6b61177f52a0bb6b2cc4f3a3c5b773e50aaa4b636d8aa1c26a7d68a6e96a5202

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Jul-20 17:21:21
Detected languages English - United States

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to security software:
  • rshell.exe
May have dropper capabilities:
  • CurrentVersion\Run
Contains domain names:
  • github.com
  • https://github.com
Malicious The PE contains functions mostly used by malware. Can access the registry:
  • RegOpenKeyExW
  • RegCloseKey
  • RegSetValueExW
Possibly launches other programs:
  • ShellExecuteW
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
Has Internet access capabilities:
  • URLDownloadToFileW
Manipulates other processes:
  • OpenProcess
Malicious VirusTotal score: 10/69 (Scanned on 2026-07-21 21:26:08) Bkav: W32.Malware.54F87225
CrowdStrike: win/malicious_confidence_60% (W)
ESET-NOD32: Generik.DMNKCZ trojan
Kaspersky: not-a-virus:RiskTool.Win64.BitCoinMiner.isle
McAfeeD: ti!6B61177F52A0
Microsoft: Trojan:Win32/Wacatac.B!ml
SentinelOne: Static AI - Suspicious PE
Skyhigh: BehavesLike.Win64.Dropper.pm
Symantec: ML.Attribute.HighConfidence
TrellixENS: Artemis!38ABFE25A8EF

Hashes

MD5 38abfe25a8ef9182601e410653457d8d
SHA1 a398375ae48e62a20d315e277b9b4c8ccedc0fbe
SHA256 6b61177f52a0bb6b2cc4f3a3c5b773e50aaa4b636d8aa1c26a7d68a6e96a5202
SHA3 f1cb94a6daeb022d5c6a44e416f5cbc24f5a49bf77e373d003edf946a3129b61
SSDeep 768:UjnCxakym8xACyv9NsqPYMlhZRuZgDo3c05uGmfxgcp:s7hyEqpbuZgDoX5ulqW
Imports Hash 53e56ef1758b667e5210ec0b7465dcb1

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jul-20 17:21:21
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x5400
SizeOfInitializedData 0x6600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000000587C (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x11000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 9e7fb434fc7286e7f8e728688404035a
SHA1 8cf45a3e594ba1a33b31f2fa59e90ce90b5f8cca
SHA256 96efbf7a9044ec15812b9a2a71ac01d528ea4ad45b2cdff49e6b823eb5dd3eec
SHA3 7bc7d3a08e02761e2451f5141c1ae7c529fdb43e10c894ece72f2a4e69efb695
VirtualSize 0x5282
VirtualAddress 0x1000
SizeOfRawData 0x5400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.32745

.rdata

MD5 c200497c3c4140655f13f9f0020b3cb3
SHA1 fd53dd2c58bad5c350b89612701396d274e695a8
SHA256 3df82a9c899cdcd415b1184213aef4152aa5d93daa24a984286de8723cdfac2e
SHA3 409ace8a67f61f4953be306bfd6bd6bc26b80ac9fe0a88d6878d92a236a2a1de
VirtualSize 0x5438
VirtualAddress 0x7000
SizeOfRawData 0x5600
PointerToRawData 0x5800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.76955

.data

MD5 27659c0b773a49c7bb913b3b70f04a08
SHA1 5663c1186e5509deef377f4af1ed92cf1c4b182d
SHA256 65607e82c2565ca388a98347fb7b098afa04a03846d5259a49caf5257e70f347
SHA3 4f22df97a04a49006caf2438769543c3acad0f40f7a6bdf0c6514444b7e5f71d
VirtualSize 0x1d8
VirtualAddress 0xd000
SizeOfRawData 0x200
PointerToRawData 0xae00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.11268

.pdata

MD5 4d6c0a9ace79b01fe1729006244b1296
SHA1 d43385d56c907097e4ff6a1fe5380f7b05a6d976
SHA256 85ab49038c5c23b65a9de99783116fd338a0721ec37da72d73d5cc9ae9b40183
SHA3 518aa3fa938e01a3df60fa92483d3a64a02d2323dbfbf8c6220d8f335d5da3fb
VirtualSize 0x414
VirtualAddress 0xe000
SizeOfRawData 0x600
PointerToRawData 0xb000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.12605

