52ef1d645c83b779784db3761d9c77a0107ae46c4c556cb9d913a6505dc08484

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1970-Jan-01 00:00:00
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.

Plugin Output

Suspicious PEiD Signature: HQR data file
Info Interesting strings found in the binary: Contains domain names:
  • -golang.org
  • .eq.github.com
  • .eq.golang.org
  • .github.com
  • .golang.org
  • .hash.github.com
  • .hash.golang.org
  • .hash.net
  • 0github.com
  • 3github.com
  • Gone.pngQuitMenu.com
  • RetroUSB.com
  • aia.ws.symantec.com
  • crl.thawte.com
  • crl.ws.symantec.com
  • d.symcb.com
  • dejavu.sourceforge.net
  • emojione.com
  • eq.github.com
  • eq.golang.org
  • github.com
  • golang.org
  • google.com
  • hash.github.com
  • hash.golang.org
  • http://crl.thawte.com
  • http://crl.thawte.com/ThawteTimestampingCA.crl0
  • http://dejavu.sourceforge.net
  • http://dejavu.sourceforge.net/wiki/index.php/License
  • http://emojione.com
  • http://emojione.comEmojiOne
  • http://ocsp.thawte.com0
  • http://s.symcb.com
  • http://s.symcb.com/pca3-g5.crl0
  • http://s.symcd.com0_
  • http://scripts.sil.org
  • http://scripts.sil.org/OFL
  • http://sw.symcb.com
  • http://sw.symcb.com/sw.crl0
  • http://sw.symcd.com0
  • http://sw.symcd.com0'
  • http://sw1.symcb.com
  • http://sw1.symcb.com/sw.crt0
  • http://ts-aia.ws.symantec.com
  • http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
  • http://ts-crl.ws.symantec.com
  • http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
  • http://ts-ocsp.ws.symantec.com07
  • http://www.google.com
  • http://www.google.com/get/noto/http
  • http://www.monotype.com
  • http://www.monotype.com/studioThis
  • http://www.w3.org
  • http://www.w3.org/1999/xlink
  • http://www.w3.org/2000/svg
  • http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd
  • http://www.w3.org/XML/1998/namespacexml
  • https://d.symcb.com
  • https://d.symcb.com/cps0%
  • https://d.symcb.com/rpa0
  • https://d.symcb.com/rpa0+
  • monotype.com
  • pngQuitMenu.com
  • s.symcb.com
  • scripts.sil.org
  • sourceforge.net
  • sw.symcb.com
  • sw1.symcb.com
  • symantec.com
  • symcb.com
  • thawte.com
  • ts-aia.ws.symantec.com
  • ts-crl.ws.symantec.com
  • ws.symantec.com
  • www.google.com
  • www.monotype.com
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious VirusTotal score: 2/71 (Scanned on 2026-10-10 14:35:22) McAfeeD: ti!52EF1D645C83
Trapmine: malicious.moderate.ml.score

Hashes

MD5 faf25869d90a2b8c860b6bcd1a800d2e 🔍
SHA1 a05c6b36433f61ac3c4614baeda079456ee35b4a 🔍
SHA256 52ef1d645c83b779784db3761d9c77a0107ae46c4c556cb9d913a6505dc08484 🔍
SHA3 b15065632e9ee3ee1798747d614c8817d68df818681e035a2c6fc4154aae4183 🔍
SSDeep 393216:liMjy3BFLS7B3Zdp1uPGiSPWw1Jvg2gkoVM4M:liMjOPm7Vfp1uVS+w1Vi 🔍
Imports Hash 903cde1e95c31a1da1bbfeb3e9a2c3c5 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 11
TimeDateStamp 1970-Jan-01 00:00:00
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 2.0
SizeOfCode 0x80ee00
SizeOfInitializedData 0xfd2a00
SizeOfUninitializedData 0x99400
AddressOfEntryPoint 0x00000000000013D0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 0.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0x1882000
SizeOfHeaders 0x400
Checksum 0x17e5a42
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 bea4b687d9956a86178ab574e9093633 🔍
SHA1 36ebd7e35ed4123b8d581a6a290e9ecd4d61bed8 🔍
SHA256 4755d56219816616ae34b211da34ed0d5ebc5f95752b57be7df23f803f334595 🔍
SHA3 1f57aa792446e032d41173681323f6ea00e8cbd8ff0a5fbe5c865ef8fae92981 🔍
VirtualSize 0x80eda0
VirtualAddress 0x1000
SizeOfRawData 0x80ee00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.22614

