f6547471b97c26c0339b4bbadc724def1fcc2f3a31ab6f5dc01a55fcc6a0ad82

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2024-Jul-23 14:45:32
Detected languages English - United States
Debug artifacts E:\06. Command & Control\05. ShadowSpecter\ShadowSpecter\x64\Debug\ShadowSpecter.pdb
CompanyName N/A
FileDescription N/A
FileVersion 1.2.0.3
InternalName zoom.exe
OriginalFilename zoom.exe
ProductName Zoom
ProductVersion 1.2.0.3
Author 분쇄기

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Interesting strings found in the binary: Contains domain names:
  • communications.com
  • specter-communications.com
Suspicious The PE is possibly packed. Section .textbss is both writable and executable.
Suspicious The PE contains functions most legitimate programs don't use. Possibly launches other programs:
  • CreateProcessW
Has Internet access capabilities:
  • WinHttpConnect
  • WinHttpReceiveResponse
  • WinHttpSendRequest
  • WinHttpOpenRequest
  • WinHttpOpen
  • WinHttpCloseHandle
  • WinHttpReadData
  • WinHttpQueryDataAvailable
Interacts with services:
  • OpenServiceW
  • OpenSCManagerW
  • CreateServiceW
Suspicious VirusTotal score: 1/72 (Scanned on 2025-03-28 12:08:32) Elastic: malicious (high confidence)

Hashes

MD5 5d638d00983cf746a3da1dc6ee40e5d9
SHA1 8a4400c4c71fd90d311c62ac89b4b6c1ea51734b
SHA256 f6547471b97c26c0339b4bbadc724def1fcc2f3a31ab6f5dc01a55fcc6a0ad82
SHA3 4e50f590b48d0dc6f78952bf65471733c075663fedb2e924e08dadefe892f837
SSDeep 12288:hxTAfDCugGpQ/v39FJd3Lhdc9WPp4enRg1zRRRr:jzwQ/PyWPp4enRg1zRRRr
Imports Hash 54b7b2c50382e8e367f97d0d5bdb2bda

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 9
TimeDateStamp 2024-Jul-23 14:45:32
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x6d200
SizeOfInitializedData 0x31000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000338CE (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xd5000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.textbss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x3048f
VirtualAddress 0x1000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.text

MD5 09af6ac8f0a0b61a75dbe18b166ac024
SHA1 3498d74d549d7a5a621a1f28d46050ce938a41a0
SHA256 b3ca7dfb53e3a40a34992b7017ae5a236049f148401476f5513d054dc15b0c32
SHA3 4438e58590b9b59cd323650f6f9a9b2e003b4051921c4786ac3cd5dfcaacee0b
VirtualSize 0x6d1ff
VirtualAddress 0x32000
SizeOfRawData 0x6d200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 4.80843

.rdata

MD5 f23902d87f151b1ff1b5d2cb093b2c68
SHA1 8439328bf613dbe135d9f8857fc933385db0ecf7
SHA256 9a8cb9aee32a3202854d57209705445c6d473b9dca71d824fbb68c121319bb96
SHA3 7b24b4bd5b2cc25ccfe32a843eaa56ed49a40dd2570f0428fd0e5416dcc71312
VirtualSize 0x22055
VirtualAddress 0xa0000
SizeOfRawData 0x22200
PointerToRawData 0x6d600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.57078

.data

MD5 dee99615656e81bf62079987812ef173
SHA1 97ea96c57435347e57f83be58ee2fb0be748d8e8
SHA256 6fac16318e89dc2e70038c1bf662bf4d5d44c3c4f5f97a94cf82ab5477275410
SHA3 d1f7712237ae479fa5086d52b9abbbadb904462fd5771a229bfe7c99663b7b58
VirtualSize 0x1151
VirtualAddress 0xc3000
SizeOfRawData 0xa00
PointerToRawData 0x8f800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.67979

.pdata

MD5 dc2568bad4b34ff0a7d7bfa41c07e300
SHA1 0aa46f8a104569441be4db1d66bd9993f78d842c
SHA256 26c66c1fcb62f11109cd50fb5911d29b7b141cf75c157025c11a88622fd5d9e8
SHA3 1b21e30e9595964011d47303e2b4e87ee569a66732a3aa4e240c267a60e802f7
VirtualSize 0x91e0
VirtualAddress 0xc5000
SizeOfRawData 0x9200
PointerToRawData 0x90200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.74837

.idata

MD5 1bca667787c3a4d181e9eddd31c0b044
SHA1 8749ac66356f8ae7bf6cb891ed60008b9ef2af44
SHA256 1d27d358e2206b63d7ccba082bf10b48fde8a4acc7679a9619ef648775d71658
SHA3 afcbffbef797b0a1e532bb2ccb8adfe56869186655d1c16b4bcdfbfcbbbc6712
VirtualSize 0x2dc4
VirtualAddress 0xcf000
SizeOfRawData 0x2e00
PointerToRawData 0x99400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.03607