.rsrc

MD5 c5c9d1dffa19d5651ce31eeb0064f8f0
SHA1 048791308911e8e82c819bd0313478a6ee376c34
SHA256 c4eeb7a8dc8603a1741e39ab3da03d568549db33cb1a3fe946005675afff5022
SHA3 787ef6ecf6f2ba29f82ead18aff2df793dcca8e8aee6c5ace5e569895b13d26d
VirtualSize 0x4d0
VirtualAddress 0xf000
SizeOfRawData 0x600
PointerToRawData 0xb600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.72474

.reloc

MD5 d265b87f755aadcc479bebb0579d3ffb
SHA1 b48e288732ad567cd4e6f3f72f580fe6a0620a80
SHA256 02a6b7b84adc03d19c1f1fe6a9d5127c825e680c8bfcd7ff2ac2c878d0d04ee2
SHA3 344cd93f1acf1af0b13c01944069b1931e0cad2e11c4a6537cc2ea4e10673925
VirtualSize 0x68
VirtualAddress 0x10000
SizeOfRawData 0x200
PointerToRawData 0xbc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.37357

Imports

KERNEL32.dll WriteConsoleOutputCharacterW
SetConsoleTitleW
SetUnhandledExceptionFilter
InitializeSListHead
GetSystemTimeAsFileTime
GetCurrentProcessId
QueryPerformanceCounter
GetConsoleScreenBufferInfo
FillConsoleOutputAttribute
FillConsoleOutputCharacterW
FreeConsole
QueryFullProcessImageNameW
SetConsoleCursorPosition
GetModuleHandleW
GetModuleFileNameW
OpenProcess
Sleep
CloseHandle
CreateDirectoryW
GetCurrentThreadId
GetStdHandle
USER32.dll GetWindowRect
GetClientRect
TranslateMessage
GetWindowTextW
GetForegroundWindow
FillRect
GetWindowThreadProcessId
LoadCursorW
EndPaint
DrawTextW
DefWindowProcW
BeginPaint
DispatchMessageW
GetAsyncKeyState
SetWindowPos
SetLayeredWindowAttributes
ShowWindow
DestroyWindow
CreateWindowExW
RegisterClassExW
PeekMessageW
GDI32.dll CreateFontW
SetTextColor
CreatePen
CreateSolidBrush
SetBkMode
SelectObject
RoundRect
DeleteObject
SHELL32.dll ShellExecuteW
SHGetFolderPathW
ADVAPI32.dll RegOpenKeyExW
RegCloseKey
RegSetValueExW
urlmon.dll URLDownloadToFileW
MSVCP140.dll ?_Throw_Cpp_error@std@@YAXH@Z
_Cnd_do_broadcast_at_thread_exit
_Thrd_id
_Thrd_detach
_Query_perf_frequency
_Query_perf_counter
?_Xout_of_range@std@@YAXPEBD@Z
?_Xlength_error@std@@YAXPEBD@Z
_Thrd_join
VCRUNTIME140.dll __current_exception_context
__current_exception
__C_specific_handler
memcmp
memset
memmove
memcpy
__std_exception_copy
_CxxThrowException
__std_exception_destroy
VCRUNTIME140_1.dll __CxxFrameHandler4
api-ms-win-crt-string-l1-1-0.dll towlower
wcslen
api-ms-win-crt-runtime-l1-1-0.dll _c_exit
_cexit
__p___wargv
__p___argc
_exit
_initialize_onexit_table
_register_onexit_function
_crt_atexit
exit
terminate
_initterm_e
_register_thread_local_exe_atexit_callback
_beginthreadex
_initterm
_configure_wide_argv
_set_app_type
_seh_filter_exe
_get_initial_wide_environment
_initialize_wide_environment
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
_callnewh
malloc
free
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
api-ms-win-crt-stdio-l1-1-0.dll _set_fmode
__p__commode
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x46e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.15713
MD5 bb454eb621bbd35f2bb0d4362b8e6317
SHA1 121f62de96752eba9a8ac88e03e266b6cdf74871
SHA256 ba5281f8f723d6cb91bb9fe1353afb68edf620f6cc3476bb9b119774b82e8b04
SHA3 5e74b760781c073b1d9246fd4d20fb6f351143549300344bea371f58ee153a46

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-20 17:21:21
Version 0.0
SizeofData 720
AddressOfRawData 0xac5c
PointerToRawData 0x945c

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14000d000

RICH Header

XOR Key 0x8e2e7c2
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 12
ASM objects (35403) 4
C objects (35403) 10
C++ objects (35403) 28
Imports (35403) 6
Imports (33145) 13
Total imports 121
C++ objects (35728) 1
Resource objects (35728) 1
Linker (35728) 1

Errors

Leave a comment

No comments yet.