788a1c56dc633b273cec6cb5553fd6c095c410f27aaa17853157e581edbe9f05

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 1970-Jan-01 00:00:00
Detected languages English - United States

Plugin Output

Suspicious PEiD Signature: HQR data file
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to internet browsers:
  • chrome.exe
Accesses the WMI:
  • root\Microsoft
  • root\cimv2
Contains domain names:
  • 22.uefa.com
  • 25252Fchampionsleague-sales.tickets.uefa.com
  • 252Fchampionsleague-sales.tickets.uefa.com
  • AudioOutputDeviceRequestedJavaScriptInterfaceRemovedPrefetchNotUsedProbeFailedinsufficientSourceCapacitynoMatchingSourceFilterDatagoogle.golang.org
  • activate.org
  • api.pushover.net
  • apigoogle.golang.org
  • assets.queue-it.net
  • auth.ticketmaster.com
  • banquetrecords.com
  • birthpopuptypesapplyImagebeinguppernoteseveryshowsmeansextramatchtrackknownearlybegansuperpapernorthlearngivennamedendedTermspartsGroupbrandusingwomanfalsereadyaudiotakeswhile.com
  • cdn.discordapp.com
  • championsleague-sales.tickets.uefa.com
  • connect.paris2024.org
  • dd.tickets.uefa.com
  • discord.com
  • discordapp.com
  • dot.style.top
  • epsf.ticketmaster.co.uk
  • europaleague-sales.tickets.uefa.com
  • eventim.co.uk
  • eventim.de
  • genretrucklooksValueFrame.net
  • gigya.connect.paris2024.org
  • github.com
  • golang.org
  • google.golang.org
  • hostname.com
  • http://127.0.0.1
  • http://85.10.204.199
  • http://shop.api.eventix.io
  • http://shop.api.eventix.io/3.0.0/%v/data?nocache
  • http://shop.api.eventix.io/3.0.0/%v/order?nocache
  • http://shop.api.eventix.io/3.0.0/%v/reserve/ticket/%v?nocache
  • http://tibbaa.com
  • http://www.C
  • http://www.a
  • http://www.css
  • http://www.hortcut
  • http://www.ibm.com
  • http://www.ibm.com/data/dtd/v11/ibmxhtml1-transitional.dtdabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ\p
  • http://www.icon
  • http://www.interpretation
  • http://www.language
  • http://www.style
  • http://www.text-decoration
  • http://www.w3.org
  • http://www.w3.org/XML/1998/namespacexml
  • http://www.w3.org/shortcut
  • http://www.wencodeURIComponent
  • http://www.years
  • https://api.2captcha.cominvalid
  • https://api.capmonster.cloudFailed
  • https://api.capsolver.comRecaptchaV3EnterpriseTaskNew
  • https://api.line-up.tickets
  • https://api.line-up.tickets/api/performance/%v/Max
  • https://api.line-up.tickets/api/performance/%v/seating-object/?code
  • https://api.line-up.tickets/api/transaction/https
  • https://api.pushover.net
  • https://api.pushover.net/1pushover
  • https://api.tickio.eu
  • https://api.tickio.eu/api/akamai/gethttps
  • https://api.tickio.eu/api/authenticatehttps
  • https://api.tickio.eu/api/cartix/download/windows?key
  • https://api.tickio.eu/api/collect/logshttps
  • https://api.tickio.eu/api/create/queueiterrors
  • https://api.tickio.eu/api/eventix/gethttps
  • https://api.tickio.eu/api/extension/%sEventim/4.24.2
  • https://api.tickio.eu/api/healthhttps
  • https://api.tickio.eu/api/incapsula/gethttps
  • https://api.tickio.eu/api/initialreflect
  • https://api.tickio.eu/api/px/getAsset
  • https://api.tickio.eu/api/v2/authenticatehttps
  • https://api.tickio.eu/api/v2/collect/logshttps
  • https://api.tickio.eu/api/v2/initialhttps
  • https://api.tickio.eu/api/v2/share/getreflect.typeptrdata
  • https://api.tickio.eu/api/v2/shareError
  • https://api.tickio.eu/api/v2/statsError
  • https://assets.queue-it.net
