550f003b3cd9b51a87a11cf90f8fc7253960e7bf7e1967a578fe74e2507dddeb

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2023-Apr-14 20:20:42
TLS Callbacks 2 callback(s) detected.
Debug artifacts Embedded COFF debugging symbols

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentVersion\Run
Miscellaneous malware strings:
  • Virus
Contains domain names:
  • google.com
  • www.google.com
Suspicious The PE is possibly packed. Unusual section name found: /4
Unusual section name found: .xdata
Unusual section name found: /14
Unusual section name found: /29
Unusual section name found: /41
Unusual section name found: /55
Unusual section name found: /67
Unusual section name found: /78
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • FindWindowA
Can access the registry:
  • RegCloseKey
  • RegOpenKeyExA
  • RegSetValueExA
Possibly launches other programs:
  • system
  • ShellExecuteA
Suspicious The file contains overlay data. 34390 bytes of data starting at offset 0x7c00.
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 be17becf664ecadbaf8d8ebadddbe596
SHA1 a2152290ba816a6848d1a35c8ca19924ea7020e9
SHA256 550f003b3cd9b51a87a11cf90f8fc7253960e7bf7e1967a578fe74e2507dddeb
SHA3 6ab6803c771026572ba07e62fa437859ec17a8f210ab78d0dd6351002337de0d
SSDeep 768:8jOxF/MaRwSEIbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbpJzhmm5QlFamQNkfD5:zxFpRwSV/m4KFakl
Imports Hash e03e086ab19f113331e51d559aa7f39a

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 17
TimeDateStamp 2023-Apr-14 20:20:42
PointerToSymbolTable 0x7c00
NumberOfSymbols 1509
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 2.0
SizeOfCode 0x2a00
SizeOfInitializedData 0x5c00
SizeOfUninitializedData 0x400
AddressOfEntryPoint 0x0000000000001125 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x14000
SizeOfHeaders 0x600
Checksum 0x1d055
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 ba452c107b7c6515905e512bcdbbde53
SHA1 2230afdd58243f4d9ad4557e4d1e492591337710
SHA256 2530d3fd1b46ab062ccb41a0a65b8dbeb77efb23711f077698be908274e248ac
SHA3 e569f4708dc76e7ca8d166936fe5a28d9bddae75e991733cee8aff6ef49dc34c
VirtualSize 0x2830
VirtualAddress 0x1000
SizeOfRawData 0x2a00
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.47021

.data

MD5 c9c4b9fc7fdd39f7cb967aa786f138ee
SHA1 3e2be3aa6f2493adf44d77b42f20982d408855c9
SHA256 d7116cacff15aff66661f92d68e35fccb03475f456383c7b8ab2a93e343c77dd
SHA3 0f15aa533f256ca3d2ace872f2172ca6a80a9dd71ac10ff5d650cfd5892dd512
VirtualSize 0x550
VirtualAddress 0x4000
SizeOfRawData 0x600
PointerToRawData 0x3000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.659054

.rdata

MD5 2766bd28a55f5b9d883df86891bf7ace
SHA1 f52157fc20be3296bfa885849c68af6e729ab204
SHA256 5291a9ad88f5aa3c6f6fef8305d04299ceb8327dcee271baa622e4f0cf925163
SHA3 8bbe76b9e63152d2076e899ad14d4fbd56e0003179ad8eaecbdb99d3c0e6c08e
VirtualSize 0xfc8
VirtualAddress 0x5000
SizeOfRawData 0x1000
PointerToRawData 0x3600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.09797

/4

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x4
VirtualAddress 0x6000
SizeOfRawData 0x200
PointerToRawData 0x4600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.pdata

MD5 fc889dfa4adc47fbf71632e88d4a56c6
SHA1 a88ebb1ffc1f8abecb0460f17ee62feb179fcfbf
SHA256 55385824d9a59117ffedd37fb5d43ac1ed0e75698bac1d7b97048af97ae51404
SHA3 358b0db439326b56839dfcc60e06309f823444d6b8f051a150d4af5e02fc5c91
VirtualSize 0x2f4
VirtualAddress 0x7000
SizeOfRawData 0x400
PointerToRawData 0x4800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.21985

