756e88295b88c8e016f6b6b126663f7bfbb6a4ea0444f147f99f5c022e419e5a

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Aug-13 08:46:33
Detected languages English - United States

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Interesting strings found in the binary: Contains domain names:
  • github.com
  • http://www.zkysky.com.ar
  • http://www.zkysky.com.ar/Julieta
  • https://github.com
  • https://openfontlicense.orgThis
  • https://openfontlicense.orghttp
  • inkscape.org
  • www.inkscape.org
  • www.zkysky.com
  • zkysky.com
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Possibly launches other programs:
  • ShellExecuteW
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 036a64e24520fe70e7d2a2be8d23a3a5 🔍
SHA1 9d9b210a1873da008c2c809be9619c0f7de61207 🔍
SHA256 756e88295b88c8e016f6b6b126663f7bfbb6a4ea0444f147f99f5c022e419e5a 🔍
SHA3 ab57e3b2717fd5ce03570d08c411b95e712a749bbd99b8b39bdac50c98a019cb 🔍
SSDeep 24576:AtcpkMSCB2csdIJUtjJTxIidnUCRpyCzN23PdSoI3hm3QTIl5BmRhIp:vpkMSCcZdZ9VdnDyWN23PQHhJT05ARh 🔍
Imports Hash cf89d4fedfe9840585d07c86d0bbcd75 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-13 08:46:33
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x69400
SizeOfInitializedData 0x110a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000069104 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x17f000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 2c9158ec96467f560f5e82ba8b493d6c 🔍
SHA1 19aa69ff6a7505e3d1a147c5a4903a93021873a9 🔍
SHA256 3fc117085386860ddb61e66121857eac5ce29b86f06a1dc6d40f7d1f4b00ccbd 🔍
SHA3 9d12154b437455eca8eeb006e4d45c4a489236d8d32f4902298c83cc73369627 🔍
VirtualSize 0x69242
VirtualAddress 0x1000
SizeOfRawData 0x69400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.51348

.rdata

MD5 345e47fa3127a3e47e26213288390a46 🔍
SHA1 7dafa17accd10d654ff24e4e2a0c860ec9f0db56 🔍
SHA256 d0d14fd4a48c683a36d08e593ef1f29d352068eb2871c5c976b8286d684b720a 🔍
SHA3 a53bdd756244688342e6a249d745be5b37ea2da64c23bfedcfc7c84cb4915ee6 🔍
VirtualSize 0x6d21c
VirtualAddress 0x6b000
SizeOfRawData 0x6d400
PointerToRawData 0x69800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.75684

.data

MD5 b1a582fa2a4f2c141f34396ae074bfdb 🔍
SHA1 e0089b3ad87cbc39d5f8612e744f28a126143c64 🔍
SHA256 82ee6abc468dcb675d8cc53f6d4910dedd17948570ef249668cbe167dc0589b9 🔍
SHA3 63d10ec9379a4af517c77e34123b2291f180d90cfbe8a0b5a9ef28ca07ecf719 🔍
VirtualSize 0x9e860
VirtualAddress 0xd9000
SizeOfRawData 0x9e600
PointerToRawData 0xd6c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.98212

.pdata

MD5 71b0043080c3a83c59c94ac88fb4fc5f 🔍
SHA1 033c2903da0025f7200096c1c3556627b048149e 🔍
SHA256 80ce0b69e6817fe32d612707bc11e79192d6ef7c4e706dc1c6379eab2fdb81c0 🔍
SHA3 ddfb9217a88150be7a7ca5f1f355293c894574eec5d07fbc538e3effebbd018f 🔍
VirtualSize 0x47dc
VirtualAddress 0x178000
SizeOfRawData 0x4800
PointerToRawData 0x175200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.8526

.rsrc

MD5 4dd34dafead86d4c0a7926abb53baf81 🔍
SHA1 7feb96a330c166e36b0f9421dc5243940d1c54d2 🔍
SHA256 bc4158c79d5a419426d4c6c29ffb37efcad2f5466fab4588b66543442ba8a78f 🔍
SHA3 3fda8b8752474a3262581ba68ee45cbb5821bf6c6322d3dcca69d6a9b4574dd8 🔍
VirtualSize 0x1e0
VirtualAddress 0x17d000
SizeOfRawData 0x200
PointerToRawData 0x179a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.71768