  • https://assets.queue-it.net/Failed
  • https://auth.ticketmaster.com
  • https://auth.ticketmaster.com/Account
  • https://auth.ticketmaster.com/json/accounts/dual-verify/completeFailed
  • https://auth.ticketmaster.com/json/accounts/dual-verify/token/validate/%vtls
  • https://auth.ticketmaster.com/json/accounts/dual-verify/token?deliveryType
  • https://auth.ticketmaster.com/json/pre-sign-up
  • https://auth.ticketmaster.com/json/reset-passwordMax
  • https://auth.ticketmaster.com/json/sign-inMax
  • https://auth.ticketmaster.com/verify-otp/json/%v/verify?otp
  • https://auth.ticketmaster.com/verify-otp/json/init?clientToken
  • https://auth.ticketmaster.com/verify-otp/json/send/otp/
  • https://auth.ticketmaster.comFailed
  • https://backup.tickio.eu
  • https://backup.tickio.eu/api/authenticatehttps
  • https://backup.tickio.eu/api/collect/logsunexpected
  • https://backup.tickio.eu/api/create/queueitmultiple
  • https://backup.tickio.eu/api/eventix/gethttps
  • https://backup.tickio.eu/api/incapsula/getreflect
  • https://backup.tickio.eu/api/initialf859188a-875b-4478-8b54-25c12b9514e1method
  • https://backup.tickio.eu/api/swap/getreflect
  • https://backup.tickio.eu/api/v2/authenticatehttps
  • https://backup.tickio.eu/api/v2/collect/logsreflect
  • https://backup.tickio.eu/api/v2/initialreflect.MakeMapWithSize
  • https://backup.tickio.eu/api/v2/sharehttps
  • https://cdn.discordapp.com
  • https://cdn.discordapp.com/attachments/1261328556559171625/1261328577425702973/IMG_0618.webp?ex
  • https://championsleague-sales.tickets.uefa.com
  • https://championsleague-sales.tickets.uefa.com/account/lotteryApplicationstls
  • https://connect.paris2024.org
  • https://connect.paris2024.org/failed
  • https://connect.paris2024.org/oidc/OP_LoginPage.php?client_id
  • https://connect.paris2024.orgFailed
  • https://dd.tickets.uefa.com
  • https://dd.tickets.uefa.com/js/Successfully
  • https://discord.com
  • https://epsf.ticketmaster
  • https://epsf.ticketmaster.co.uk
  • https://epsf.ticketmaster.co.uk/eps-d?d
  • https://epsf.ticketmaster.co.uk/gec/v2/www.ticketmaster.co.uk/6LdWxZEkAAAAAIHtgtxW_lIfRHlcLWzZMMiwx9E1/TM_UK_intent_to_purchase_ismAvailable/%vHTTP/1.1
  • https://epsf.ticketmaster.co.ukpattern
  • https://europaleague-sales.tickets.uefa.com
  • https://europaleague-sales.tickets.uefa.com/account/lotteryApplications
  • https://europaleague-sales.tickets.uefa.com/tls
  • https://europaleague-sales.tickets.uefa.comFailed
  • https://gigya.connect.paris2024.org
  • https://gigya.connect.paris2024.org/accounts.identifier.createTokentls
  • https://gigya.connect.paris2024.org/accounts.loginUnauthorized
  • https://gigya.connect.paris2024.org/accounts.webSdkBootstrap?apiKey
  • https://gigya.connect.paris2024.org/oidc/op/v1.0/4_NJJrXj3BQz34ffVpp1d8eg/authorize/continue?context
  • https://github.com
  • https://i.imgur.com
  • https://i.imgur.com/kalBqtW.pngSuccessfully
  • https://identity.ticketmaster
  • https://identity.ticketmaster.co.uk
  • https://identity.ticketmaster.co.uk/json/signed-in?hard
  • https://identity.ticketmaster.co.uk/sign-in?doNotTrack
  • https://identity2.ticketmaster
  • https://idpassets.uefa.com
  • https://idpassets.uefa.com/saml/ticket-login.htmlcrypto/tls
  • https://mg.eventim.de
  • https://mg.eventim.de/Queue
  • https://mg.oeticket.com
  • https://mg.oeticket.com/Found
  • https://pdc.seetickets.com
  • https://pdc.seetickets.com/Passed
  • https://pdc.seetickets.cominput