.00cfg

MD5 d01097aea5568b94d43b323d22e903ea
SHA1 ff7940e68f0ea4971c37dfa5a66ee75531239d08
SHA256 9f976728a54418ebbcca16b63945a13a7fbc19da6cc7536c8e90ac650ed57665
SHA3 22a78b413169bcaeedda0e89f7cf635b82c7c3c780bd8baa5185ecbef35ad985
VirtualSize 0x175
VirtualAddress 0xd2000
SizeOfRawData 0x200
PointerToRawData 0x9c200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.502848

.rsrc

MD5 9c0d20c4fa08fed1c22bf2a8339f1aeb
SHA1 562ada902642f38e31bfba7c7b0382ec6578b7b1
SHA256 d6cbd79e67916a62154714ce015efa267fab4dab6ea045ba9e63abcfc59217cb
SHA3 84340d298195bb7af976b148d9f407e4b92b6546ab776a5a5c2f704ca2b283cc
VirtualSize 0x81c
VirtualAddress 0xd3000
SizeOfRawData 0xa00
PointerToRawData 0x9c400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.56603

.reloc

MD5 c95f78090bdaa9bc16f607b7eeb1703d
SHA1 04ad81aa064808abe117e9fdb536595c29a5dba4
SHA256 6c97927aa7ca31644fb95dce69be0e3bfc1ca27f9808a74b00ec58f105ecdebe
SHA3 e1e7d525226be5070c51fe7cffeb12d356b33568152a7b1a50a7aaab8cd1ecdb
VirtualSize 0xffa
VirtualAddress 0xd4000
SizeOfRawData 0x1000
PointerToRawData 0x9ce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 2.87856

Imports

KERNEL32.dll CreatePipe
Sleep
CreateProcessW
MultiByteToWideChar
LoadResource
GetLastError
SizeofResource
FindResourceW
ReleaseSRWLockShared
AcquireSRWLockExclusive
AcquireSRWLockShared
TryAcquireSRWLockExclusive
SetHandleInformation
CloseHandle
WriteFile
ReadFile
GetFileSize
CreateFileA
WideCharToMultiByte
LockResource
GetComputerNameA
TryAcquireSRWLockShared
GetProcAddress
FreeLibrary
VirtualQuery
GetProcessHeap
HeapFree
LocalFree
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
HeapAlloc
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
RaiseException
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
GetStartupInfoW
GetModuleHandleW
ReleaseSRWLockExclusive
USER32.dll GetDesktopWindow
GetWindowRect
ADVAPI32.dll SetServiceStatus
RegisterServiceCtrlHandlerW
OpenServiceW
OpenSCManagerW
CreateServiceW
CloseServiceHandle
GetUserNameA
StartServiceCtrlDispatcherW
ole32.dll CoSetProxyBlanket
CoInitializeSecurity
CoUninitialize
CoCreateInstance
CoInitializeEx
OLEAUT32.dll SysStringLen
SysFreeString
VariantClear
GetErrorInfo
VariantInit
VariantChangeType
SetErrorInfo
CreateErrorInfo
SysAllocString
MSVCP140D.dll ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?_New_Locimp@_Locimp@locale@std@@CAPEAV123@AEBV123@@Z
??0?$codecvt@_WDU_Mbstatet@@@std@@QEAA@_K@Z
??1?$codecvt@_WDU_Mbstatet@@@std@@MEAA@XZ
?_Incref@facet@locale@std@@UEAAXXZ
?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
?id@?$codecvt@_WDU_Mbstatet@@@std@@2V0locale@2@A
?uncaught_exception@std@@YA_NXZ
?_Xout_of_range@std@@YAXPEBD@Z
?good@ios_base@std@@QEBA_NXZ
?flags@ios_base@std@@QEBAHXZ
?width@ios_base@std@@QEBA_JXZ
?width@ios_base@std@@QEAA_J_J@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ
?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?_Xbad_function_call@std@@YAXXZ
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?_Xinvalid_argument@std@@YAXPEBD@Z
_Query_perf_counter
_Query_perf_frequency
?_Addfac@_Locimp@locale@std@@AEAAXPEAVfacet@23@_K@Z
??0_Lockit@std@@QEAA@H@Z
??1_Lockit@std@@QEAA@XZ
?_Xbad_alloc@std@@YAXXZ
??Bid@locale@std@@QEAA_KXZ
??3_Crt_new_delete@std@@SAXPEAX@Z
??2_Crt_new_delete@std@@SAPEAX_K@Z
??4?$_Yarn@D@std@@QEAAAEAV01@PEBD@Z
?_W_Getmonths@_Locinfo@std@@QEBAPEBGXZ
?_W_Getdays@_Locinfo@std@@QEBAPEBGXZ
?_Getmonths@_Locinfo@std@@QEBAPEBDXZ
?_Getdays@_Locinfo@std@@QEBAPEBDXZ
?_Getcvt@_Locinfo@std@@QEBA?AU_Cvtvec@@XZ
_Mbrtowc
?_Xlength_error@std@@YAXPEBD@Z
?in@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEA_W3AEAPEA_W@Z
NETAPI32.dll NetApiBufferFree
NetGetJoinInformation
WINHTTP.dll WinHttpConnect
WinHttpReceiveResponse
WinHttpSendRequest
WinHttpOpenRequest
WinHttpOpen
WinHttpCloseHandle
WinHttpReadData
WinHttpQueryDataAvailable
VCRUNTIME140D.dll __vcrt_LoadLibraryExW
memcmp
memcpy
memmove
__std_exception_copy
__std_exception_destroy
_CxxThrowException
memchr
__current_exception
__current_exception_context
__C_specific_handler
__C_specific_handler_noexcept
__std_type_info_destroy_list
__vcrt_GetModuleFileNameW
__vcrt_GetModuleHandleW
memset
VCRUNTIME140_1D.dll __CxxFrameHandler4
ucrtbased.dll _register_thread_local_exe_atexit_callback
_configthreadlocale
_set_new_mode
__p__commode
_seh_filter_dll
_initialize_onexit_table
_register_onexit_function
free
_crt_atexit
_crt_at_quick_exit
_free_dbg
strcpy_s
strcat_s
__stdio_common_vsprintf_s
_wmakepath_s
_wsplitpath_s
_cexit
_execute_onexit_table
strtol
exit
_wassert
localeconv
strtoull
strtoll
strtod
_dtest
terminate
_errno
__stdio_common_vsprintf
remove
strlen
wcslen
_CrtDbgReport
__p___argv
__p___argc
_set_fmode
_exit
_initterm_e
_initterm
_get_initial_narrow_environment
_initialize_narrow_environment
_configure_narrow_argv
_calloc_dbg
_c_exit
__setusermatherr
_set_app_type
_seh_filter_exe
_callnewh
_CrtDbgReportW
_invalid_parameter
wcscpy_s
malloc

