetMenu
CreateWindowExW
RegisterClassExW
LoadCursorW
DestroyIcon
DestroyWindow
IsCharAlphaW
MapVirtualKeyW
ClientToScreen
MapVirtualKeyExW
GetKeyboardLayoutNameW
ActivateKeyboardLayout
GetGUIThreadInfo
GetWindowTextW
mouse_event
WindowFromPoint
GetSystemMetrics
keybd_event
SetKeyboardState
GetKeyboardState
GetCursorPos
GetAsyncKeyState
AttachThreadInput
SendInput
UnregisterHotKey
RegisterHotKey
PostQuitMessage
SendMessageTimeoutW
UnhookWindowsHookEx
SetWindowsHookExW
PostThreadMessageW
IsCharAlphaNumericW
IsCharUpperW
IsCharLowerW
ToUnicodeEx
GetKeyboardLayout
CallNextHookEx
CharLowerW
ReleaseDC
GetDC
OpenClipboard
GetClipboardData
GetClipboardFormatNameW
RemovePropW
SetPropW
GetPropW
FlashWindow
SetMenu
ExitWindowsEx
GetMenuStringW
GetSubMenu
GetMenuItemID
GetMenuItemCount
GetSystemMenu
GetLastInputInfo
SetWindowTextW
GetCursor
CloseClipboard
SetClipboardData
EmptyClipboard
PostMessageW
FindWindowW
EndDialog
IsWindow
DispatchMessageW
TranslateMessage
ShowWindow
MessageBeep
SetDlgItemTextW
GetDlgItem
SendDlgItemMessageW
DialogBoxParamW
SetForegroundWindow
DefWindowProcW
FillRect
DrawIconEx
GetSysColorBrush
GetSysColor
RegisterWindowMessageW
IsIconic
IsZoomed
EnumWindows
GetWindowTextLengthW
EnableWindow
InvalidateRect
SetLayeredWindowAttributes
SetWindowPos
SetWindowRgn
CountClipboardFormats
SetWindowLongW
ScreenToClient
IsDialogMessageW
SendMessageW
IsWindowEnabled
GetWindowLongW
GetKeyState
TranslateAcceleratorW
KillTimer
PeekMessageW
GetFocus
GetClassNameW
GetWindowThreadProcessId
GetForegroundWindow
GetMessageW
SetTimer
GetParent
GetDlgCtrlID
CharUpperW
IsClipboardFormatAvailable
SetFocus
SetActiveWindow
VkKeyScanExW
EnumChildWindows
CheckMenuItem
GDI32.dll GetPixel
GetClipRgn
GetCharABCWidthsW
SetBkMode
CreatePatternBrush
SetBrushOrgEx
EnumFontFamiliesExW
CreateDIBSection
GdiFlush
SetBkColor
ExcludeClipRect
SetTextColor
GetClipBox
BitBlt
CreateCompatibleBitmap
GetSystemPaletteEntries
GetDIBits
CreateCompatibleDC
CreatePolygonRgn
CreateRectRgn
CreateRoundRectRgn
CreateEllipticRgn
DeleteDC
GetObjectW
GetTextMetricsW
GetTextFaceW
SelectObject
GetStockObject
CreateDCW
CreateSolidBrush
CreateFontW
FillRgn
GetDeviceCaps
DeleteObject
COMDLG32.dll CommDlgExtendedError
GetSaveFileNameW
GetOpenFileNameW
ADVAPI32.dll RegDeleteKeyW
RegSetValueExW
RegCreateKeyExW
RegQueryValueExW
AdjustTokenPrivileges
LookupPrivilegeValueW
OpenProcessToken
CloseServiceHandle
UnlockServiceDatabase
LockServiceDatabase
OpenSCManagerW
GetUserNameW
RegEnumKeyExW
RegEnumValueW
RegQueryInfoKeyW
RegOpenKeyExW
RegCloseKey
RegConnectRegistryW
RegDeleteValueW
SHELL32.dll DragQueryPoint
SHEmptyRecycleBinW
SHFileOperationW
SHGetPathFromIDListW
SHBrowseForFolderW
SHGetDesktopFolder
SHGetMalloc
SHGetFolderPathW
ShellExecuteExW
Shell_NotifyIconW
DragFinish
DragQueryFileW
ExtractIconW
ole32.dll OleInitialize
OleUninitialize
CoCreateInstance
CoInitialize
CoUninitialize
CLSIDFromString
CoGetObject
StringFromGUID2
CreateStreamOnHGlobal
OLEAUT32.dll SafeArrayGetLBound
GetActiveObject
SysStringLen
OleLoadPicture
SafeArrayUnaccessData
SafeArrayGetElemsize
SafeArrayAccessData
SafeArrayUnlock
SafeArrayPtrOfIndex
SafeArrayLock
SafeArrayGetDim
SafeArrayDestroy
SafeArrayGetUBound
VariantCopyInd
SafeArrayCopy
SysAllocString
VariantChangeType
VariantClear
SafeArrayCreate
SysFreeString

