6d7610b942da2072bde000aca632217d

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2021-Aug-20 12:32:39
TLS Callbacks 2 callback(s) detected.

Plugin Output

Suspicious PEiD Signature: HQR data file
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to internet browsers:
  • IEXPLORE.EXE
  • key3.db
  • signons.sqlite
May have dropper capabilities:
  • CurrentVersion\Run
Miscellaneous malware strings:
  • VIRUS
  • cmd.exe
  • exploit
Contains domain names:
  • .acme.com
  • .example.org
  • 2Fwww.facebook.com
  • BeOpen.com
  • Demos.PySimpleGUI.org
  • HList.info
  • Issues.PySimpleGUI.org
  • PySimpleGUI.org
  • TList.info
  • a.b.c.com
  • activestate.com
  • addinfo.info
  • apple.com
  • blog.cryptographyengineering.com
  • bugs.python.org
  • business.facebook.com
  • buymeacoffee.com
  • cam.ac.uk
  • cl.cam.ac.uk
  • cloud.google.com
  • code.activestate.com
  • crummy.com
  • cryptographyengineering.com
  • cs.ucdavis.edu
  • csrc.nist.gov
  • curl.haxx.se
  • demon.nl
  • docs.python.org
  • eGenix.com
  • editor.org
  • egenix.com
  • en.wikipedia.org
  • example.com
  • example.net
  • example.org
  • facebook.com
  • felt.demon.nl
  • freedesktop.org
  • ftp.python.org
  • ftp://dkuug.dk
  • github.com
  • githubusercontent.com
  • gmail.com
  • google.com
  • graph.facebook.com
  • gustaebel.de
  • here.my.org
  • hg.python.org
  • http://Demos.PySimpleGUI.org
  • http://Issues.PySimpleGUI.org
  • http://blog.cryptographyengineering.com
  • http://blog.cryptographyengineering.com/2012/05/how-to-choose-authenticated-encryption.html
  • http://bugs.python.org
  • http://bugs.python.org/issue14443z
  • http://code.activestate.com
  • http://code.activestate.com/recipes/577452-a-memoize-decorator-for-instance-methods/
  • http://csrc.nist.gov
  • http://csrc.nist.gov/groups/ST/toolkit/BCM/documents/proposedmodes/eax/eax-spec.pdf
  • http://csrc.nist.gov/publications/nistpubs/800-38C/SP800-38C.pdf
  • http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
  • http://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
  • http://curl.haxx.se
  • http://curl.haxx.se/rfc/cookie_spec.html
  • http://docs.python.org
  • http://docs.python.org/3/library/subprocess#subprocess.Popen.kill
  • http://docs.python.org/3/library/subprocess#subprocess.Popen.returncode
  • http://docs.python.org/3/library/subprocess#subprocess.Popen.terminate
  • http://docs.python.org/library/unittest.html
  • http://en.wikipedia.org
  • http://en.wikipedia.org/wiki/Cache_replacement_policies#Least_recently_used_
  • http://en.wikipedia.org/wiki/IEEE_854-1987
  • http://en.wikipedia.org/wiki/Triangular_distribution
  • http://example.com
  • http://google.com
  • http://hg.python.org
  • http://hg.python.org/cpython/file/603b4d593758/Lib/socket.py#l535
  • http://httpbin.org
  • http://json.org
  • http://lists.sourceforge.net
  • http://lists.sourceforge.net/lists/listinfo/optik-users
  • http://opensource.apple.com
  • http://opensource.apple.com/source/CF/CF-744.18/CFBinaryPList.c
  • http://purl.org
  • http://schemas.xmlsoap.org
  • http://schemas.xmlsoap.org/wsdl/z
  • http://speleotrove.com
  • http://support.microsoft.com
  • http://support.microsoft.com/kb/118623
  • http://tip.tcl.tk
  • http://tip.tcl.tk/48
  • http://tools.ietf.org
  • http://tools.ietf.org/html/rfc4880
  • http://tools.ietf.org/html/rfc5297
  • http://tools.ietf.org/html/rfc5869
  • http://tools.ietf.org/html/rfc6125#section-6.4.3
  • http://users.rcn.com
  • http://users.rcn.com/python/download/Descriptor.htm
  • http://web.cs.ucdavis.edu
  • http://web.cs.ucdavis.edu/
  • http://www.apple.com
  • http://www.apple.com/DTDs/PropertyList-1.0.dtd
  • http://www.cl.cam.ac.uk
  • http://www.cl.cam.ac.uk/
  • http://www.crummy.com
  • http://www.crummy.com/software/BeautifulSoup/
  • http://www.crummy.com/software/BeautifulSoup/bs4/doc/
  • http://www.crummy.com/software/BeautifulSoup/bs4/doc/#installing-a-parser
  • http://www.cs.ucdavis.edu
  • http://www.cs.ucdavis.edu/
  • http://www.iana.org
  • http://www.iana.org/assignments/character-sets
  • http://www.iana.org/assignments/tls-parameters/tls-parameters.xml#tls-parameters-6
  • http://www.iana.org/time-zones/repository/tz-link.html
  • http://www.ibiblio.org
  • http://www.ibiblio.org/xml/examples/shakespeare/hamlet.xml
  • http://www.megginson.com
  • http://www.megginson.com/SAX/.
  • http://www.nightmare.com
  • http://www.nightmare.com/squirl/python-ext/misc/syslog.py
  • http://www.ocert.org
  • http://www.ocert.org/advisories/ocert-2011-003.html
  • http://www.phys.uu.nl
  • http://www.phys.uu.nl/
  • http://www.python.org
  • http://www.python.org/'
  • http://www.python.org/dev/peps/pep-%04d/r
  • http://www.python.org/dev/peps/pep-%04d/r7
  • http://www.python.org/dev/peps/pep-0205/
  • http://www.python.org/download/releases/2.3/mro/.
  • http://www.python.org/sax/properties/encodingz3http
  • http://www.python.org/sax/properties/interning-dictN
