| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1970-Jan-25 06:32:32 |
| Detected languages |
English - United States
|
| TLS Callbacks | 2 callback(s) detected. |
| Suspicious | PEiD Signature: | ASPack v2.12 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
| Suspicious | The PE is possibly packed. |
Section .text is both writable and executable.
Section .rsrc is both writable and executable. Unusual section name found: \xe0\x14\x00\x00\xa3u" Section \xe0\x14\x00\x00\xa3u" is both writable and executable. |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 63/71 (Scanned on 2026-06-25 09:53:11) |
ALYac:
Win32.VJadtre.3
APEX: Malicious AVG: Other:Malware-gen [Trj] Acronis: suspicious AhnLab-V3: Win32/VJadtre.Gen Alibaba: Virus:Win32/Nimnul.402c Antiy-AVL: Virus/Win32.Nimnul.f Arcabit: Win32.VJadtre.3 Avast: Other:Malware-gen [Trj] Avira: W32/Jadtre.B BitDefender: Win32.VJadtre.3 Bkav: W32.FamVT.DumpModuleInfectiousNME.PE CTX: exe.unknown.vjadtre ClamAV: Win.Malware.Wapomi-10020301-0 CrowdStrike: win/malicious_confidence_100% (D) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS DrWeb: BackDoor.Darkshell.246 ESET-NOD32: Win32/Wapomi.BA virus Elastic: malicious (high confidence) Emsisoft: Win32.VJadtre.3 (B) F-Secure: Malware.W32/Jadtre.B Fortinet: W32/CoinMiner.EC2B!tr GData: Win32.Virus.Wapomi.A Google: Detected Gridinsoft: Trojan.Heur!.03202301 Ikarus: Virus.Win32.Wapomi Jiangmin: Win32/Nimnul.f K7AntiVirus: Virus ( 0040f7441 ) K7GW: Virus ( 0040f7441 ) Kaspersky: Virus.Win32.Nimnul.f Kingsoft: Win32.Nimnul.f.168959 Malwarebytes: Malware.AI.143219663 MaxSecure: Virus.Nimnul.F McAfeeD: Real Protect-LS!19667F6B6C67 MicroWorld-eScan: Win32.VJadtre.3 Microsoft: Virus:Win32/Mikcer.B NANO-Antivirus: Trojan.Win32.Banload.cstqaj Panda: W32/Pcarrier.A Rising: Virus.Wapomi!1.9E10 (CLASSIC) Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Malicious PE Skyhigh: BehavesLike.Win32.Infected.dz Sophos: W32/Nimnul-A Symantec: W32.Wapomi.C!inf TACHYON: Virus/W32.Ramnit.C Tencent: Virus.Win32.Loader.aab Trapmine: malicious.high.ml.score TrellixENS: W32/Kudj TrendMicro: PE_WAPOMI.BM TrendMicro-HouseCall: PE_WAPOMI.BM VBA32: Virus.Nimnul.19209 VIPRE: Win32.VJadtre.3 Varist: W32/PatchLoad.E ViRobot: Win32.Ramnit.F VirIT: Win32.Nimnul.F Xcitium: Virus.Win32.Wali.KA@558nxg Zillya: Virus.Nimnul.Win32.5 ZoneAlarm: W32/Nimnul-A Zoner: Probably Heur.ExeHeaderL alibabacloud: Virus:Win/Jadtre.A(dyn) huorong: Virus/Jadtre.ax |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 10 |
| TimeDateStamp | 1970-Jan-25 06:32:32 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0xd000 |
| SizeOfInitializedData | 0x36800 |
| SizeOfUninitializedData | 0x600 |
| AddressOfEntryPoint | 0x00050000 (Section: \xe0\x14\x00\x00\xa3u") |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xa000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 1.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x55000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| libgcc_s_dw2-1.dll |
_Unwind_Resume
__deregister_frame_info __register_frame_info |
|---|---|
| KERNEL32.dll |
DeleteCriticalSection
