6e1953433d891db10790aafcced19b30

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Sep-29 07:36:13
Detected languages English - United States
TLS Callbacks 3 callback(s) detected.
CompanyName Google Chrome
FileTitle chrome_exe
FileDescription Google Chrome
FileVersion 129,0,6668,60
LegalCopyright Copyright 2024 Google LLC. All rights reserved.
LegalTrademark
ProductName Google LLC
ProductVersion 129,0,6668,60

Plugin Output

Suspicious The PE is possibly packed. Unusual section name found: .text0
Unusual section name found: .text1
Unusual section name found: .text2
The PE only has 2 import(s).
Malicious The program tries to mislead users about its origins. The PE pretends to be from Google but is not signed!
Malicious VirusTotal score: 49/71 (Scanned on 2024-10-01 08:01:40) ALYac: Trojan.GenericKD.74215355
AVG: Win64:Evo-gen [Trj]
AhnLab-V3: Trojan/Win.Miner.C5674474
Alibaba: Trojan:Win32/Miner.0cb9f6f0
Antiy-AVL: Trojan[Packed]/Win64.VMProtect
Arcabit: Trojan.Generic.D46C6FBB
Avast: Win64:Evo-gen [Trj]
Avira: TR/Miner.qwkut
BitDefender: Trojan.GenericKD.74215355
Bkav: W64.AIDetectMalware
CTX: exe.trojan.vmprotect
CrowdStrike: win/malicious_confidence_90% (D)
Cylance: Unsafe
Cynet: Malicious (score: 99)
DeepInstinct: MALICIOUS
DrWeb: Trojan.Siggen29.44767
ESET-NOD32: a variant of Win64/Packed.VMProtect.AC suspicious
Emsisoft: Trojan.GenericKD.74215355 (B)
F-Secure: Trojan.TR/Miner.qwkut
FireEye: Generic.mg.6e1953433d891db1
Fortinet: Riskware/Application
GData: Trojan.GenericKD.74215355
Google: Detected
Gridinsoft: Trojan.Win64.XMRig.tr
Ikarus: PUA.VMProtect
K7AntiVirus: Trojan ( 005aeb761 )
K7GW: Trojan ( 005aeb761 )
Lionic: Trojan.Win32.VMProtect.4!c
Malwarebytes: Trojan.BitCoinMiner
McAfee: Artemis!6E1953433D89
McAfeeD: Real Protect-LS!6E1953433D89
MicroWorld-eScan: Trojan.GenericKD.74215355
Microsoft: Trojan:Win64/Coinminer!rfn
Paloalto: generic.ml
Rising: Trojan.Agent!8.B1E (TFE:5:FkFUO8h2JGR)
Sangfor: CoinMiner.Win64.Agent.Vcyn
Skyhigh: BehavesLike.Win64.Generic.vc
Sophos: Mal/Generic-S
Symantec: Trojan Horse
Tencent: Win32.Trojan.Miner.Wimw
Trapmine: malicious.moderate.ml.score
TrendMicro: Trojan.Win64.PRIVATELOADER.YXEI3Z
TrendMicro-HouseCall: Trojan.Win64.PRIVATELOADER.YXEI3Z
VIPRE: Trojan.GenericKD.74215355
Varist: W64/ABApplication.TRJX-4860
VirIT: Trojan.Win64.Agent.HHP
Webroot: W32.Backdoor.Gen
Xcitium: ApplicUnwnt@#2jgnjgqon12id
alibabacloud: Miner:Win/Miner.bpnVv

Hashes

MD5 6e1953433d891db10790aafcced19b30
SHA1 c46581f4673f068a357b76fbe1bfd1909b81d79f
SHA256 af708267cf479834fbd0811c58facd377ccd0226a3733ae9f6e086813e68bcfa
SHA3 ad6b32987672e446c9a587555f650e929d246f62cacd8a0bcb326f0dfa0b91ee
SSDeep 196608:RSsIH57c1MGDV4QUT5pgLifA3d5Lb36QavG9bt5h1VLwklfXs1GlPhkv6b:RBo7nGDHM5SLio3d9Gg95PbBXVlpkva
Imports Hash 3fac356340f08f787f93cbf317f090cd