  • http://www.rfc-editor.org
  • http://www.rfc-editor.org/info/rfc7253
  • http://www.rfc-editor.org/rfc/rfc%d.txtz
  • http://www.robotstxt.org
  • http://www.robotstxt.org/norobots-rfc.txt
  • http://www.tarsnap.com
  • http://www.tarsnap.com/scrypt/scrypt-slides.pdf
  • http://www.w3.org
  • http://www.w3.org/1999/02/22-rdf-syntax-ns#z
  • http://www.w3.org/1999/xhtml
  • http://www.w3.org/1999/xhtmlN
  • http://www.w3.org/1999/xhtmlz+http
  • http://www.w3.org/2000/xmlns/
  • http://www.w3.org/2000/xmlns/r
  • http://www.w3.org/2000/xmlns/z
  • http://www.w3.org/2001/XInclude
  • http://www.w3.org/2001/XMLSchema-instancez
  • http://www.w3.org/2001/XMLSchemaz
  • http://www.w3.org/TR/NOTE-datetime
  • http://www.w3.org/TR/html4/strict.dtd
  • http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd
  • http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
  • http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd'
  • http://www.w3.org/XML/1998/namespace
  • http://www.w3.org/XML/1998/namespacez
  • http://www.xmlrpc.com
  • http://www.xmlrpc.com/discuss/msgReader$1208
  • http://www.xmlrpc.com/discuss/msgReader$1208z
  • http://wwwsearch.sf.net
  • http://wwwsearch.sf.net/
  • http://xml.org
  • http://xml.python.org
  • http://xml.python.org/entities/fragment-builder/internalz
  • http://xmlrpc.usefulinc.com
  • http://xmlrpc.usefulinc.com/doc/reserved.html
  • http://yahoo.com
  • httpbin.org
  • https://business.facebook.com
  • https://business.facebook.com/business/adaccount/limits/?business_id
  • https://business.facebook.com/business_locations/
  • https://business.facebook.com/settings/info?business_id
  • https://cloud.google.com
  • https://cloud.google.com/appengine/docs/flexible/
  • https://cloud.google.com/appengine/docs/python/sockets/
  • https://cloud.google.com/appengine/docs/python/urlfetch
  • https://cloud.google.com/appengine/docs/python/urlfetch/#Python_Quotas_and_limits
  • https://cloud.google.com/appengine/docs/standard/runtimes
  • https://cryptography.io
  • https://docs.python.org
  • https://docs.python.org/
  • https://docs.python.org/%d.%d/libraryNr
  • https://docs.python.org/X.Y/library/
  • https://en.wikipedia.org
  • https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#Cipher-block_chaining_.28CBC.29
  • https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#Cipher_feedback_.28CFB.29
  • https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#Counter_.28CTR.29
  • https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#Electronic_codebook_.28ECB.29
  • https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#Output_feedback_.28OFB.29
  • https://en.wikipedia.org/wiki/CRIME_
  • https://en.wikipedia.org/wiki/Server_Name_Indication
  • https://github.com
  • https://google.com
  • https://graph.facebook.com
  • https://graph.facebook.com/v7.0/act_
  • https://graph.facebook.com/v7.0/me/personal_ad_accounts?fields
  • https://httpbin.org
  • https://m.facebook.com
  • https://m.facebook.com/login/reauth.php?next
  • https://mbasic.facebook.com
  • https://mbasic.facebook.com/
  • https://mbasic.facebook.com/friends/center/requests/#friends_center_main
  • https://packaging.python.org
  • https://packaging.python.org/specifications/entry-points/
  • https://pypi.org
  • https://pysimplegui.readthedocs.io
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#button-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#buttonmenu-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#canvas-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#checkbox-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#column-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#combo-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#frame-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#graph-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#horizontalseparator-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#image-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#input-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#listbox-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#menu-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#multiline-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#optionmenu-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#output-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#pane-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#progressbar-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#radio-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#slider-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#spin-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#statusbar-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#tab-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#tabgroup-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#table-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#text-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#tree-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#verticalseparator-element
