5eef02dc3d11007fdbf881949dfecc2d18167c9f834110acef98bbef4a4e0c76

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Mar-30 15:09:52
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.
CompanyName Veyrix Soft
FileDescription Veyrix Desktop Platform
FileVersion 3.1.4.0
InternalName veyrix
LegalCopyright Copyright © 2026 Veyrix Soft. All rights reserved.
LegalTrademarks Copyright © Veyrix Soft. All rights reserved.
OriginalFilename veyrix.exe
ProductName Veyrix
ProductVersion 3.1.4
Comments Veyrix Desktop Platform

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • schtask
Looks for Qemu presence:
  • QeMu
  • qEMu
Miscellaneous malware strings:
  • VIRUS
  • cmd.exe
Contains domain names:
  • https://docs.rs
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to RC5 or RC6
Microsoft's Cryptography API
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegCloseKey
  • RegOpenKeyExW
  • RegQueryValueExW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Uses Windows's Native API:
  • NtCancelIoFileEx
  • NtCreateFile
  • NtDeviceIoControlFile
  • NtOpenFile
  • NtReadFile
  • NtWriteFile
  • NtCreateNamedPipeFile
Uses Microsoft's cryptographic API:
  • CryptUnprotectData
Can create temporary files:
  • CreateFileA
  • CreateFileW
  • GetTempPathA
  • GetTempPathW
Leverages the raw socket API to access the Internet:
  • ws2_32.dll
Interacts with the certificate store:
  • CertAddCertificateContextToStore
  • CertOpenStore
Malicious VirusTotal score: 11/71 (Scanned on 2026-08-30 11:06:27) ClamAV: Win.Backdoor.LucidRook-10059729-0
CrowdStrike: win/malicious_confidence_90% (D)
DeepInstinct: MALICIOUS
ESET-NOD32: Win64/Spy.Agent.AUI trojan
Elastic: malicious (high confidence)
Malwarebytes: Malware.AI.4071137053
McAfeeD: Trojan:Win/RustStealer.AF
Rising: Stealer.Agent!1.14343 (CLASSIC)
SentinelOne: Static AI - Malicious PE
Symantec: ML.Attribute.HighConfidence
huorong: TrojanSpy/Stealer.xs

Hashes

MD5 11e4bbfc63bd263e556bc2ba053c43c8 🔍
SHA1 b8b8154d134cc14b70eafb990f2fc305c3d8bbd2 🔍
SHA256 5eef02dc3d11007fdbf881949dfecc2d18167c9f834110acef98bbef4a4e0c76 🔍
SHA3 1be4384593f4ef989069226b425f507406738e4611d0964cd5be18e503703e07 🔍
SSDeep 49152:sx/zlKyAIbzjxt03LzQcAVjyho397txCSC1Y94cxNB27TWOqPcAlvEhEpuYvTXC:sRJticBg0lsHniFbIjLRDtqNFi 🔍
Imports Hash 8a90f35eb1ac2c9096ce42ea899a5500 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 10
TimeDateStamp 2026-Mar-30 15:09:52
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x26fa00
SizeOfInitializedData 0x320600
SizeOfUninitializedData 0x400
AddressOfEntryPoint 0x00000000000013F0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x597000
SizeOfHeaders 0x400
Checksum 0x598946
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 90abe2803724dd47cc1032130b1868e3 🔍
SHA1 fa9ca9bb9afd10c8c31b0effa49ff599503ded15 🔍
SHA256 9c120c9c67566f9ea12a523523d828826cfe0bf255411a09d38787a654ede7ae 🔍
SHA3 98e5e6e5ec9b6fc51fa5114417ac793036fc38b70cba1f9c8beffb7ff691691b 🔍
VirtualSize 0x26f9e0
VirtualAddress 0x1000
SizeOfRawData 0x26fa00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.36745

.data

MD5 6220956b20e28fed1f865aacbbaddf52 🔍
SHA1 dfc5e91cf036471a16a410d014efceca8b9e987a 🔍
SHA256 c9df068709419eca7e68ec9bccb9b40a901e5ed5e6b7027cfa6442a2cdb785c7 🔍
SHA3 cdfd29c8a2fb58532b4bf1cb3b424d8517bd4cc74cbd270158591f1ace6cd34c 🔍
VirtualSize 0x5460
VirtualAddress 0x271000
SizeOfRawData 0x5600
PointerToRawData 0x26fe00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.99075