Delayed Imports

100

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.875
MD5 1eda8fc3e15faeb20b266ffc3cda6894
SHA1 bc0c62c3e6866c83eef944c489c3f04771c07f00
SHA256 5c272d2d593c5b21f9fb5d36feb314316485bcebfa5bb3277978a37e65a7e945
SHA3 56878c213bbb2cfae0dd1c7fdb457d694c17ea1898e9ceddcc196c9e5cdb7e84

101

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x1b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.68081
MD5 6b7eb0df128a9a161550d0b2abac16ab
SHA1 c649a13a3b87afd921f04470b627c2a421440541
SHA256 fb1af21ff3ff68d3d5bdc64a95bd2afa86af966b5b9543cb23ac3e9d20c1ccf7
SHA3 9730fc22781ab113592669893b6edb929b2b500ab7c4a9a9dbeaa6ebe04190c1

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x250
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32832
MD5 8acec14c85b93ca48fa239dd5ab9172d
SHA1 5d0e1a6583cf66a1c2a8485fe83f858847ea9abc
SHA256 0282419e6d609c0728fe6cb7e26cf85bffb5ce3c18ac4f6c89601d7cdd421574
SHA3 bb54cc63082ce474b91e1fc7c7d524f1a658740e48a176c654863c9fcbc3acd6

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.2.0.3
ProductVersion 1.2.0.3
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName N/A
FileDescription N/A
FileVersion (#2) 1.2.0.3
InternalName zoom.exe
OriginalFilename zoom.exe
ProductName Zoom
ProductVersion (#2) 1.2.0.3
Author 분쇄기
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2024-Jul-23 14:45:32
Version 0.0
SizeofData 109
AddressOfRawData 0xb3584
PointerToRawData 0x80b84
Referenced File E:\06. Command & Control\05. ShadowSpecter\ShadowSpecter\x64\Debug\ShadowSpecter.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2024-Jul-23 14:45:32
Version 0.0
SizeofData 20
AddressOfRawData 0xb35f4
PointerToRawData 0x80bf4

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1400c3040

RICH Header

XOR Key 0xf61c169f
Unmarked objects 0
ASM objects (33731) 4
C objects (33731) 10
C objects (30795) 1
C++ objects (33731) 41
Imports (33731) 6
Imports (30795) 17
Total imports 197
C++ objects (33812) 3
Resource objects (33812) 1
151 1
Linker (33812) 1

Errors

[*] Warning: Section .textbss has a size of 0!
Leave a comment

No comments yet.