76ec76309ca49a2e4feb840e02a46e8b

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2022-Jun-29 13:01:49
Detected languages English - United Kingdom
English - United States
CompanyName Simon Tatham
ProductName PuTTY suite
FileDescription SSH, Telnet, Rlogin, and SUPDUP client
InternalName PuTTY
OriginalFilename PuTTY
FileVersion Release 0.77 (without embedded help)
ProductVersion Release 0.77
LegalCopyright Copyright © 1997-2022 Simon Tatham.

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Info Cryptographic algorithms detected in the binary: Uses constants related to Blowfish
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Malicious VirusTotal score: 11/66 (Scanned on 2022-06-30 12:37:40) Bkav: W32.AIDetect.malware2
Elastic: malicious (moderate confidence)
FireEye: Generic.mg.76ec76309ca49a2e
Sangfor: Suspicious.Win32.Save.a
Symantec: ML.Attribute.HighConfidence
APEX: Malicious
Cynet: Malicious (score: 100)
Trapmine: malicious.moderate.ml.score
SentinelOne: Static AI - Malicious PE
Rising: Trojan.Generic@AI.88 (RDML:CbWBkCZ3QK1eRyMWzxVBKQ)
BitDefenderTheta: Gen:NN.ZexaF.34742.@B0@am!43ybi

Hashes

MD5 76ec76309ca49a2e4feb840e02a46e8b
SHA1 67576e46cef8186e301a3dc0c523d7aae4fe224c
SHA256 5fced57ac1e244e501c4ef62eae22bff63e56e6b2cf92fc7927e5a4e6df94e7b
SHA3 128c63a09b9b4961eb27689e6d8fd44d5aec4a922c2170dd5cce1a32a63400c9
SSDeep 98304:5WVnBToYKHdEnBJz9WM/fFokNHXOPPjg:y/B5bdlH+P
Imports Hash 0ff7861acf7a18bfe7caa4a06ec231a3

DOS Header

e_magic MZ
e_cblp 0x78
e_cp 0x1
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x78

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 6
TimeDateStamp 2022-Jun-29 13:01:49
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x4b9e00
SizeOfInitializedData 0x66600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0047A67F (Section: .text)
BaseOfCode 0x1000
BaseOfData 0
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x524000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 beee2507de6a85fa4374e410edba3115
SHA1 92a9891f75c9b7cdcbeba072282ee62ea52e382e
SHA256 407ef0bcb9cc03d69865f2178a91b20d4d3a3921dc4d34861317cd0c6d1c1f45
SHA3 98b07e21cd5968f9da0bbd1d1f22a50c56187ca0db17e9538e27c8f9fe762ede
VirtualSize 0x4b9d54
VirtualAddress 0x1000
SizeOfRawData 0x4b9e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.97976

.rdata

MD5 09cd64d89e7067485a7eac16acb7501f
SHA1 43ccd4e3e2d88d4791bcce30077c1754cd5642b9
SHA256 c9657b3062bf82856e27397141432e2df364172a69dfb9d9b6141bf2211c01f2
SHA3 b3559f85cd1c1fe10a6b6dc41e9977dca6e2ffce1dc4e0bf491782f948cd7458
VirtualSize 0xb23c
VirtualAddress 0x4bb000
SizeOfRawData 0xb400
PointerToRawData 0x4ba200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.39344

.data

MD5 e0c1ae5516b3c887befdf18707433321
SHA1 9ee22529dc44e0b23c35412ba671e1fb3a28402f
SHA256 05e5948eb8d3195f0c5b92a6b9036262129d108abb9ba4bfd72821b0ed1a2a70
SHA3 65825d2bfc1d3f81a12061cfa0f9c9dda028fd7731f906de84ccc61324b2c2f2
VirtualSize 0xd246
VirtualAddress 0x4c7000
SizeOfRawData 0xd400
PointerToRawData 0x4c5600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.28328

.rsrc

MD5 6b57b7bfc77461f6a9abe1a186000831
SHA1 d3c34503cbebb753b21f0394ac948c05b0e9bcce
SHA256 2139eb0675d32f4a8d5902cb4c483c53d4f7d8664c7e1c9beee384676a761041
SHA3 6d06464b1d63c08740a0a080c466b2c059ebb63ee9349942f08b65d71096cbbc
VirtualSize 0x2630
VirtualAddress 0x4d5000
SizeOfRawData 0x2800
PointerToRawData 0x4d2a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.74603