.data

MD5 1527844874f16281232284e31f5de2be 🔍
SHA1 09b2c4cf6497bf41c1253c89c6d89767e1c4ebb3 🔍
SHA256 bca92afe57ae343e8eeca210db113798cb71bba6db5f4cb80f584e3b94e68148 🔍
SHA3 f0b601c3e7c5d42452dbf108789cf609752f915f96dbb47ebc633049e5b83e3e 🔍
VirtualSize 0x78f720
VirtualAddress 0x810000
SizeOfRawData 0x78f800
PointerToRawData 0x80f200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.06345

.rdata

MD5 0c0b050f388fd48ca0ec47d7e4445877 🔍
SHA1 a9b36665b03bfa99c00c8f03c4d76f2f59f3a211 🔍
SHA256 d43dc8539f6eb94e6081b4f167536f240adf9ae8801fd5fc36b89a07c468fd6f 🔍
SHA3 097da5cf5e9bd4cc83154eae633ce63cdaf0e9eb7897ffe65bd40d6f2244808d 🔍
VirtualSize 0x7d21b0
VirtualAddress 0xfa0000
SizeOfRawData 0x7d2200
PointerToRawData 0xf9ea00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.63246

.pdata

MD5 f5be567ee75b457eb194767f2d00c942 🔍
SHA1 c6dd1edea068fbcd44e0f83b3e2614f0bf7b6d84 🔍
SHA256 d462723ef14ebb3c1cb0a08cffa06c8a10a7800548b8487501976147af5dfe1a 🔍
SHA3 73669cb62d997cee6a56e51352912bb2c341413c44fd926c50aec0c201a89bc2 🔍
VirtualSize 0x36930
VirtualAddress 0x1773000
SizeOfRawData 0x36a00
PointerToRawData 0x1770c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.01196

.xdata

MD5 134a2ee66063494efe1e5e9905967744 🔍
SHA1 efaf94c15b1b5f50e5c17b6194da0d6bdf0b88d1 🔍
SHA256 82393aaf60ca2bff9b68cd24ed10b5b0b4a40e310636ea66c448ad24205a4662 🔍
SHA3 36932e28d4de925fe05a09388c96143775a215ad4875b99f78acbec6013cc042 🔍
VirtualSize 0x5418
VirtualAddress 0x17aa000
SizeOfRawData 0x5600
PointerToRawData 0x17a7600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.82565

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍
VirtualSize 0x992b0
VirtualAddress 0x17b0000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.edata

MD5 e04ec72725515233c0c465cee16cc51a 🔍
SHA1 86220fcc623d423ff5e24aa3e750f884f8088019 🔍
SHA256 6f6c9af8a678f6286406668894e76335f986a6c5cfc25a3ef5087b3eef837725 🔍
SHA3 46b06b8520a2a3c100b10985734b1d8fd954500e08bdc41f90d6d43fbb34531d 🔍
VirtualSize 0x259
VirtualAddress 0x184a000
SizeOfRawData 0x400
PointerToRawData 0x17acc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.8116

.idata

MD5 fe39a0f454a12a4bb7fc9a5b41b7f59e 🔍
SHA1 4aa7db5adf04768b861a79a84c7cffbde22ff0ca 🔍
SHA256 23af753efaba80a44e201221472bb59cdc314308f696a7f3740dbad07c88e78a 🔍
SHA3 7a0030257e6eecc3287b1cfb9f4a99a8203d75cd121d33015f7ac7c50ba9c312 🔍
VirtualSize 0x2268
VirtualAddress 0x184b000
SizeOfRawData 0x2400
PointerToRawData 0x17ad000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.85218

