67083b149be508ac690cbbff0a2ef2c5fd504299e39f834d793e379b461a9dce

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Apr-11 02:22:37
Detected languages English - United States
CompanyName Luanti community
FileDescription Luanti self-extracting launcher
FileVersion 5.16.1
InternalName luanti
LegalCopyright (c) 2010-2026 Perttu Ahola (celeron55) and contributors
ProductName Luanti

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • http://nsis.sf.net
  • http://nsis.sf.net/NSIS_Error
  • nsis.sf.net
Suspicious The PE is an NSIS installer Unusual section name found: .ndata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Can access the registry:
  • RegCloseKey
  • RegCreateKeyExW
  • RegDeleteKeyW
  • RegDeleteValueW
  • RegEnumKeyW
  • RegEnumValueW
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegSetValueExW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 11895498 bytes of data starting at offset 0x1aa00.
The overlay data has an entropy of 7.99998 and is possibly compressed or encrypted.
Overlay data amounts for 99.0915% of the executable.
Suspicious VirusTotal score: 2/71 (Scanned on 2026-06-27 15:37:55) DeepInstinct: MALICIOUS
Trapmine: malicious.high.ml.score

Hashes

MD5 6af278d9224136d980cab21bd344b81a
SHA1 91a57da29f7bd90babfbed803debc5e1ddfacc84
SHA256 67083b149be508ac690cbbff0a2ef2c5fd504299e39f834d793e379b461a9dce
SHA3 2028ce24afe64ecb36d2b0fbea92079c042401a8750cb34d58401f00e76d7745
SSDeep 196608:actDN4gvYxGnYVawYGaz3IoeeeCsbbXtHU/swbJE4NKFovApWS4v23Lyt:aaN8xxow6zYoevbb9DiNio4pz4+byt
Imports Hash f4d1e4cd7416ef83f79f7c6a038875b3

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 7
TimeDateStamp 2024-Apr-11 02:22:37
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x9400
SizeOfInitializedData 0xf200
SizeOfUninitializedData 0x1f800
AddressOfEntryPoint 0x00004580 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xb000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 6.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x50000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 49479d4daf89a8e7998c373e6049b6d2
SHA1 7328fedab03479a087dc772cc6d2cc47203c8804
SHA256 b81441f81a30c4829cc3b84af141ca4cab44306df93668359e74751f30ad3da7
SHA3 3e3a432416cca9d85d3aa612a15973f45b2f5ac728a5651874dfede511e6175c
VirtualSize 0x92cc
VirtualAddress 0x1000
SizeOfRawData 0x9400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.08655

.data

MD5 473a8a00597026dddeebfbf10ed72492
SHA1 c5b0a19c3f7b82ef72a2e280ce34b0d381f14046
SHA256 fc48a4f2f43ef99c0e7fa253c76ef876ae28a5fc61bec98d8a342fcbf64afc8a
SHA3 859fd3840c8f3141d2b889ae05d16bb542d238ea7c2858beea859c195f2351c7
VirtualSize 0xe0
VirtualAddress 0xb000
SizeOfRawData 0x200
PointerToRawData 0x9800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.56763

.rdata

MD5 ea967d0afcbe5f5f2f5b9b5e9bde1553
SHA1 6774c66fb74d6e9e0fb6a4fa7ce979f283a0b3b6
SHA256 8c1efb91c2b6699d66da55ce8449ae3ee22fa7264cd1f72004a933671a6c4f93
SHA3 081d7d5535d446ee2e00e73e15f1aec58308bf6a2a50374d10d0b95159019105
VirtualSize 0xc708
VirtualAddress 0xc000
SizeOfRawData 0xc800
PointerToRawData 0x9a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.29021