.reloc

MD5 a950c153ffa27f138ef9a80d08163d21
SHA1 4873fa109b3ce8cf138d223bae57126be3ad608e
SHA256 453993cd0c6cc5985228a4af408e089e6ec8436818118279023f6fac58b9b53c
SHA3 1ebc3a5ebb5c70d448f16ab0dca0705306fdbce5abf667d1c6137780c48a59a9
VirtualSize 0x6cd4
VirtualAddress 0x4d8000
SizeOfRawData 0x6e00
PointerToRawData 0x4d5200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.06734

.rdata (#2)

MD5 54afde188ce8ca6cb281262abf712412
SHA1 7bd5adf5e8635a7736c54ed3fd5e42bf61209298
SHA256 43948306e5745e5ef77bdeb121a841f5d5845dcf4687d4ff6d9b921524c31b2c
SHA3 4cff7b505e165d49ef3e12b1296bf7cd7dd73bf020ac424f9fd1826aa5097d5b
VirtualSize 0x44650
VirtualAddress 0x4df000
SizeOfRawData 0x44800
PointerToRawData 0x4dc000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.99886

Imports

KERNEL32.dll CloseHandle
CompareStringW
CreateFileW
DecodePointer
DeleteCriticalSection
EncodePointer
EnterCriticalSection
EnumSystemLocalesW
ExitProcess
FindClose
FindFirstFileExW
FindNextFileW
FlushFileBuffers
FreeEnvironmentStringsW
FreeLibrary
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentProcess
GetCurrentProcessId
GetCurrentThread
GetCurrentThreadId
GetDateFormatW
GetEnvironmentStringsW
GetFileSizeEx
GetFileType
GetLastError
GetLocaleInfoW
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
GetTimeFormatW
GetUserDefaultLCID
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
InitializeCriticalSectionAndSpinCount
InitializeSListHead
InterlockedFlushSList
InterlockedPushEntrySList
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
IsValidLocale
LCMapStringW
LeaveCriticalSection
LoadLibraryExW
LocalAlloc
MultiByteToWideChar
OutputDebugStringW
QueryPerformanceCounter
RaiseException
ReadConsoleW
ReadFile
RtlUnwind
SetConsoleCtrlHandler
SetEnvironmentVariableW
SetFilePointerEx
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
UnhandledExceptionFilter
WideCharToMultiByte
WriteConsoleW
WriteFile
COMDLG32.dll ChooseColorW
ChooseFontW
USER32.dll GetCursorInfo
LoadCursorW

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.74321
MD5 84660bec1eeebe3ad61960f5b6785077
SHA1 38a40c423383d9e79664115cf1bfea6369e82dad
SHA256 89101ef80cb32eccdb988e8ea35f93fe4c04923023ad5c9d09d6dbaadd238073
SHA3 c423144290bb9d9273fb83be08980440a3c2cbb0dca4e170f8a7db81b2bedbfb

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.98271
MD5 7d4cff360d2871fed319ecef64aa7d3d
SHA1 d7b7f55cbc2db4fad3018b6f068f1d56b1b2f88b
SHA256 8130832a780a7c334abfaaf3fce44fd99b2b8cff2e6d652764f4180472aeba74
SHA3 74045787c0b1a9cd244e4915f8121f761c4f3bd3afadaf720da5cef4eb4be380

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.67905
MD5 401c9b96e28a617d87b18f017e47e714
SHA1 15e92225acb8fb97731c2bf55b7ae535d1a04043
SHA256 fcab313f71a454c02f47579f088001b972056019c2077da20c54473def350549
SHA3 d464f12be5ff5584404967fabd1c380a396908062b4823eb99e7e122dbc236d7

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xb0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.38964
MD5 1899fdd1a312061843a64f2dc3fb9bd2
SHA1 5c81855117b20af2a5b7405a3a875564b7601d33
SHA256 549e2b61d82d10da12bc640ff22dbe352087d641c391fe382f7665847066c31a
SHA3 3909e0f0041a56a52ec3a2094d2fb33cd7389b68f551ce4b94300f66e5427bac

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x130
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.48609
MD5 ff8720e524b5fd54f831d5051e37017a
SHA1 eb680d020357a6a7aea93e8c617205a9bd673b58
SHA256 14528797e8c9c18854e9e5340c0453f608f83f63de0961e25c0528583c9fe781
SHA3 90860f98bb96b9bc2d537ab29e9063690a553019ceb55d6f2721edb5d06a9a7f

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x330
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62978
MD5 cec32b23e7b9942c91b7d943369d82d3
SHA1 cc936495e775e943954d3e0209ec87c715abe110
SHA256 90ce310a4f670171b69ba82f780064dccd25c92ff92cfeebb41f69b19008111a
SHA3 6450647b46175493d84ba14b12f84928309b81f4618d95a94df980c75acd565a