.tls

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x10
VirtualAddress 0x184e000
SizeOfRawData 0x200
PointerToRawData 0x17af400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 35aced31363681f5abc551313f3c2332 🔍
SHA1 711f718881181c5d589fedeeb5d4192313a094b7 🔍
SHA256 a146c62e00a746c8ef4fc7a2913b297088976b0261eb516bbc9793b223d0974c 🔍
SHA3 32e6ddc064dd30f1144f745247fcbdd111b0e84c85d668f9a2bfaba74ca2c9da 🔍
VirtualSize 0xbb68
VirtualAddress 0x184f000
SizeOfRawData 0xbc00
PointerToRawData 0x17af600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.9566

.reloc

MD5 8accdcade3045e9b9dcfebcb98b778a6 🔍
SHA1 ec2b10ce129a8ee55a6256384547d0ab42b15aa0 🔍
SHA256 57d1eca3e8abbed8ee2dd56ce2bd4a2ba65b3f8a898a1c2d8f84e55d80842450 🔍
SHA3 caf8a081e468d86135522114169e99b9f37b20626045f66239c4b88a2d04d897 🔍
VirtualSize 0x269c4
VirtualAddress 0x185b000
SizeOfRawData 0x26a00
PointerToRawData 0x17bb200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.43983

Imports

GDI32.dll ChoosePixelFormat
CreateBitmap
CreateDCW
CreateDIBSection
CreateRectRgn
DeleteDC
DeleteObject
DescribePixelFormat
GetDeviceCaps
GetDeviceGammaRamp
SetDeviceGammaRamp
SetPixelFormat
SwapBuffers
KERNEL32.dll AddVectoredContinueHandler
AddVectoredExceptionHandler
CloseHandle
CreateEventA
CreateFileA
CreateIoCompletionPort
CreateThread
CreateWaitableTimerExW
DeleteCriticalSection
DuplicateHandle
EnterCriticalSection
ExitProcess
FormatMessageW
FreeEnvironmentStringsW
FreeLibrary
GetConsoleMode
GetCurrentThreadId
GetEnvironmentStringsW
GetErrorMode
GetLastError
GetModuleHandleExW
GetModuleHandleW
GetProcAddress
GetProcessAffinityMask
GetQueuedCompletionStatusEx
GetStdHandle
GetSystemDirectoryA
GetSystemInfo
GetThreadContext
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
InitializeCriticalSection
IsDBCSLeadByteEx
LeaveCriticalSection
LoadLibraryA
LoadLibraryExW
LoadLibraryW
MultiByteToWideChar
PostQueuedCompletionStatus
QueryPerformanceCounter
QueryPerformanceFrequency
RaiseFailFastException
ResumeThread
RtlLookupFunctionEntry
RtlVirtualUnwind
SetConsoleCtrlHandler
SetErrorMode
SetEvent
SetProcessPriorityBoost
SetThreadContext
SetThreadExecutionState
SetUnhandledExceptionFilter
SetWaitableTimer
Sleep
SuspendThread
SwitchToThread
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
VerSetConditionMask
VirtualAlloc
VirtualFree
VirtualProtect
VirtualQuery
WaitForMultipleObjects
WaitForSingleObject
WerGetFlags
WerSetFlags
WideCharToMultiByte
WriteConsoleW
WriteFile
__C_specific_handler
msvcrt.dll ___lc_codepage_func
___mb_cur_max_func
__getmainargs
__initenv
__iob_func
__set_app_type
__setusermatherr
_amsg_exit
_beginthread
_cexit
_commode
_errno
_fmode
_initterm
_lock
_onexit
_wassert
_unlock
abort
calloc
exit
fprintf
fputc
free
fwrite
getc
isspace
isxdigit
ldexp
localeconv
malloc
memcpy
memmove
memset
qsort
realloc
signal
strcmp
strcpy
strcspn
strerror
strlen
strncmp
strncpy
strspn
strstr
strtok
strtol
strtoul
tolower
ungetc
vfprintf
wcscmp
wcscpy
wcslen
_strtoui64
_strtoi64
OPENGL32.dll wglGetProcAddress
SHELL32.dll DragAcceptFiles
DragFinish
DragQueryFileW
DragQueryPoint
USER32.dll AdjustWindowRectEx
BringWindowToTop
ChangeDisplaySettingsExW
ClientToScreen
ClipCursor
CloseClipboard
CreateIconIndirect
CreateWindowExW
DefWindowProcW
DestroyIcon
DestroyWindow
DispatchMessageW
EmptyClipboard
EnumDisplayDevicesW
EnumDisplayMonitors
EnumDisplaySettingsExW
EnumDisplaySettingsW
FlashWindow
GetActiveWindow
GetClassLongPtrW
GetClientRect
GetClipboardData
GetCursorPos
GetDC
GetKeyState
GetLayeredWindowAttributes
GetMessageTime
GetMonitorInfoW
GetPropW
GetRawInputData
GetRawInputDeviceInfoA
GetRawInputDeviceList
GetSystemMetrics
GetWindowLongW
GetWindowPlacement
GetWindowRect
IsIconic
IsWindowVisible
IsZoomed
LoadCursorW
LoadImageW
MapVirtualKeyW
MonitorFromWindow
MoveWindow
MsgWaitForMultipleObjects
OffsetRect
OpenClipboard
PeekMessageW
PostMessageW
PtInRect
RegisterClassExW
RegisterDeviceNotificationW
RegisterRawInputDevices
ReleaseCapture
ReleaseDC
RemovePropW
ScreenToClient
SendMessageW
SetCapture
SetClipboardData
SetCursor
SetCursorPos
SetFocus
SetForegroundWindow
SetLayeredWindowAttributes
SetPropW
SetRect
SetWindowLongW
SetWindowPlacement
SetWindowPos
SetWindowTextW
ShowWindow
SystemParametersInfoW
ToUnicode
TrackMouseEvent
TranslateMessage
UnregisterClassW
UnregisterDeviceNotification
WaitMessage
WindowFromPoint