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x1f620
VirtualAddress 0x19000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 e356ba5c7689851cbbab6bda1c5e59d1
SHA1 23978bd5260c1825d4ce754aace0f185af08038b
SHA256 30efd99c2d725d20953f79decaf3ed743d677f22bcc737e632c3cecefddbe61d
SHA3 cd0f98200da8a30b17db6b521a2dedc95ec9cc3ff4a9626e87b6eee7980ca427
VirtualSize 0x13b0
VirtualAddress 0x39000
SizeOfRawData 0x1400
PointerToRawData 0x16200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.40596

.ndata

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x11000
VirtualAddress 0x3b000
SizeOfRawData 0x200
PointerToRawData 0x17600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 52d14cbbbff41a886486fe96920bdb05
SHA1 163d6c0d0752dcd059597cec83ce8f4f966d657e
SHA256 196fb45139c3f9263d5a8c7ba71cd5dc78405a6d188d15b0afd84e3610883c3b
SHA3 d11cdd22af0bca32d00d7d104fac186719dd6bb7ccde8675fcfbc1a041a1608a
VirtualSize 0x3028
VirtualAddress 0x4c000
SizeOfRawData 0x3200
PointerToRawData 0x17800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.39403

Imports

ADVAPI32.dll AdjustTokenPrivileges
LookupPrivilegeValueW
OpenProcessToken
RegCloseKey
RegCreateKeyExW
RegDeleteKeyW
RegDeleteValueW
RegEnumKeyW
RegEnumValueW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
COMCTL32.dll ImageList_AddMasked
ImageList_Create
ImageList_Destroy
InitCommonControls
GDI32.dll CreateBrushIndirect
CreateFontIndirectW
DeleteObject
GetDeviceCaps
SelectObject
SetBkColor
SetBkMode
SetTextColor
KERNEL32.dll CloseHandle
CompareFileTime
CopyFileW
CreateDirectoryW
CreateFileW
CreateProcessW
CreateThread
DeleteFileW
ExitProcess
ExpandEnvironmentStringsW
FindClose
FindFirstFileW
FindNextFileW
FreeLibrary
GetCommandLineW
GetCurrentProcess
GetDiskFreeSpaceW
GetExitCodeProcess
GetFileAttributesW
GetFileSize
GetFullPathNameW
GetLastError
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
GetPrivateProfileStringW
GetProcAddress
GetShortPathNameW
GetSystemDirectoryW
GetTempFileNameW
GetTempPathW
GetTickCount
GetVersionExW
GetWindowsDirectoryW
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
LoadLibraryExW
MoveFileExW
MoveFileW
MulDiv
MultiByteToWideChar
ReadFile
RemoveDirectoryW
SearchPathW
SetCurrentDirectoryW
SetEnvironmentVariableW
SetErrorMode
SetFileAttributesW
SetFilePointer
SetFileTime
Sleep
WaitForSingleObject
WideCharToMultiByte
WriteFile
WritePrivateProfileStringW
lstrcatW
lstrcmpW
lstrcmpiA
lstrcmpiW
lstrcpyA
lstrcpynW
lstrlenA
lstrlenW
ole32.dll CoCreateInstance
CoTaskMemFree
IIDFromString
OleInitialize
OleUninitialize
SHELL32.dll SHBrowseForFolderW
SHFileOperationW
SHGetFileInfoW
SHGetPathFromIDListW
ShellExecuteExW
USER32.dll AppendMenuW
BeginPaint
CallWindowProcW
CharNextA
CharNextW
CharPrevW
CheckDlgButton
CloseClipboard
CreateDialogParamW
CreatePopupMenu
CreateWindowExW
DefWindowProcW
DestroyWindow
DialogBoxParamW
DispatchMessageW
DrawTextW
EmptyClipboard
EnableMenuItem
EnableWindow
EndDialog
EndPaint
ExitWindowsEx
FillRect
FindWindowExW
GetClassInfoW
GetClientRect
GetDC
GetDlgItem
GetDlgItemTextW
GetMessagePos
GetSysColor
GetSystemMenu
GetSystemMetrics
GetWindowLongW
GetWindowRect
InvalidateRect
IsWindow
IsWindowEnabled
IsWindowVisible
LoadCursorW
LoadImageW
MessageBoxIndirectW
OpenClipboard
PeekMessageW
PostQuitMessage
RegisterClassW
ReleaseDC
ScreenToClient
SendMessageTimeoutW
SendMessageW
SetClassLongW
SetClipboardData
SetCursor
SetDlgItemTextW
SetForegroundWindow
SetTimer
SetWindowLongW
SetWindowPos
SetWindowTextW
ShowWindow
SystemParametersInfoW
TrackPopupMenu
wsprintfA
wsprintfW