.rdata

MD5 16e8723da0905129806d66b5b164a716 🔍
SHA1 cbd78e6f8047cfaa9e5c758bc1664fa642e0480c 🔍
SHA256 cf225157e5078c7b04577fced247ca1adbc440f45123261e24793599ebddbe91 🔍
SHA3 5c584d4969e633f10f69daa144fbf6a34af235b6f5563e8b3a470b24889c2c6b 🔍
VirtualSize 0x2e3618
VirtualAddress 0x277000
SizeOfRawData 0x2e3800
PointerToRawData 0x275400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.50656

.pdata

MD5 f3214569910cdfeb1ebd7ef456b82c80 🔍
SHA1 b141f6bfa116def05f9dee6f9f372f93814b78ff 🔍
SHA256 c93b745ac1320f876441bbb350f6e67c45396d0d518e3493a6075016c9193347 🔍
SHA3 828bec0ef988b9e0c0e9623f39c66d0345df57e1648b2416e6cc9c92f2947193 🔍
VirtualSize 0x14244
VirtualAddress 0x55b000
SizeOfRawData 0x14400
PointerToRawData 0x558c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.2877

.xdata

MD5 95fdc8f9548020f2c3f473af001271b8 🔍
SHA1 b10453bf54551c70c084873456bc3434525c0003 🔍
SHA256 3a17dd366bbbf3eb0a7a71664c78987f06240fb11d45f5642ee75cf034a5f882 🔍
SHA3 c0d59dfdb7c6cf6c445cfdd515da1955b3c2f3fa376163eb8f9bec76faa578bb 🔍
VirtualSize 0x187c8
VirtualAddress 0x570000
SizeOfRawData 0x18800
PointerToRawData 0x56d000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.84679

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍
VirtualSize 0x260
VirtualAddress 0x589000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 b96be822533e457c68ff6a73036d55fc 🔍
SHA1 b298e436ff9f02e17b6fe6eeaf7a53d28b7f0d8e 🔍
SHA256 e0625a7525ea253cf373a2391e32651e2439656ad74b871dd42b43886b724877 🔍
SHA3 c25e6b9f244a964d56cedebeacb8371605723cac03eb111ea2cf687ce727210b 🔍
VirtualSize 0x299c
VirtualAddress 0x58a000
SizeOfRawData 0x2a00
PointerToRawData 0x585800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.667

.tls

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x10
VirtualAddress 0x58d000
SizeOfRawData 0x200
PointerToRawData 0x588200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 9ad992857a932704de27361a78fe4ae4 🔍
SHA1 0521fb8a034534e20b3b02aa30b4af0739860856 🔍
SHA256 e33d250a83253f926acfac0733631430ef1390df1d86851fcbd8a10d2c76c61b 🔍
SHA3 cd8d2186b63ca56c1471379a58aa9511f3898e004062d15c54af4afa64f6dee2 🔍
VirtualSize 0x820
VirtualAddress 0x58e000
SizeOfRawData 0xa00
PointerToRawData 0x588400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.07446

.reloc

MD5 674fcd054d5b4f6ff479dfccc6f5a9d2 🔍
SHA1 06d9025de6ad57c9568952b5ca4a3eb4b869697d 🔍
SHA256 f3b9af47612c6b3d9999f489d2b9ca80a580736724f1f00e13b925863de51c34 🔍
SHA3 60dc52be5ade4df8159708846d2412872121ccc2d5dcabaff04e3bf9b2c5a10c 🔍
VirtualSize 0x7588
VirtualAddress 0x58f000
SizeOfRawData 0x7600
PointerToRawData 0x588e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.46343