Delayed Imports

_cgo_dummy_export

Ordinal 1
Address 0x18486d0

glowDebugCallback_gl21

Ordinal 2
Address 0x7e80d0

goCharCB

Ordinal 3
Address 0x7d3560

goCharModsCB

Ordinal 4
Address 0x7d35b0

goCursorEnterCB

Ordinal 5
Address 0x7d3430

goCursorPosCB

Ordinal 6
Address 0x7d33d0

goDropCB

Ordinal 7
Address 0x7d3610

goErrorCB

Ordinal 8
Address 0x7d32c0

goFramebufferSizeCB

Ordinal 9
Address 0x7d3780

goJoystickCB

Ordinal 10
Address 0x7d3320

goKeyCB

Ordinal 11
Address 0x7d34e0

goMonitorCB

Ordinal 12
Address 0x7d3670

goMouseButtonCB

Ordinal 13
Address 0x7d3370

goScrollCB

Ordinal 14
Address 0x7d3480

goWindowCloseCB

Ordinal 15
Address 0x7d37e0

goWindowContentScaleCB

Ordinal 16
Address 0x7d3950

goWindowFocusCB

Ordinal 17
Address 0x7d38b0

goWindowIconifyCB

Ordinal 18
Address 0x7d3900

goWindowMaximizeCB

Ordinal 19
Address 0x7d3820

goWindowPosCB

Ordinal 20
Address 0x7d36c0

goWindowRefreshCB

Ordinal 21
Address 0x7d3870

goWindowSizeCB

Ordinal 22
Address 0x7d3720

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2c5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.63042
Detected Filetype PNG graphic file
MD5 2bc171330f0b654b12b06874c2a77b66 🔍
SHA1 1d96e91307f9942c1f4ff04df218bcff7b3c24f9 🔍
SHA256 689b920aa0c7e41a95b9015977168f0870643c0275224fffe15125984d802e99 🔍
SHA3 0ce0f78ef90a00ba2caf276d4ac95dcac791db5cd264fccd75c2a390b7adfde9 🔍