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.86108
MD5 a39fb44bf8050f41f6d83455a14d1e66
SHA1 2dd0427450108b59ace3a04792f05415949ae7d5
SHA256 48371b314b0fe0d31d36b0b70b2360930b491b51a099b879d73045add236019c
SHA3 c76ad8953ad38b2d5017109fb4b34294921110d5e43bf4a8bda7b5d9b4b9784e

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37027
MD5 43e1dcd2406d58c8db6a5c02e7999c12
SHA1 83c5d441bd94ec88fb47ae6aa9359a44841b3f17
SHA256 438e452bb673b15eeb4cf0232a116703d211a586889d98d6927915a2fecfd4dc
SHA3 05fcd83f1be53d0b5bc947db45924361cffec22a2367bf3627dfccbceb0808cc

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.67639
MD5 d71b7306acf232a20b51a1222ef1659f
SHA1 50e0c9ddabfb4415198cb3a8487d811e5fcb7637
SHA256 2bc02fc0c6b5c414ac2310c3ad9cb50e7d26ac1991973aa72b8750bcb018c847
SHA3 bc134de925cee2e92a3e2972ea01ab915f1cd8f1a488795fbd7412322b7cb20c

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.84157
MD5 1c93a14c5a485c11350ef568f5e423c1
SHA1 bead6553859c4ec6e647551a19b224dc2357fc5f
SHA256 ae6b56a4aabbeb5d22f508ed6d1522ba6e5b668d1ffb05e4d9cee348a14197cd
SHA3 5719b4dc9bcc5a323c95d760317d4a5b737343f709eee16eddf819e8054ee6dd

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.3349
MD5 266626c8655c67b9530c361ca939f01d
SHA1 4f799d89f7255ef58628605cc0f37a3420925a3d
SHA256 1bfebd87e8f7129fe598c91a87ff03e7962b95af723ea024faf9549e6442aa84
SHA3 85b69f2f4e1bfa507c52634afc60ad29f41321a0a4526654693b1dd7a6f516d9

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.46964
MD5 fbbd1dfd9481f55d0e9ebc890ce09c3c
SHA1 cbfd96b3e1c556af63424b3a153def765077b8fb
SHA256 5ef6e7b16676575434a274b3654dcc6c4934adcb5c86ee31939720568578d2c0
SHA3 108eb4ba2bc3e913cec2e0d5cd215901fb0f4ebffc7fbd7679673ea2c735a609

7

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.56056
MD5 9104d9f5acc220ac5a9a1c29a283e42d
SHA1 7e274a143071c4d7801c07669074cd8fa2972047
SHA256 e773c795d1dbb9bf8cd8f73f12c4f02c047f58dc516be4a629fe807610476917
SHA3 8cd4a3f7555bedc4ecddbcb83b34780f450c902a91ddda511b41f9b6f1c21103

211

Type RT_MENU
Language English - United States
Codepage Latin 1 / Western European
Size 0x2c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37124
MD5 2cfd05e0e8346abd1be8b6933d0684ad
SHA1 898c4f11bceec1fb399cc9e0f305e09b9a2df803
SHA256 c0306fb5f7462e74df09e5e0627c01a238f291bbdc89c24c0ea1f46e7341ab5a
SHA3 8f3778cee4660e3c85805aa4bce2602547080ca7cfc425029bce1441a5af9a1f

205

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82326
MD5 fec66af562e184a3acd4ada5b1603016
SHA1 fe5cd5d19cfc12992d23a18db8edaf1c06f610c2
SHA256 0b54b12fc56db7f7a5a366544081e75cfd312d6db7dd0b298b8088ad2f748908
SHA3 36780025f039a7044aac6d427f489314299b398567b3b737bb5f229278d74563

212

Type RT_ACCELERATOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x48
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.96144
MD5 7fb94687aa0fe2b18873dba5ac59ab1d
SHA1 e19e8d6b0e33da063de27c83fa0bab4058513332
SHA256 86286a59831ad1d0d84eb411ae6fa236b21bca5d3ebfc93a59cf4b6bf1d466d0
SHA3 33011788d35d1127a1ee6fbdb975c0d4ef6b36d3896e0d27d3f75f0ff68e3aec

>AUTOHOTKEY SCRIPT<

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0xeb2b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.03063
MD5 2af39ebba5a474eb8ab89039b70a722d
SHA1 d0b1454726a73fa93634b95b477f33ba959bd2ce
SHA256 eccb49fac228abf925824f50e1991d1dc4a5a09e4eef1267f99f17b197f430cb
SHA3 a326d90693e7d703e0e145c0bbf50290c02a2b6105500f666821bec275179901