  • https://pysimplegui.readthedocs.io/en/latest/call%20reference/#window
  • https://raw.githubusercontent.com
  • https://raw.githubusercontent.com/
  • https://raw.githubusercontent.com/PySimpleGUI/PySimpleGUI/master/
  • https://requests.readthedocs.io
  • https://rss.imagemakeup.net
  • https://rss.imagemakeup.net/rss/popular_youtube
  • https://stackoverflow.com
  • https://tools.ietf.org
  • https://tools.ietf.org/html/rfc2388#section-4.4
  • https://tools.ietf.org/html/rfc3610
  • https://tools.ietf.org/html/rfc5297
  • https://twitter.com
  • https://upload.pypi.org
  • https://upload.pypi.org/legacy/
  • https://urllib3.readthedocs.io
  • https://urllib3.readthedocs.io/en/1.26.x/advanced-usage.html#ssl-warnings
  • https://urllib3.readthedocs.io/en/1.26.x/contrib.html#socks-proxies
  • https://urllib3.readthedocs.io/en/1.26.x/reference/urllib3.contrib.html.
  • https://w3c.github.io
  • https://w3c.github.io/html/sec-forms.html#multipart-form-data
  • https://www.buymeacoffee.com
  • https://www.buymeacoffee.com/PySimpleGUI
  • https://www.facebook.com
  • https://www.facebook.com/
  • https://www.facebook.com/ads/manager/account_settings/information/?act
  • https://www.facebook.com/ads/manager/account_settings/notification_preferences/?act
  • https://www.facebook.com/ads/manager/post_all_adaccount_notifications/
  • https://www.facebook.com/security/2fac/factors/recovery-code/
  • https://www.facebook.com/security/2fac/settings
  • https://www.facebook.com/settings?tab
  • https://www.ibm.com
  • https://www.ibm.com/support/knowledgecenter/en/ssw_aix_61/com.ibm.aix.basetrf1/dlopen.htm
  • https://www.ibm.com/support/knowledgecenter/en/ssw_aix_61/com.ibm.aix.basetrf1/load.htm
  • https://www.ietf.org
  • https://www.ietf.org/rfc/rfc2898.txt
  • https://www.paypal.me
  • https://www.paypal.me/psgui
  • https://www.pyopenssl.org
  • https://www.python.org
  • https://www.python.org'
  • https://www.python.org/dev/peps/pep-0506/
  • https://www.python.org/download/releases/2.3/mro/.
  • https://www.python.org/psf/license/
  • https://www.unicode.org
  • https://www.unicode.org/Public/13.0.0/ucd/DerivedCoreProperties.txt
  • https://www.usenix.org
  • https://www.usenix.org/legacy/events/usenix99/provos/provos_html/node4.html
  • https://www.youtube.com
  • https://www.youtube.com/watch?v
  • ibiblio.org
  • imagemakeup.net
  • jython.org
  • kennethreitz.org
  • la.mastaler.com
  • lemburg.com
  • lists.sourceforge.net
  • logger.info
  • m.facebook.com
  • mastaler.com
  • mbasic.facebook.com
  • megginson.com
  • microsoft.com
  • nightmare.com
  • nightshade.la.mastaler.com
  • ocert.org
  • opensource.apple.com
  • packaging.python.org
  • phys.uu.nl
  • pitrou.net
  • pyopenssl.org
  • python.net
  • python.org
  • pythoncom.com
  • raw.githubusercontent.com
  • red-dove.com
  • redivi.com
  • rfc-editor.org
  • robotstxt.org
  • rss.imagemakeup.net
  • samba.org
  • schemas.xmlsoap.org
  • segfault.org
  • sendmail.org
  • shazow.net
  • skippinet.com.au
  • sockets.ru
  • sourceforge.net
  • speleotrove.com
  • sprymix.com
  • stackoverflow.com
  • support.microsoft.com
  • sweetapp.com
  • tarsnap.com
  • three.org
  • tip.tcl.tk
  • tools.ietf.org
  • twitter.com
  • uCanvas.tk
  • uGraph.tk
  • uHTTPResponse.info
  • uMockResponse.info
  • uOutput.tk
  • ucdavis.edu
  • ufacebook.com
  • unicode.org
  • upload.pypi.org
  • usefulinc.com
  • usenix.org
  • users.rcn.com
  • uwww.PySimpleGUI.org
  • uwww.facebook.com
  • web.cs.ucdavis.edu
  • wikipedia.org
  • www.PySimpleGUI.org
  • www.acme.com
  • www.apple.com
  • www.buymeacoffee.com
  • www.cl.cam.ac.uk
  • www.crummy.com
  • www.cs.ucdavis.edu
  • www.example.com
  • www.facebook.com
  • www.iana.org
  • www.ibiblio.org
  • www.ibm.com
  • www.ietf.org
  • www.jython.org
  • www.megginson.com
  • www.nightmare.com
  • www.ocert.org
  • www.phys.uu.nl
  • www.pyopenssl.org
  • www.python.org
  • www.rfc-editor.org
  • www.robotstxt.org
  • www.tarsnap.com
  • www.unicode.org
  • www.usenix.org
  • www.w3.org
  • www.xmlrpc.com
  • www.youtube.com
  • wwwsearch.sf.net
  • xml.python.org
  • xmlrpc.com
  • xmlrpc.usefulinc.com
  • xmlsoap.org
  • yahoo.com
  • youtube.com
  • zen.co.uk
  • zesty.ca
Suspicious The PE is possibly packed. Unusual section name found: .xdata
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
Info The PE is digitally signed. Signer: ANK Software
Issuer: ANK Software
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 6d7610b942da2072bde000aca632217d
SHA1 eb0f33510ab75eed95076fe70522d35200807279
SHA256 a114f3e417b707a0e98c1baf9d8a3fb3e84e1d9a1b9510e22c880ae2ac749415
SHA3 8f13ed784e2df3396950a18781d0288783500f30813f35ac4af6bf3580f40c02
SSDeep 196608:so06FF4FSN8Q71wTJhpg3Ge4sZFMQIDnqjujxY:706r8QMzLMIDWb
Imports Hash a77c4a08069ca49bec0280e9ed03f8a2