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.33191
MD5 571762426b9837f7c6041c1d49e5349a
SHA1 e0d2b5e6d35db4adb92ae102eea4ed0f885e2dca
SHA256 38925f889626371a3aec01842ee549c39c26669537016c1cca32533e57d42d66
SHA3 ff85befe1139b546bf928665c87fe37599e4772f4dd840d0a93845316aff2b19

105

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x118
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.68696
MD5 1f15b900e319de1c07d6c94344e45dfc
SHA1 28b665272300d0b29ad3a7e0fbdde74323f0646e
SHA256 dd775e96a2ea37d3ae31e6d7fcd751a3cb30108342e13d0bc898a20b08678fd0
SHA3 c59fa07cb13519481058c05d518cabcb136d05bcc27552fc764470e2fa769bd7

106

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.78455
MD5 19c43cea62a88c8b94904df755355124
SHA1 0485e2a4c93c69989736a8e4cf96c35be5ec3922
SHA256 74ec047b04861aa25b1cb07c8b455c7d93a8ddf0d652209a5b5bfcd521a18907
SHA3 eb1024138d82cedf819fd8de7a6174fcc49cb6ec6e3ce988014f41198eb39bd0

111

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x60
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.48825
MD5 6be4e1387d369cf86e68eacbdd0e81dd
SHA1 351970fe2681b9b35b5d59ad052011ed96a96e17
SHA256 85025c8556952f6a651c2468c8a0d58853b0ba482be9ad5cd3060f216540dfc0
SHA3 45e552e173141e06d113209b6cc915042ad0b4d5531464b8dbe5637029f489cb

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Icon file
MD5 6da8e7d5ae1d5d15e0230a67a7c16c6d
SHA1 678db52cbe5d617c33c6269bfd4b6d8d1a17f956
SHA256 6eb54801f91b6d8effccbfaefe6b2d7705a274a75940e6226e24e0d4ec58c396
SHA3 994fc217c7b8bc8008ac262ff58044403206de6eceafd424d4640ecad395eb2f

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x2ac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26405
MD5 052d59d6c850cbbae5e04c6c056cf6ea
SHA1 3aa14ab8be6dd7667c283e144c936de8e36e826a
SHA256 44ab119325b9e82348224dcfa7bc57fe53397be142d071dbef050fd4c184baf7
SHA3 2bee55d8d33f052cb5d3fe18e9d3f436507bd9d6e6338d0f05692fc5f8f496c8

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x340
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.30022
MD5 edc972c220d4180562831a4f3e0d8c0f
SHA1 51e14a3d5443c4011e1960b064d5b6d527a690d2
SHA256 b86f58a4d62114fb7596cdee0e1e59b830432c93df28c81d26aaa99c946184cc
SHA3 464124d1190b469f69361606dd515eafc128ada3c9aad514b4b820ba90c40fe3

Version Info

Signature 0xfeef04bd
StructVersion 0
FileVersion 0.0.0.0
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Luanti community
FileDescription Luanti self-extracting launcher
FileVersion (#2) 5.16.1
InternalName luanti
LegalCopyright (c) 2010-2026 Perttu Ahola (celeron55) and contributors
ProductName Luanti
Resource LangID English - United States

TLS Callbacks

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0!
Leave a comment

No comments yet.