EnterCriticalSection FreeLibrary GetCurrentProcess GetCurrentProcessId GetCurrentThreadId GetLastError GetModuleHandleA GetProcAddress GetStartupInfoA GetSystemTimeAsFileTime GetTickCount InitializeCriticalSection LeaveCriticalSection LoadLibraryA QueryPerformanceCounter SetUnhandledExceptionFilter Sleep TerminateProcess TlsGetValue UnhandledExceptionFilter VirtualProtect VirtualQuery |
| msvcrt.dll |
__dllonexit
__getmainargs __initenv __lconv_init __set_app_type __setusermatherr _acmdln _amsg_exit _cexit _fmode _initterm _iob _lock _onexit _unlock abort calloc exit fprintf free fwrite malloc memcpy memset signal strlen strncmp vfprintf |
| USER32.dll |
RegisterDeviceNotificationW
|
| libstdc++-6.dll |
_ZNSs4_Rep10_M_destroyERKSaIcE
_ZNSs4_Rep10_M_disposeERKSaIcE _ZNSsC1EPKcjRKSaIcE _ZTVN10__cxxabiv117__class_type_infoE _ZTVN10__cxxabiv120__si_class_type_infoE _ZTVN10__cxxabiv121__vmi_class_type_infoE _ZdaPv _ZdlPv _Znaj _Znwj __cxa_begin_catch __cxa_end_catch __cxa_rethrow __gxx_personality_v0 |
| QtCore4.dll |
_Z17qt_message_output9QtMsgTypePKc
_Z5qFreePv _ZN10QByteArray7reallocEi _ZN10QByteArrayC1EPKc _ZN10QTextCodec12codecForNameERK10QByteArray _ZN10QTextCodec17setCodecForLocaleEPS_ _ZN10QTextCodec4cftrE _ZN11QMetaObject8activateEP7QObjectPKS_iPPv _ZN11QTextStreamC1EP7QString6QFlagsIN9QIODevice12OpenModeFlagEE _ZN11QTextStreamD1Ev _ZN11QTextStreamlsERK7QString _ZN11QTextStreamlsEc _ZN11QTextStreamlsEi _ZN16QCoreApplication13processEventsE6QFlagsIN10QEventLoop17ProcessEventsFlagEE _ZN16QCoreApplication19applicationFilePathEv _ZN4QDir10setCurrentERK7QString _ZN5QFile4openE6QFlagsIN9QIODevice12OpenModeFlagEE _ZN5QFileC1ERK7QString _ZN5QFileD1Ev _ZN6QTimer10singleShotEiP7QObjectPKc _ZN7QObject10childEventEP11QChildEvent _ZN7QObject10timerEventEP11QTimerEvent _ZN7QObject11customEventEP6QEvent _ZN7QObject11eventFilterEPS_P6QEvent _ZN7QObject13connectNotifyEPKc _ZN7QObject16disconnectNotifyEPKc _ZN7QObject5eventEP6QEvent _ZN7QObject7connectEPKS_PKcS1_S3_N2Qt14ConnectionTypeE _ZN7QString11shared_nullE _ZN7QString13fromLocal8BitEPKci _ZN7QString16codecForCStringsE _ZN7QString16fromAscii_helperEPKci _ZN7QString4freeEPNS_4DataE _ZN7QString6numberEii _ZN7QString6removeEii _ZN7QString8fromUtf8EPKci _ZN7QString9fromAsciiEPKci _ZN7QStringaSERKS_ _ZN7QThread11qt_metacallEN11QMetaObject4CallEiPPv _ZN7QThread11qt_metacastEPKc _ZN7QThread16staticMetaObjectE _ZN7QThread3runEv _ZN7QThread5sleepEm _ZN7QThreadC2EP7QObject _ZN7QThreadD2Ev _ZN9QIODevice4readEPcx _ZN9QListData11detach_growEPii _ZN9QListData11shared_nullE _ZN9QListData6appendEv _ZN9QListData6detachEi _ZNK11QMetaObject2trEPKcS1_ _ZNK5QFile5atEndEv _ZNK7QString11lastIndexOfERKS_iN2Qt15CaseSensitivityE _ZNK7QString11toLocal8BitEv _ZNK7QString7toAsciiEv _ZNK7QStringeqERK13QLatin1String _ZNK7QStringeqERKS_ |
| QtGui4.dll |
_ZN10QBoxLayout10addSpacingEi