.xdata

MD5 7d8084ff459f8d5a4e4fc60168791d42
SHA1 1a9486b01efe597a50dc2deadb1140eccd85fce7
SHA256 5cac0eb63b6857d014881c6e38b0e5d1f9db1aa5df507008e26ecdf74105cb77
SHA3 23d29097d093337003ede59ad0d398ddd2f6047bf4d9d3f494d75f7836aa9806
VirtualSize 0x300
VirtualAddress 0x8000
SizeOfRawData 0x400
PointerToRawData 0x4c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.16733

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x220
VirtualAddress 0x9000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 5b35649e1fa94058f8a3b8972b535d38
SHA1 80bb41d4283642b06b732660bcdf73081f3bfc94
SHA256 ebf66d3e83bb39a9d790ec2f68a3ac7d88dd25993e7cbf07c58e1553f35415e1
SHA3 9f0e799f488ff8d09556fee312ddfe9f2fd5c8f8870adf37b93d8bf967ef63ed
VirtualSize 0xa48
VirtualAddress 0xa000
SizeOfRawData 0xc00
PointerToRawData 0x5000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.69952

.CRT

MD5 0bdc7162fc630f68ac31ff38dc031445
SHA1 f4399b455c29377c9be46d5829486382bf5953b6
SHA256 850822115b544554d3c1f71436425c67607adea2d5b4234bcec601ab380a4a98
SHA3 db4bbc2aee6bb527bda3972978184876426b947fed291245ff31e18a7255b032
VirtualSize 0x60
VirtualAddress 0xb000
SizeOfRawData 0x200
PointerToRawData 0x5c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.290466

.tls

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0xc000
SizeOfRawData 0x200
PointerToRawData 0x5e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.reloc

MD5 ecb4c005d45be486943fb6be6da99b58
SHA1 40aeedcce7d99fc110fea918475152fb6650891a
SHA256 9f3a719b436e48ac0b62da077b2f9976b08a23d2f8c3c8fe3e48e819fd972c32
SHA3 b356f7757c11d6589042a56748d34df74ee88d5a437ed0fde00e8789e0d334cc
VirtualSize 0x84
VirtualAddress 0xd000
SizeOfRawData 0x200
PointerToRawData 0x6000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.50896

/14

MD5 05f845554c2cf747962b4bb5b3403aae
SHA1 739da2c7cf6995280cd35a8395bf717d3b9a8220
SHA256 e8695b4875ba3c0ecc3ccde6c8d165c89350d22a23095e456a8ed3ce7c8eb770
SHA3 6aea9a42c1e83cdd1ea1347f94151f31735e796e61cc5e0700a9061dc8b7dde2
VirtualSize 0x50
VirtualAddress 0xe000
SizeOfRawData 0x200
PointerToRawData 0x6200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.236539

/29

MD5 c12f285ddf54be39ab0504411ebac707
SHA1 e5be26e0ffd5b918e3320ce470a224353a0d4ba0
SHA256 efc759b69b5436b0d63dfef81c54df79ff4dddf701cdc9520148f01565ae9d2d
SHA3 b5e8c5c992f0dfedf57134311cea9b8776ab20e33910ab85c2959ad47230fc01
VirtualSize 0xf45
VirtualAddress 0xf000
SizeOfRawData 0x1000
PointerToRawData 0x6400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.20653

/41

MD5 3926a4e9348a2d2f293d468143da249a
SHA1 427b6ff38a8342550083c4131e1639c4076334f7
SHA256 a50238fc47f9f54df2bd53a74f1ef7318b6bc09d391ab0ed61687bdb5bad4c57
SHA3 7b27c0ca26b6f05e9ed4accdb48fc14b8cd39065d5470d1cf1ab954f53708a4a
VirtualSize 0xaf
VirtualAddress 0x10000
SizeOfRawData 0x200
PointerToRawData 0x7400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 2.12863