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 11
TimeDateStamp 2021-Aug-20 12:32:39
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 2.0
SizeOfCode 0x125e200
SizeOfInitializedData 0x1c69e00
SizeOfUninitializedData 0x73600
AddressOfEntryPoint 0x00000000000010ED (Section: .text)
BaseOfCode 0x1000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x1ce5000
SizeOfHeaders 0x400
Checksum 0x1c7a108
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x968000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 82389720e3d0c3be7450a33f09ac5d78
SHA1 2b57eb8ea9c5a2018785a3ac31fc667c12eacd99
SHA256 ac25b0ee74e24d76bd4958b62bb7187d326ac31bfd229b6541dcbffd84728d3e
SHA3 7eae74f6e17f413cc987e9ef858f28e23e456dbb00b36506c347c487d5eadbf0
VirtualSize 0x125e108
VirtualAddress 0x1000
SizeOfRawData 0x125e200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.90747

.data

MD5 fd3bd330dc7b1bf3f5f340fb3f098f60
SHA1 b9ffba4752d74de565365ef4946e124db746fcfa
SHA256 1c5d782ae3e69e10dbd89315086507d0f29b3f9769ff3e321de795a7788d1055
SHA3 6db99208cb7af3ed4768adf7ccd2289064e3d66bc4bec96424dd825d77a2eaf2
VirtualSize 0xeda0
VirtualAddress 0x1260000
SizeOfRawData 0xee00
PointerToRawData 0x125e600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.39176