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4f6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.77926
Detected Filetype PNG graphic file
MD5 a9a0bf90fd1074616920b783ef6a4656 🔍
SHA1 297eaac22d0fd01dee843cc817fbfeea9494d5f6 🔍
SHA256 37850a9d3fff6f99c167a93eb76a6e8fd1754f8f2c83b6120cf9b426ebc46539 🔍
SHA3 d8c9b3e124c8e43a126d34c57813dab722dea927f83bfda28715e835db2ad95d 🔍

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x790
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87257
Detected Filetype PNG graphic file
MD5 84c0e70ff99afd1578a8d7276b3744b8 🔍
SHA1 e24e5bde1e87eeae28aea1fd8ebe123f81254e76 🔍
SHA256 2ae427a17967310254a39cce169eb43f4ce5060b52c30d0d7d0be11df6fe832b 🔍
SHA3 c155449fdc2c16bf13df5d85725b8855c5dd9d40657b0f01b9d9e9d63fe88707 🔍

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xce0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.90457
Detected Filetype PNG graphic file
MD5 c426b4af642a4bca16839bdd01c3e42a 🔍
SHA1 b3d9b6d71a3250c62bee4468a456c08acc4dc1d9 🔍
SHA256 01f78a9006c2b82dca9a626596b184bf68c7ac86d5fd964c4cc791f5fa630716 🔍
SHA3 0dea8bdc5a6351727178a28a2b49278ad396a1e8b5173af06a7afff571e8ccb7 🔍

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x11f2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92469
Detected Filetype PNG graphic file
MD5 4efae5d702e8d56dc44a910c99176163 🔍
SHA1 91cf4c048e91a8fea7aa755eb44ca7b81d48e0aa 🔍
SHA256 bf63f5e7a993025d035ba8586da52aa4031d7ad73e51bfe544be01a927925327 🔍
SHA3 5245b3d6d44f767ebe474ad5addf3dc5b8922a0ce3e2b7ae6d1854f3b107600f 🔍

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2ae7
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.96287
Detected Filetype PNG graphic file
MD5 0661c0b9bc1b62d3ef9f133968e69fdd 🔍
SHA1 62c763dd3a337cc885133da9694985d32f605b7d 🔍
SHA256 58be545a8c00d28946d2c2d6a9d886736199802de43b64b150a63939d24323df 🔍
SHA3 2f548991dd77c2105bad4840e97adb1d83c549fb2c0563a6f4ed52eb40dbc251 🔍

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x6029
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97212
Detected Filetype PNG graphic file
MD5 4f9ce5c143b31731d2bc9e513af642f2 🔍
SHA1 fa785262b77cb7c2fccafa52c688e533d572e7ce 🔍
SHA256 1480ee46b6603d5990f4ef8373bf270be44208e239a9f0058c42a43678a9c343 🔍
SHA3 7b2900e7f083372f6b6629124f35e19867a74331e7c9fbd6a8a80b8c310ffa78 🔍

1 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.91401
Detected Filetype Icon file
MD5 6a71061ff1a1bf1399fcee2a3068e74b 🔍
SHA1 e80ec238eb6882cb4181476dc52441e58bad0282 🔍
SHA256 d3afbaf42b818fdc3760f342e719609a149487eb6ce6ca086493503072a1d2a0 🔍
SHA3 83ce087987acc3263c13a85f745832a75d2fd1ab5671df1f03a4fee6c9530042 🔍

Version Info

TLS Callbacks

StartAddressOfRawData 0x14184e000
EndAddressOfRawData 0x14184e008
AddressOfIndex 0x14184918c
AddressOfCallbacks 0x141772188
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks 0x000000014080D5F0
0x000000014080D5C0

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0!
Leave a comment

No comments yet.