DOS Header

e_magic MZ
e_cblp 0x78
e_cp 0x1
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x78

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 10
TimeDateStamp 2024-Sep-29 07:36:13
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x8200
SizeOfInitializedData 0xcd0800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000011EA501 (Section: .text2)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x19ac000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x8166
VirtualAddress 0x1000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ

.rdata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x1eb8
VirtualAddress 0xa000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ

.data

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0xc9ea28
VirtualAddress 0xc000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.pdata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x180
VirtualAddress 0xcab000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ

.00cfg

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x10
VirtualAddress 0xcac000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x10
VirtualAddress 0xcad000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.text0

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x28e7cc
VirtualAddress 0xcae000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ

.text1

MD5 1e01ecd75a29f7b4e4bbc5712b57ed65
SHA1 3620ceeb75ffb5435ce2fe7f421c54bb62293cad
SHA256 4f8f312b089977c886479b51c9c2c8682dbc547e55e5f7d6e3018d959be8dce0
SHA3 a3d7472c52e76f89c1efc8fbda56e9ddebc565b6cc6e6739580bee644746958d
VirtualSize 0x58
VirtualAddress 0xf3d000
SizeOfRawData 0x200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.142636

.text2

MD5 c979e0e09fa9106cca6afe10461f26e3
SHA1 880121244111137e86ca323447d18581a8e90eca
SHA256 56d7e6740ff7501460ed480e612b578d7b8e043d5040a5de458ab2b0fa49d8c1
SHA3 85a19b5f50504c8edc443986aae46d5f23796522e89112849217b41cd762c859
VirtualSize 0xa3ca50
VirtualAddress 0xf3e000
SizeOfRawData 0xa3cc00
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
Entropy 7.97552

.rsrc

MD5 3b3bb02c006da329d6e5e19107c1f594
SHA1 ea41ff74aa8b08850cd78e51fcce338e239ff1d0
SHA256 45d6f4818f564ddf6436e0744505508efc1949cdd3f76967195dd4966a6657a5
SHA3 3c1b2abe97d185453e93ac42a1290153c3a84366ff2287d29d530ee09c79ab0f
VirtualSize 0x304d0
VirtualAddress 0x197b000
SizeOfRawData 0x30600
PointerToRawData 0xa3d200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.88652

Imports

msvcrt.dll __C_specific_handler
KERNEL32.dll DeleteCriticalSection

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x872e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.96842
Detected Filetype PNG graphic file
MD5 99122806e2b92d5e813ecdfd8517967c
SHA1 0d11c1fad5d3e4b4970873141d8656cb9cd4e0d5
SHA256 acaa57e1d3184fe0c96bb99faf3bc8dee91cd88cfb759929874418023608acd7
SHA3 12350c0fd5f96e847f3b6f8469fb37d98b65c3bb5e0c3a2988c08307ce599b9f

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.04851
MD5 f8eae2c55cd3af122817338c580c7a72
SHA1 cc6e10afc80680d1e81ba39bc97961ae238e58da
SHA256 0160fb0a681b6d9f0a4039911836b50559d21d0b4bf077c7f52bf9269bff9976
SHA3 dc4e06523e891573e00d6e0bfcb521d6e013c5362c9b99719d80293a21f5c081

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.27785
MD5 d8a478924f2e318676a4df907df42ff4
SHA1 1341c1aa747a71728d22684e136c2e9f53e4d04f
SHA256 35fe746bf7a04d3667cda1f509b1c8c5b0ab8ec2437940128ffa5ba18b0743e2
SHA3 ff4b9a070b9076c275553c8831f8ed31609f2d3976b0cff1bca1231a72b145bf

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5488
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.23003
MD5 7aa54d1920b3263d9f02ff611873b873
SHA1 fa8eac0614a35d97b96347e9d35e744571fad3b5
SHA256 f88c84eac747a98428f6a07ce9d6d27010f5873c59dc2769d07215cb2ff81efc
SHA3 884b976e967070d51e56238523b4ab6e3d3f494ef7003b5ceec5335560869fa8