.rdata

MD5 7823ac1b96a03f0e2da24c41c824c848
SHA1 a9f7a29d5e90431edd5511069d57fc9e1f18ca77
SHA256 aac44d9bbe30620921518e593c673b9d8c2d4363627143fada073b674af5cffe
SHA3 cb5bb31705670ae2fae6acf3a8897b479b86c5d206c3463be13e5e6123eb7bd4
VirtualSize 0x231d0
VirtualAddress 0x126f000
SizeOfRawData 0x23200
PointerToRawData 0x126d400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.91794

.eh_fram

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x4
VirtualAddress 0x1293000
SizeOfRawData 0x200
PointerToRawData 0x1290600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.pdata

MD5 6201803cf2320326b41f754e5bf2479e
SHA1 8ae54f0f8afb83040f60990c69edd267c1ac9112
SHA256 6864306ba3288e3016c01fcedbd1bb25c81ff81b8096f9092bfdbc29ada2e64f
SHA3 233ab7a0029d26593e73a47090d2ce8c961d015f4225680dacfbaa4f69321f03
VirtualSize 0x16458
VirtualAddress 0x1294000
SizeOfRawData 0x16600
PointerToRawData 0x1290800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.60737

.xdata

MD5 ce2e99d915c6d2019b5b1bbc27108c1d
SHA1 bf1245c0fc5c283005978a927b2a6f8bd9167478
SHA256 0bba98924f86639a3ef50b258f0d4faac028434739296afa86cc53a7bd29a17c
SHA3 44b87573191e4c47bd0216dda32485869bdaf11eb8261231b440df7fc4890007
VirtualSize 0x21c9c
VirtualAddress 0x12ab000
SizeOfRawData 0x21e00
PointerToRawData 0x12a6e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.79867

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x735c0
VirtualAddress 0x12cd000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 03eac331aefd6bd01833586afe093c28
SHA1 6416e964d1d1d61ec07f57fa5bdcb03b626a1a93
SHA256 48b0e5b3723aecd4d42dc2f8164b9c482ef36bd70e629945c9bd1b8a6cf7d2e3
SHA3 3f6fa5f266e2ea5eea6bf9eb9e5ec58f86078d4a0cf64829959bee1269c1339f
VirtualSize 0x37d4
VirtualAddress 0x1341000
SizeOfRawData 0x3800
PointerToRawData 0x12c8c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.95453

.CRT

MD5 bb67ced207f329e806f07fd61cb93535
SHA1 c0175c9ec45bfe3b872d79cec712428659b2f0c8
SHA256 0ad589db4898cf36abbe9bcea6b85f62e8d7f7ab28bde7bc153cd87f7787326e
SHA3 f3d4f95368c7825496f92a8d817fb880f474cbc59b7210d8c02b9633dc6eded5
VirtualSize 0x68
VirtualAddress 0x1345000
SizeOfRawData 0x200
PointerToRawData 0x12cc400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.335931

.tls

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0x1346000
SizeOfRawData 0x200
PointerToRawData 0x12cc600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 fa0284df161d4d603def85d050b95a2f
SHA1 d40bf5066e390cb51aeddae6d202bb668f861eb8
SHA256 dfe4b6e0743925d21d109da184fd3c44bb56c18c17cfc089ada165ad04a0180c
SHA3 ff4e0e51f27bf86210783062be30225a97065a923afd5869229ef05765434322
VirtualSize 0x99d900
VirtualAddress 0x1347000
SizeOfRawData 0x99da00
PointerToRawData 0x12cc800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.63056