Imports

kernel32.dll GetComputerNameExW
advapi32.dll RegCloseKey
RegOpenKeyExW
RegQueryValueExW
kernel32.dll (#2) GetComputerNameExW
kernel32.dll (#3) GetComputerNameExW
advapi32.dll (#2) RegCloseKey
RegOpenKeyExW
RegQueryValueExW
api-ms-win-core-synch-l1-2-0.dll WaitOnAddress
WakeByAddressAll
WakeByAddressSingle
bcrypt.dll BCryptGenRandom
bcryptprimitives.dll ProcessPrng
kernel32.dll (#4) GetComputerNameExW
ntdll.dll NtCancelIoFileEx
NtCreateFile
NtDeviceIoControlFile
NtOpenFile
NtReadFile
NtWriteFile
RtlNtStatusToDosError
secur32.dll AcceptSecurityContext
AcquireCredentialsHandleA
ApplyControlToken
DecryptMessage
DeleteSecurityContext
EncryptMessage
FreeContextBuffer
FreeCredentialsHandle
InitializeSecurityContextW
QueryContextAttributesW
ws2_32.dll WSAGetLastError
WSAIoctl
WSASend
WSASocketW
WSAStartup
bind
closesocket
connect
freeaddrinfo
getaddrinfo
getpeername
getsockname
getsockopt
ioctlsocket
recv
send
setsockopt
shutdown
gdi32.dll GetDeviceCaps
kernel32.dll (#5) GetComputerNameExW
shell32.dll ShellExecuteW
user32.dll GetDC
GetDesktopWindow
GetWindowRect
ReleaseDC
ShowWindow
CRYPT32.dll CertAddCertificateContextToStore
CertCloseStore
CertDuplicateCertificateChain
CertDuplicateCertificateContext
CertDuplicateStore
CertEnumCertificatesInStore
CertFreeCertificateChain
CertFreeCertificateContext
CertGetCertificateChain
CertOpenStore
CertVerifyCertificateChainPolicy
CryptUnprotectData
KERNEL32.dll RaiseException
RtlUnwindEx
VirtualProtect
VirtualQuery
__C_specific_handler
msvcrt.dll __getmainargs
__initenv
__iob_func
__set_app_type
__setusermatherr
_amsg_exit
_beginthreadex
_cexit
_commode
_endthreadex
_errno
_fmode
_fpreset
_initterm
_localtime64
abort
atexit
calloc
exit
fprintf
free
ldexp
malloc
memchr
memcmp
memcpy
memmove
memset
qsort
realloc
signal
strchr
strcmp
strcspn
strlen
strncmp
strrchr
strspn
vfprintf
wcslen
ntdll.dll (#2) NtCancelIoFileEx
NtCreateFile
NtDeviceIoControlFile
NtOpenFile
NtReadFile
NtWriteFile
RtlNtStatusToDosError

Delayed Imports

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x3c4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.39597
MD5 0b524970418aa00f699f95f55061f6eb 🔍
SHA1 5ea111fb47e75c2da8f7f85cb9395a9fa96d2a68 🔍
SHA256 fbc355fccfbdc96344f9e3016c3126c90f9c431246a545f2ff464ccb5f88454e 🔍
SHA3 2f4c6660c4d992489135c5a6dc66b8dc31bd067eaf00609d2b86becd354b1903 🔍

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x3b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.21746
MD5 f617b75aff2e3d6fca7e9589ecadaee8 🔍
SHA1 227c1041711b1b2bd6025a218422dc348e4a49a4 🔍
SHA256 eb60eb1986cf12f5ff203f01f8fc5bfd78e852b04370321e8b0b25ffd86615e9 🔍
SHA3 78bb8acfca93008c18eb5cae879417a430138303ae1e921972d397c69bc11031 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 3.1.4.0
ProductVersion 3.1.4.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Veyrix Soft
FileDescription Veyrix Desktop Platform
FileVersion (#2) 3.1.4.0
InternalName veyrix
LegalCopyright Copyright © 2026 Veyrix Soft. All rights reserved.
LegalTrademarks Copyright © Veyrix Soft. All rights reserved.
OriginalFilename veyrix.exe
ProductName Veyrix
ProductVersion (#2) 3.1.4
Comments Veyrix Desktop Platform
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x14058d000
EndAddressOfRawData 0x14058d008
AddressOfIndex 0x14058918c
AddressOfCallbacks 0x14055a5f0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks 0x00000001401BD4E0
0x00000001401BD4C0

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0!
Leave a comment
📁 Transfer № J5669 from Coinbase. SIGN IN ->>> graph.org/Bitcoin 16 hours ago
📁 Transfer № J5669 from Coinbase. SIGN IN ->>> graph.org/Bitcoin-Mining-08-27?hs=71eba39f1ca126e9c1cf4cc1f7bfa4c2& 📁