7

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16607
MD5 24fa9e5d440f1eb2741c3ff69bcf0066
SHA1 176a233a5af1f19b578f4ff28b30abb5b35703fa
SHA256 ca6932144ee553c7df83805a932ca120d4a6458fda707ad92b758ade870bbff5
SHA3 7d89863c42b1bfcef049d2b1f9f3e295d8ad4d08d4d0b8f91ccdc89b8f2fd684

8

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.57192
MD5 88ae047b639324c0c2532300cce7761e
SHA1 db8418aeb902e55c805617aaca62b5148f25f385
SHA256 40d176e64a8772483202fa25b4d7ef89341ddfb3b0c168d762fc1f86c35abae7
SHA3 aff6159d87a79321c53dfba65f1fa7d25cf1cd9fbc98c136cef94bf0b69ef0f4

9

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24629
MD5 d814ed55a8ec423c506a097ed5452e1c
SHA1 3199ef73669357b3176967cf729689ffdf506b12
SHA256 a8085f0bf68db8adc5aab891081cb87d3089a4dff05d3359047c503f17510559
SHA3 547ea078849cd72726d9b23aa04f61023fa4e6ae2796cacb09a42449f51eec44

10

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xb0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.59447
MD5 1bcd2ac1427e73b3a2616488fcb926e9
SHA1 41f1b135dba51510b2eb89108500a54d624107b9
SHA256 0fee484eb60dac53c69ca37b3d0fe76d75a1c927f5adc1db82949a3fd63c116c
SHA3 a94d7c044505574da9e6396e020e037b4ec017ea42434110be12eeba60cc7773

11

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x130
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.131
MD5 000e79a9829ed30a66c9e9f46b630867
SHA1 bb080b9a8f1c3e44cfc93651bc84841615278c5a
SHA256 09aeee834e20c34531786e0db7a69eb388d3365b1f06d2e9bfea30c6fe2a49e5
SHA3 d19f1f5d1aa0c4262c651cf72b30b46493c9f0e8451e57e795cb476c9e03a3c1

12

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x330
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.12285
MD5 6d9fd0eb34bb2598e10c2885d4c4a74e
SHA1 70a4473f857c959408dafba7a616c9baaf4626b7
SHA256 a0ac1114637fa796329b357fda4dcb1d6986ee0c8735b6072439322e86eb1a21
SHA3 a1d3545ab5b2416703e70ff48f8ecbca04edee92410cd2513444b4d7aded867d

200

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.74417
Detected Filetype Icon file
MD5 d148c75e59377aa79c180396f45f355c
SHA1 b0b26cad3bc43856c4de4bcb92e54dce6bf1f6f7
SHA256 ef77555c4d1e769f6748372d39d8422b85e6af8f11c8a811c82ce78a87cc8c9d
SHA3 e87f2a758ae18abe7e030c83b7d0b1e53c08b6b448376f9e954b53967f547bf5

201

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92968
Detected Filetype Icon file
MD5 9e81388befd1d4f93e209377728cb884
SHA1 4f7f26481375e507ac0045c531d8080586cc00f4
SHA256 383ca4cb5b95add3073e2cd86e4c5d62477d81bc80e0066da0919a1005f5033c
SHA3 29e35edf9c489ed74f8ae22c4e8ffc50cf11c6ca7607012da0ddcae96c53ba71

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x340
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.43725
MD5 45020dbfd848dff5691cb43d4434741b
SHA1 a30e44e6886743eab400d068c3f1f566b60060fa
SHA256 44bf8b4c5b2de243ccc214311c34b108b0628df589d290dada42894f8495e9a6
SHA3 d8a7cd3899a814efbf408151a433d3b4a1398323cb698b69ee5a7026e49230e3

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.77.0.0
ProductVersion 0.77.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United Kingdom
CompanyName Simon Tatham
ProductName PuTTY suite
FileDescription SSH, Telnet, Rlogin, and SUPDUP client
InternalName PuTTY
OriginalFilename PuTTY
FileVersion (#2) Release 0.77 (without embedded help)
ProductVersion (#2) Release 0.77
LegalCopyright Copyright © 1997-2022 Simon Tatham.
Resource LangID English - United States

TLS Callbacks

Load Configuration

Size 0xc0
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x8d2084
SEHandlerTable 0x8c4d8c
SEHandlerCount 7

RICH Header

Errors

<-- -->