Imports

KERNEL32.dll DeleteCriticalSection
EnterCriticalSection
FindResourceA
FormatMessageA
FreeLibrary
GetCommandLineW
GetCurrentProcessId
GetLastError
GetModuleFileNameW
GetModuleHandleA
GetProcAddress
GetShortPathNameW
GetStartupInfoA
GetSystemTimeAsFileTime
GetTempPathW
InitializeCriticalSection
IsDBCSLeadByteEx
LeaveCriticalSection
LoadLibraryA
LoadLibraryExW
LoadResource
LockResource
MultiByteToWideChar
SetDllDirectoryW
SetErrorMode
SetUnhandledExceptionFilter
Sleep
TlsGetValue
VirtualProtect
VirtualQuery
WideCharToMultiByte
msvcrt.dll __C_specific_handler
___lc_codepage_func
___mb_cur_max_func
__argc
__argv
__getmainargs
__initenv
__iob_func
__lconv_init
__set_app_type
__setusermatherr
_acmdln
_amsg_exit
_cexit
_commode
_errno
_fmode
_initterm
_itoa_s
_lock
_onexit
_snprintf
_unlock
_wcsicmp
abort
atoi
calloc
exit
fprintf
fputc
free
fwrite
getenv
localeconv
malloc
mbstowcs
memcmp
memcpy
memset
puts
signal
strchr
strcmp
strerror
strlen
strncmp
strncpy
strrchr
vfprintf
wcscmp
wcslen
SHELL32.dll CommandLineToArgvW
python38.dll PyObject_GC_Del
_PyObject_GC_Resize
_PyObject_GC_New
_PyObject_GC_Malloc
PyObject_GC_UnTrack
PyObject_GC_Track
_PyTraceMalloc_NewReference
PyIter_Next
PyObject_GetIter
PyObject_IsSubclass
PyObject_IsInstance
PyMapping_Check
PySequence_Contains
PySequence_List
PySequence_Tuple
PySequence_GetItem
PySequence_InPlaceConcat
PySequence_Check
PyNumber_ToBase
PyNumber_Float
PyNumber_Long
PyNumber_AsSsize_t
PyNumber_Index
PyNumber_Invert
PyNumber_Positive
PyNumber_Negative
PyNumber_InPlaceMultiply
PyNumber_InPlaceAdd
PyNumber_InPlaceLshift
PyNumber_FloorDivide
PyNumber_Add
PyNumber_Subtract
PyBuffer_Release
PyObject_GetBuffer
PyObject_DelItem
PyObject_SetItem
PyObject_GetItem
PyObject_LengthHint
PyObject_Size
PyBool_Type
_Py_FalseStruct
_Py_TrueStruct
_PyByteArray_empty_string
PyByteArray_Type
PyByteArray_FromStringAndSize
PyByteArray_FromObject
PyBytes_Type
_PyBytes_Resize
PyBytes_FromString
PyBytes_FromStringAndSize
PyObject_CallFunctionObjArgs
PyObject_CallMethodObjArgs
PyObject_CallObject
PyObject_Call
PyCapsule_New
PyMethod_Type
PyCode_Type
PyCode_NewWithPosOnlyArgs
PyComplex_Type
PyComplex_FromDoubles
PyProperty_Type
PyDict_Type
PyDict_DelItemString
PyDict_SetItemString
PyDict_GetItemString
PyDict_Copy
PyDict_Merge
PyDict_MergeFromSeq2
PyDict_Next
PyDict_DelItem
PyDict_SetItem
PyDict_GetItem
_PyDict_NewPresized
PyDict_New
PyEnum_Type
PyReversed_Type
PyExc_ImportWarning
PyExc_Exception
PyExc_KeyError
PyExc_RuntimeError
PyExc_IOError
PyExc_UnboundLocalError
PyExc_PermissionError
PyExc_AttributeError
PyExc_ZeroDivisionError
PyExc_ValueError
PyExc_BaseException
PyExc_OverflowError
PyExc_UnicodeError
PyExc_UnicodeDecodeError
PyExc_IsADirectoryError
PyExc_SyntaxError
PyExc_StopIteration
PyExc_OSError
PyExc_NotImplementedError
PyExc_StopAsyncIteration
PyExc_TypeError
PyExc_NameError
PyExc_LookupError
PyExc_IndexError
PyExc_UnicodeEncodeError
PyExc_ImportError
PyExc_SystemError
PyExc_AssertionError
PyExc_GeneratorExit
PyExc_FileNotFoundError
PyExc_ModuleNotFoundError
PyException_SetContext
PyException_GetContext
PyException_SetCause
PyException_GetTraceback
PyFloat_Type
PyFloat_FromString