.reloc

MD5 dd575249e11a2dd3c43674fc7b4f3b98 🔍
SHA1 d8ddacfc229b963dcbc9832a71b292a23dcc7b12 🔍
SHA256 6a0cb336ce28c7b9ec296120219b12481caca35825b8201c91b298628a823d50 🔍
SHA3 6162949c40f587ed76050e0a485f75857289c81b8812e6b1f841a1a8de41095d 🔍
VirtualSize 0x1e8
VirtualAddress 0x17e000
SizeOfRawData 0x200
PointerToRawData 0x179c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.98802

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
D3DCOMPILER_47.dll D3DCompile
KERNEL32.dll LoadLibraryA
QueryPerformanceFrequency
IsDBCSLeadByte
GetProcAddress
FreeLibrary
QueryPerformanceCounter
GlobalAlloc
InitializeSListHead
GetSystemTimeAsFileTime
GetCurrentThreadId
GetCurrentProcessId
SleepConditionVariableSRW
IsDebuggerPresent
GetLocaleInfoA
GlobalUnlock
WideCharToMultiByte
GlobalLock
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
GlobalFree
MultiByteToWideChar
AcquireSRWLockExclusive
RtlCaptureContext
ReleaseSRWLockExclusive
WakeAllConditionVariable
RtlLookupFunctionEntry
USER32.dll CloseClipboard
OpenClipboard
SetCursorPos
IsWindowUnicode
GetClientRect
SetCursor
LoadCursorW
GetForegroundWindow
GetKeyboardLayout
DefWindowProcW
ClientToScreen
ScreenToClient
GetMessageExtraInfo
GetKeyState
GetWindowRect
DestroyWindow
SetWindowPos
SetWindowRgn
CreateWindowExW
SendMessageW
GetClipboardData
TrackMouseEvent
UnregisterClassW
RegisterClassExW
ShowWindow
GetCapture
DispatchMessageW
SetTimer
PeekMessageW
ValidateRect
TranslateMessage
SetCapture
KillTimer
PostQuitMessage
UpdateWindow
ReleaseCapture
GetCursorPos
BeginPaint
EndPaint
SetClipboardData
EmptyClipboard
GDI32.dll CreateRoundRectRgn
SHELL32.dll ShellExecuteW
dwmapi.dll DwmExtendFrameIntoClientArea
IMM32.dll ImmSetCompositionWindow
ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __C_specific_handler
__std_terminate
__current_exception
__current_exception_context
memchr
memset
memcpy
memmove
memcmp
api-ms-win-crt-stdio-l1-1-0.dll fflush
__acrt_iob_func
_wfopen
__stdio_common_vsprintf
fseek
__stdio_common_vfprintf
fclose
ftell
fread
__stdio_common_vsscanf
__p__commode
_set_fmode
fwrite
api-ms-win-crt-heap-l1-1-0.dll free
_set_new_mode
malloc
realloc
api-ms-win-crt-string-l1-1-0.dll strncmp
strcmp
strncpy
api-ms-win-crt-convert-l1-1-0.dll strtol
api-ms-win-crt-math-l1-1-0.dll pow
fmodf
sqrtf
ldexp
__setusermatherr
ceilf
acosf
sinf
cosf
api-ms-win-crt-runtime-l1-1-0.dll exit
_exit
_initterm_e
_initterm
_c_exit
_register_thread_local_exe_atexit_callback
_get_narrow_winmain_command_line
_initialize_narrow_environment
_configure_narrow_argv
_wassert
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_set_app_type
_seh_filter_exe
_cexit
terminate
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-13 08:46:33
Version 0.0
SizeofData 756
AddressOfRawData 0xcfe78
PointerToRawData 0xce678

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-13 08:46:33
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1400d0190
EndAddressOfRawData 0x1400d01c0
AddressOfIndex 0x140177600
AddressOfCallbacks 0x14006b560
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1400d9040

RICH Header

XOR Key 0x84b492a5
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 16
Imports (35207) 4
ASM objects (35207) 3
C objects (35207) 9
C++ objects (35207) 23
Imports (33145) 17
Total imports 162
C++ objects (LTCG) (35228) 12
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.