AUTOHOTKEY.EXE

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x122600
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.41196
Detected Filetype PE Executable
MD5 b7f69206ce622662cf399c3d4e847d7b
SHA1 dcd85a655bba6a444da2dfe026f19ce8418a805f
SHA256 f8f74facb797dc8d7f8702efc12cd005aebc157268e7f39acac17f5d99991a20
SHA3 e2374656cbe417f7392835a92f913ac5ab21f24800e88801004340019bec20bd

159

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.45849
Detected Filetype Icon file
MD5 dafef03caf7d734f3b3109544d379061
SHA1 38346ec865640b6f3fff23486d584ed75daf36b2
SHA256 3c56cd7df93d9db479214fe27416c1e6fb7def4aa7be334f5f191bcff395674c
SHA3 f33c3b7db100d2e8cd39d715a1ada8d8c7595baaab95d8a26658133740031c9c

160

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.02322
Detected Filetype Icon file
MD5 6a368971d47678239d334269be28300e
SHA1 9fcfe92b319b372d6d59c9096cf13e9662e8299f
SHA256 45de95e2bc9da2d99016c89cba3816940f7ddb7f044c6d34b5f5c168c3b638ff
SHA3 10b30bfdab83169af38b453132bc26884230b58321aab1e2ebd88135cfae8457

206

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.9815
Detected Filetype Icon file
MD5 40c1414025bcc34e7ba97fd22bc9f5a4
SHA1 b53a6a13513b5205cef6fc6d7556ad80d8b62173
SHA256 d6659139f55adad2497df8d1a11fcd68324a00ccdadbc133ddd49fb79e9ccc1c
SHA3 88c00f73975983695c16e34c6a1750573250999152f5399a198b799e76349720

207

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0815
Detected Filetype Icon file
MD5 9b2193af49fdb53892356f594e9f18b9
SHA1 448aa28721dd65475b37505de8140d88d5aa1501
SHA256 9b8ca9c6a330d0d17d1108ab5442d60ea574817a65caa860cceb24313cc4f0e4
SHA3 46527c3333b02958fd025cfdaa12d481f8505aa77c1cd0b5f15348e870530116

208

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0815
Detected Filetype Icon file
MD5 5f51cbb6145d3a4c36cffa3b028b0199
SHA1 b2bbd2afcfa1c44725bf90df8948792d3bc7fb97
SHA256 fbb52a958caa73dce023ce27649d69f8886e86b5706e767153c41dde7b5eebf9
SHA3 93f253b05e0e42147b5a9000d421c3e105df42f9fafae5147c4e9a09958e3f79

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x1fc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24882
MD5 a5e3d47cb56992ea7eafb3530d92ba6f
SHA1 b8bb8ec8e16af35cf86500c88cc4106cdf9db690
SHA256 9d65d3db120876a309091799878a5aa74f3aec9bb5af8070c7b00477a0f5bc92
SHA3 9a7483a70d0e180c71956c30ba317cbdef7f73399137e9327000301f4f7c9d75

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x487
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.33598
MD5 860e627ae4633ebb9326e5a97f4c6cbd
SHA1 a2a09d7cc70c02b32b872c87d1a4817275cdca54
SHA256 29683761de7899822f4792623368bab484d93e2077fa91fc48c9d75a9d0228c7
SHA3 8407bd21860ad62fb4fadb9c8d3081ce755f71d75155c1d16ecddafe1bd8d94c

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.1.30.3
ProductVersion 1.1.30.3
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
FileVersion (#2) 1.1.30.03
ProductVersion (#2) 1.1.30.03
Resource LangID English - United States

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2019-Apr-04 21:13:43
Version 0.0
SizeofData 948
AddressOfRawData 0xf083c
PointerToRawData 0xef83c

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2019-Apr-04 21:13:43
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x14010f000
EndAddressOfRawData 0x14010f008
AddressOfIndex 0x1401008f8
AddressOfCallbacks 0x1400c4f40
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x94
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1400fd018

RICH Header

XOR Key 0xc5a45a01
Unmarked objects 0
241 (40116) 19
243 (40116) 140
242 (40116) 23
ASM objects (VS2015 UPD3 build 24123) 8
C++ objects (VS2015 UPD3 build 24123) 40
C objects (VS2015 UPD3 build 24123) 20
C objects (VS2008 SP1 build 30729) 6
135 (VS2008 SP1 build 30729) 1
Imports (VS2008 SP1 build 30729) 27
Total imports 462
ASM objects (VS2015 UPD3 build 24210) 2
C++ objects (LTCG) (VS2015 UPD3.1 build 24215) 42
Resource objects (VS2015 UPD3 build 24210) 1
Linker (VS2015 UPD3.1 build 24215) 1

Errors

Leave a comment

No comments yet.