PyFloat_FromDouble
PyFrame_Type
PyFrame_New
PyFrame_GetLineNumber
PyFunction_Type
_PyAsyncGenWrappedValue_Type
PyCoro_Type
PyGen_Type
PyAsyncGen_Type
_PyGen_FetchStopIterationValue
_PyGen_SetStopIterationValue
PySeqIter_Type
PyCallIter_Type
PyList_Type
PyList_Insert
PyList_SetItem
PyList_New
PyLong_Type
PyLong_FromUnicodeObject
PyLong_FromString
PyLong_FromSsize_t
PyLong_FromUnsignedLongLong
PyLong_FromLongLong
PyLong_FromVoidPtr
PyLong_AsLong
PyLong_AsLongAndOverflow
PyLong_FromLong
_PyLong_New
PyMemoryView_Type
PyCFunction_Type
PyCFunction_NewEx
PyModule_Type
PyModuleDef_Type
PyModule_GetDef
PyModule_GetFilenameObject
PyModule_GetName
PyModule_GetDict
PyModule_ExecDef
PyModule_FromDefAndSpec2
PyModule_NewObject
_Py_NoneStruct
_Py_NotImplementedStruct
_Py_Dealloc
PyObject_Dir
PyCallable_Check
PyObject_IsTrue
PyObject_GenericSetAttr
PyObject_GenericGetAttr
PyObject_SelfIter
PyObject_SetAttr
PyObject_GetAttr
PyObject_SetAttrString
PyObject_HasAttrString
PyObject_GetAttrString
PyObject_RichCompareBool
PyObject_RichCompare
PyObject_Str
PyObject_Repr
_PyObject_New
_Py_tracemalloc_config
PyObject_Free
PyObject_Realloc
PyObject_Malloc
PyMem_Realloc
PyMem_Malloc
PyRange_Type
PyFrozenSet_Type
PySet_Type
_PySet_NextEntry
PySet_Add
PyFrozenSet_New
PySet_New
PySlice_Type
_Py_EllipsisObject
PyEllipsis_Type
PySlice_New
PyStructSequence_InitType
PyStructSequence_SetItem
PyStructSequence_New
PyTuple_Type
PyTuple_Pack
PyTuple_New
PyBaseObject_Type
PySuper_Type
PyType_Type
PyType_Ready
_PyType_Lookup
PyType_GetFlags
PyType_IsSubtype
PyUnicode_Type
PyUnicode_InternInPlace
PyUnicode_Format
PyUnicode_Substring
PyUnicode_Concat
PyUnicode_Join
PyUnicode_FindChar
PyUnicode_Find
PyUnicode_DecodeUTF8
PyUnicode_GetLength
PyUnicode_AsUnicode
PyUnicode_AsUTF8
PyUnicode_FromEncodedObject
PyUnicode_FromOrdinal
PyUnicode_FromFormat
PyUnicode_FromString
PyUnicode_FromStringAndSize
PyUnicode_FromWideChar
_PyUnicode_Ready
PyUnicode_New
PyObject_ClearWeakRefs
_PyWarnings_Init
PyErr_WarnEx
PyMap_Type
PyFilter_Type
PyZip_Type
PyEval_GetFuncName
PyEval_GetFrame
PyEval_EvalCodeEx
PyEval_EvalFrameEx
PyEval_EvalCode
Py_MakePendingCalls
PyEval_SaveThread
PyEval_AcquireThread
PyEval_ThreadsInitialized
PyErr_WriteUnraisable
PyErr_Format
PyErr_SetFromErrno
PyErr_NoMemory
PyErr_BadArgument
_PyErr_FormatFromCause
PyErr_NormalizeException
PyErr_ExceptionMatches
PyErr_GivenExceptionMatches
PyImport_FrozenModules
_PyArg_NoKeywords
PyArg_UnpackTuple
PyArg_ParseTupleAndKeywords
PyArg_ParseTuple
PyImport_ImportModule
PyImport_ImportFrozenModule
PyImport_ExecCodeModuleEx
PyImport_ExecCodeModule
_PyImport_FixupExtensionObject
PyImport_GetModule
PyImport_GetModuleDict
Py_NoSiteFlag
Py_NoUserSiteDirectory
Py_DontWriteBytecodeFlag
Py_DebugFlag
Py_BytesWarningFlag
Py_VerboseFlag
Py_OptimizeFlag
Py_UTF8Mode
Py_InteractiveFlag
Py_InspectFlag
Py_IgnoreEnvironmentFlag
Py_FrozenFlag
PyMarshal_ReadObjectFromString
_Py_PackageContext
PyModule_AddObject
Py_BuildValue
PyOS_snprintf
Py_SetPythonHome
Py_SetPath
Py_Exit
Py_Initialize
PyThreadState_Get
Py_CompileStringExFlags
PyErr_Print
PyErr_PrintEx
PySys_WriteStderr
PySys_SetArgv
PySys_SetPath
PySys_SetObject
PySys_GetObject
PyTraceBack_Type