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.21522
MD5 78fe129372867e6940ab2377501aeafd
SHA1 4fc933cd4e2852d072028896158f216a9207bebc
SHA256 488d7b5d0e6da59a0662b9d064776ab09ea26502136b4d9cfed49d33235499a4
SHA3 71efc71d139a6626b97045054a43fcef822537074cde60912a221e4e1d4602ee

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.28461
MD5 f5a665b3a25213414d8c24588adda635
SHA1 64e65ff20177b95f047a58a1a0fb8a7146806c9c
SHA256 c9abb61c85b033234230660467d85470ef4a2ed7ef68e7d5e0bb9f37304a52d9
SHA3 e20d142cb43eca38fd24bdb7228a2c32856f157c35a0d7d4e33460185ec86367

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.34694
MD5 5018e9f400c1230d80292add87216e34
SHA1 8d5108f69654afb280b5f6db6083a5bff56a78bf
SHA256 524dc97b33b57a03bb62246063fc03f629bcf95bd6b1839eb2868b41d34eeefe
SHA3 51d064a807d6a90bf92f09d676722ec1755304e4580931e97fe6e7cb1e48c00e

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.5176
MD5 4bbe8626b942a096219f5a01c8962582
SHA1 18e51d4f87f05b1ed3272051f31c9e5368d629b3
SHA256 42ab8b4a4b552e44048580da7fd2e1940c3398103dcf46cbdc6db8dcdac406ac
SHA3 97bd0b9af7dbd15ed644d7f4f046fdec6b85db2b4bcf2cfad766955a3ee34e9c

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.61832
MD5 9da8c3cfd4c232339b39079b43e161e8
SHA1 0048ea1336c7a8ff24e1b734f687c6c666c0afcf
SHA256 f15075e3f22073788401aef933522abec13c52a36ed46fdbf853fbab0acce948
SHA3 b48abbd3e290ce68d3ac2dacf8594c180a4df773e5dbbd81555e1e8296fae791

1 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.03466
Detected Filetype Icon file
MD5 7b014dbf5879bd5faa7254852f963c21
SHA1 8f0c2f8524716b4d849a015a591ba9f9b80e9427
SHA256 468cc1d22830794ae3cd7896e0b2e8f317896c05e9fbd49219efbd731cdc1b9a
SHA3 29c0ec8a5c40526f2ab5f241d340a214b2a8a923b57c772004f4f5c3184ce200

1 (#3)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x2f0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.40063
MD5 3c9bdf892212d1be2ae975329c80d118
SHA1 8d51141fa0d5a8e781705addab50883b94bb83f7
SHA256 143eaa24aedc2c2d33885c285f6adc116f627f9cc60343702b046bc2efdd66ba
SHA3 5ee52715d5d3e3baa3c00e6c4a909964802cb8b0219f89676dc7d3ffdb06d981

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 129.0.6668.60
ProductVersion 129.0.6668.60
FileFlags (EMPTY)
FileOs (EMPTY)
FileType VFT_UNKNOWN
Language English - United States
CompanyName Google Chrome
FileTitle chrome_exe
FileDescription Google Chrome
FileVersion (#2) 129,0,6668,60
LegalCopyright Copyright 2024 Google LLC. All rights reserved.
LegalTrademark
ProductName Google LLC
ProductVersion (#2) 129,0,6668,60
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x140f3d020
EndAddressOfRawData 0x140f3d028
AddressOfIndex 0x140ca99a8
AddressOfCallbacks 0x140f4b898
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x0000000140FC0BA9
0x0000000140001760
0x00000001400017E0

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0

RICH Header

Errors

[*] Warning: Section .text has a size of 0! [*] Warning: Section .rdata has a size of 0! [*] Warning: Section .data has a size of 0! [*] Warning: Section .pdata has a size of 0! [*] Warning: Section .00cfg has a size of 0! [*] Warning: Section .tls has a size of 0! [*] Warning: Section .text0 has a size of 0!
<-- -->