/55

MD5 9aebd18a0496c3c7aa8f26359257f1a5
SHA1 455067cad6fe00b36068bf2c9e764aa1427ab83a
SHA256 99043fce7f8c85ae36dca8b6525b31be75456bf99cb39307e56b54c42c0dd14d
SHA3 48acc563342e4d0e281da8044a9567c85c3c8b508bbdeb4ca4204738c16a34d7
VirtualSize 0xa4
VirtualAddress 0x11000
SizeOfRawData 0x200
PointerToRawData 0x7600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.47729

/67

MD5 e33b7706239a9f56b2244507f16f58f4
SHA1 e316a1b678361eef8392123d232ed3e67e12b11b
SHA256 22123714d197987ed8aa1643be594e82d6e313f38b9b728bc052c7665382b368
SHA3 0745a842ef051885a715c660a35bac0d35c793ff4ff885f81176904bae705fd0
VirtualSize 0x7f
VirtualAddress 0x12000
SizeOfRawData 0x200
PointerToRawData 0x7800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.97604

/78

MD5 426c3b5acc6343c3572de8960568c3c0
SHA1 b76188ace41281db889010d90516e7a619e6f279
SHA256 65a0c99cefa43184e860af0e622dcd23aa76da5b68c10c95d97197b4491f7eef
SHA3 e25a3cb87016cda9798822ae289c0074e1f58b8c6696df357ead5c525b8ce896
VirtualSize 0x183
VirtualAddress 0x13000
SizeOfRawData 0x200
PointerToRawData 0x7a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.18362

Imports

libstdc++-6.dll _ZNSt8ios_base4InitC1Ev
_ZNSt8ios_base4InitD1Ev
_ZSt4cout
_ZStlsISt11char_traitsIcEERSt13basic_ostreamIcT_ES5_PKc
ADVAPI32.dll RegCloseKey
RegOpenKeyExA
RegSetValueExA
KERNEL32.dll Beep
CopyFileA
CreateThread
DeleteCriticalSection
EnterCriticalSection
FreeLibrary
GetLastError
GetModuleFileNameA
GetModuleHandleA
GetProcAddress
GetStartupInfoA
GetSystemDirectoryA
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryA
SetUnhandledExceptionFilter
Sleep
TlsGetValue
VirtualProtect
VirtualQuery
msvcrt.dll __C_specific_handler
__getmainargs
__initenv
__iob_func
__set_app_type
__setusermatherr
_acmdln
_amsg_exit
_cexit
_commode
_fmode
_initterm
_onexit
_time64
abort
calloc
exit
fprintf
free
fwrite
malloc
memcpy
memset
rand
signal
srand
strlen
strncmp
system
vfprintf
SHELL32.dll ShellExecuteA
USER32.dll BlockInput
FindWindowA
PostMessageA
SendMessageA
SetCursorPos
SetWindowTextA
ShowWindow

Delayed Imports

Version Info

TLS Callbacks

StartAddressOfRawData 0x14000c000
EndAddressOfRawData 0x14000c008
AddressOfIndex 0x140009100
AddressOfCallbacks 0x14000b038
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks 0x0000000140001FD0
0x0000000140002090

Load Configuration

RICH Header

Errors

[*] Warning: Tried to read outside the COFF string table to get the name of section /4! [*] Warning: Tried to read outside the COFF string table to get the name of section /14! [*] Warning: Tried to read outside the COFF string table to get the name of section /29! [*] Warning: Tried to read outside the COFF string table to get the name of section /41! [*] Warning: Tried to read outside the COFF string table to get the name of section /55! [*] Warning: Tried to read outside the COFF string table to get the name of section /67! [*] Warning: Tried to read outside the COFF string table to get the name of section /78! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF String Table's reported size is bigger than the remaining bytes! [*] Warning: Section .bss has a size of 0!
Leave a comment

No comments yet.