_ZN10QBoxLayout9addLayoutEP7QLayouti _ZN10QBoxLayout9addWidgetEP7QWidgeti6QFlagsIN2Qt13AlignmentFlagEE _ZN11QHBoxLayoutC1Ev _ZN11QPushButtonC1ERK7QStringP7QWidget _ZN11QVBoxLayoutC1Ev _ZN12QApplication4execEv _ZN12QApplicationC1ERiPPci _ZN12QApplicationD1Ev _ZN12QProgressBar14setTextVisibleEb _ZN12QProgressBar8setRangeEii _ZN12QProgressBar8setValueEi _ZN12QProgressBarC1EP7QWidget _ZN15QAbstractButton5clickEv _ZN5QFont12setPointSizeEi _ZN5QFont9setFamilyERK7QString _ZN5QFontC1Ev _ZN5QFontD1Ev _ZN6QLabel7setTextERK7QString _ZN6QLabelC1ERK7QStringP7QWidget6QFlagsIN2Qt10WindowTypeEE _ZN7QWidget10closeEventEP11QCloseEvent _ZN7QWidget10enterEventEP6QEvent _ZN7QWidget10fontChangeERK5QFont _ZN7QWidget10leaveEventEP6QEvent _ZN7QWidget10paintEventEP11QPaintEvent _ZN7QWidget10setEnabledEb _ZN7QWidget10setVisibleEb _ZN7QWidget10wheelEventEP11QWheelEvent _ZN7QWidget11actionEventEP12QActionEvent _ZN7QWidget11changeEventEP6QEvent _ZN7QWidget11qt_metacallEN11QMetaObject4CallEiPPv _ZN7QWidget11qt_metacastEPKc _ZN7QWidget11resizeEventEP12QResizeEvent _ZN7QWidget11styleChangeER6QStyle _ZN7QWidget11tabletEventEP12QTabletEvent _ZN7QWidget12focusInEventEP11QFocusEvent _ZN7QWidget13dragMoveEventEP14QDragMoveEvent _ZN7QWidget13enabledChangeEb _ZN7QWidget13focusOutEventEP11QFocusEvent _ZN7QWidget13keyPressEventEP9QKeyEvent _ZN7QWidget13paletteChangeERK8QPalette _ZN7QWidget14dragEnterEventEP15QDragEnterEvent _ZN7QWidget14dragLeaveEventEP15QDragLeaveEvent _ZN7QWidget14languageChangeEv _ZN7QWidget14mouseMoveEventEP11QMouseEvent _ZN7QWidget14setFocusPolicyEN2Qt11FocusPolicyE _ZN7QWidget14setMinimumSizeEii _ZN7QWidget14setWindowTitleERK7QString _ZN7QWidget15keyReleaseEventEP9QKeyEvent _ZN7QWidget15mousePressEventEP11QMouseEvent _ZN7QWidget15setMaximumWidthEi _ZN7QWidget16contextMenuEventEP17QContextMenuEvent _ZN7QWidget16inputMethodEventEP17QInputMethodEvent _ZN7QWidget16setMinimumHeightEi _ZN7QWidget16staticMetaObjectE _ZN7QWidget17mouseReleaseEventEP11QMouseEvent _ZN7QWidget18focusNextPrevChildEb _ZN7QWidget21mouseDoubleClickEventEP11QMouseEvent _ZN7QWidget22windowActivationChangeEb _ZN7QWidget5eventEP6QEvent _ZN7QWidget7setFontERK5QFont _ZN7QWidget9dropEventEP10QDropEvent _ZN7QWidget9hideEventEP10QHideEvent _ZN7QWidget9moveEventEP10QMoveEvent _ZN7QWidget9setLayoutEP7QLayout _ZN7QWidget9showEventEP10QShowEvent _ZN7QWidgetC2EPS_6QFlagsIN2Qt10WindowTypeEE _ZN7QWidgetD2Ev _ZN9QLineEdit7setTextERK7QString _ZN9QLineEditC1EP7QWidget _ZNK7QWidget11paintEngineEv _ZNK7QWidget14heightForWidthEi _ZNK7QWidget15minimumSizeHintEv _ZNK7QWidget16inputMethodQueryEN2Qt16InputMethodQueryE _ZNK7QWidget5getDCEv _ZNK7QWidget5winIdEv _ZNK7QWidget6metricEN12QPaintDevice17PaintDeviceMetricE _ZNK7QWidget7devTypeEv _ZNK7QWidget8sizeHintEv _ZNK7QWidget9releaseDCEP5HDC__ _ZThn8_NK7QWidget11paintEngineEv _ZThn8_NK7QWidget5getDCEv _ZThn8_NK7QWidget6metricEN12QPaintDevice17PaintDeviceMetricE _ZThn8_NK7QWidget7devTypeEv _ZThn8_NK7QWidget9releaseDCEP5HDC__ |
| hidapi.dll |
hid_close
hid_open_path hid_set_nonblocking hid_send_feature_report hid_write hid_get_feature_report hid_read hid_enumerate hid_free_enumeration |
| ISPDLL.dll |
LoadProgdata
GetMCUInfo GetChksum ConnectToBootloader VerifyByPage PartialProgram BlankCheck EraseByPage ExecuteProgramFrom DisConnectBootloader LockAll SwitchToUserProgram |
| StartAddressOfRawData | 0x438000 |
|---|---|
| EndAddressOfRawData | 0x43801c |
| AddressOfIndex | 0x4330cc |
| AddressOfCallbacks | 0x437020 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x00407020
0x00406FD0 |
No comments yet.