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.66858
MD5 111260069e99e56b4ff21f023e50ea1e
SHA1 c5400f4388582c8b596044c0461be68250f99dad
SHA256 bd4ea11622f9d15bccafad068cb6fc0dfa8edd97e42b193a8f3c708095bdb04a
SHA3 cbf4e022b3d7af7123b8bd8ee4dd9914a4a7aca768cfe007c997ba6413c360c2

2

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.72979
MD5 631d13da983b9d82b984c527285eb792
SHA1 5aee8595fa9d8dd81c47becc7cbd1f9712db0330
SHA256 741cfb717f5ed68e47fee8025541c96104a13d75a2bc67aef4f16e4defabb06c
SHA3 e48131f87aabfe645b61a5ae0e49f2d184e179c70faa08f7ff5f0f838351a2dc

3

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.67663
MD5 55729cfb067a7917dd9dcb360ce14c9c
SHA1 90dfa0369c8eeb835477a335de2a1d0967adca13
SHA256 e0db25bf66a8d54804e3dc888ba7b90cb5ebbffdf9c4e67a69d3ce00d8f61f76
SHA3 fcf545bcdb3754a5ba93db4baa25341ae8b1c91fef3321ef08410c020f344c65

4

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.53318
MD5 ab7d97e706c86b2780a3133761c47855
SHA1 4034a5fcbb8b8c64baa7131e33bed4a9a12ddb4c
SHA256 c61bd85ad270f16591fa889092a0aeb896d884b59a4d2ae30c7585381418006f
SHA3 46df9d7f336fc022cb86d4fac9dbab9b69c45a16d28a380b8ff4e98f625738c8

5

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x18421
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99288
Detected Filetype PNG graphic file
MD5 91fa8f999c63b8a470db8d4263cea3d9
SHA1 aa64aec89c919a0fc69d101128ec0924b07bf4b3
SHA256 2edabb2509a8b6a3a967d148e7b281f825e95c7ec5fe45963a8170b81e7dfd76
SHA3 3c31c0e116a030568a068e9c5d807821c06c955a929cb2cf917d2ef2c78e62f0

3 (#2)

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x980ea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.57447
MD5 549845da87b88b83b3ae3a6b9816bda8
SHA1 89f41632e833f8e246d0a768f4ea7a3249298858
SHA256 aa0ec72eb9e32c5f858b32fd81382d91a25f087ddf725992c0274cf964b01933
SHA3 0a8b82478391bb1c343d05cfab781c923ddc7b2e5d5e5483b61e5464f2e1ad39

1 (#2)

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.67841
Detected Filetype Icon file
MD5 67573d91d64ffeff08aa2afe4de08c55
SHA1 e4861f5876e1cb7d13144c57ad041e4944907f1a
SHA256 eb1d332d7aa87315b341448d13a7f82a06305901dd3719b8761413c5ad3ebfe8
SHA3 744dc165dfd56912317372b52e5bfc1bf78e5a5fa806ce02b596bb5628bff88a

Version Info

TLS Callbacks

StartAddressOfRawData 0x1746000
EndAddressOfRawData 0x1746008
AddressOfIndex 0x173faa0
AddressOfCallbacks 0x1745040
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks 0x0000000001654220
0x00000000016542DF

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0!
<-- -->