  • https://protobuf.dev
  • https://queue.ticketmaster.co.ukinvalid
  • https://queue.ticketmaster.eu
  • https://queue.ticketmaster.eu/?c
  • https://queue.ticketmaster.eu/Payment
  • https://queue.ticketmaster.euQueue
  • https://secure.ticketmaster
  • https://secure.ticketmaster.at
  • https://secure.ticketmaster.at/20617/ls17c9wmw?qty
  • https://secure.ticketmaster.co.uk
  • https://secure.ticketmaster.co.uk/%v/%v?qty
  • https://secure.ticketmaster.co.uk/2300609AC6820B19/l5n78cszj?qty
  • https://secure.ticketmaster.co.uk/prepay?brand
  • https://secure.ticketmaster.co.ukCheckout
  • https://secure.ticketmaster.de
  • https://secure.ticketmaster.de/517067/lr2hf0d9?qty
  • https://secure.ticketmaster.es
  • https://secure.ticketmaster.es/39487/l00ts5ls?qty
  • https://secure.ticketmaster.https
  • https://secure.ticketmaster.nl
  • https://secure.ticketmaster.nl/294871/l3bhb5mw?qty
  • https://services.ticketmaster.co.uk
  • https://services.ticketmaster.co.uk/api/ismds/host/limiterEvent.stop
  • https://shop.eventix.io
  • https://shop.eventix.io/%v/ticketsSuccessfully
  • https://sms-activate.org
  • https://tibbaa.com
  • https://ticketing.lwtheatres.co.uk
  • https://ticketing.lwtheatres.co.uk/a
  • https://ticketing.lwtheatres.co.uk/event/364/performance/%vsync/atomic
  • https://ticketing.lwtheatres.co.uk/event/364/transaction/%v/productshttps
  • https://ticketing.lwtheatres.co.ukNoDefaultCurrentDirectoryInExePathunexpected
  • https://tickets.paris2024.org
  • https://tickets.paris2024.org/?affiliate
  • https://tickets.paris2024.org/?pass_through
  • https://tickets.paris2024.org/EWTSrXOpc/2T/F_eNJfg/u5uY4zL9uY2fiS/VHwrOQRU/Kyx9dS/MHPBchttps
  • https://tickets.paris2024.org/api/login/ssoProvider?redirectUrl
  • https://tickets.paris2024.org/obj/media/FR-Paris2024/teaser/Failed
  • https://upload.wikimedia.org
  • https://upload.wikimedia.org/wikipedia/de/7/77/UEFA_Logo.pngsync/atomic
  • https://whop.com
  • https://www.World
  • https://www.banquetrecords.com
  • https://www.banquetrecords.com/Proxy
  • https://www.banquetrecords.com/cartFailed
  • https://www.banquetrecords.com/eventsexec
  • https://www.eventim.co.uk
  • https://www.eventim.co.uk/Ra1KXi1PL/Yu/CITEVVg/i7zEwJiwuapb9i/QC9EKwE/C3NfEQsH/S30refusing
  • https://www.eventim.co.uk/obj/media/UK-eventim/teaser/
  • https://www.eventim.co.ukchildReservations.ProductError
  • https://www.eventim.de
  • https://www.eventim.de/obj/media/DE-eventim/teaser/Unauthorized
  • https://www.eventim.de/y_kZI/N/_0/xHui/4kKY9swm/GY7JD6imEODNaEm5/Zmw1TEs/Axp/0QD8xVBUhttps
  • https://www.eventim.dedata-discount-level-idxsrfToken
  • https://www.lippu.fi
  • https://www.lippu.fi/MLW4J3L3_/RXiSExFs/gQgsvGl2/hw/Yr7GkziSX94Q/VRFBOFZ1QQM/Fjc/JMkdaaxIhttps
  • https://www.lippu.fi/obj/media/FI-eventim/teaser/%v/api/promocode/?affiliate
  • https://www.lippu.fiWrong
  • https://www.oeticket.com
  • https://www.oeticket.com/_Hivpg/ce4G/R/I/S_fz9ASk6iXqfUk/VEY5QfXE5Gbu/eVAlAg/Eg/NHaD4dLiQhttps
  • https://www.oeticket.com/obj/media/AT-eventim/teaser/https
  • https://www.oeticket.comhttps
  • https://www.recent
  • https://www.ticketcorner.ch
  • https://www.ticketcorner.ch/obj/media/CH-eventim/teaser/Unauthorized
  • https://www.ticketcorner.ch/pUIiNGM8/Ozr14Wo/aF52b0w/jN/iLfYhkk9z3Dt/Zmw1TEs/Pik0YiYc/YQUBhttps
  • https://www.ticketcorner.chFailed
  • https://www.ticketmaster
  • https://www.ticketmaster.Invoking
  • https://www.ticketmaster.co.uk
  • https://www.ticketmaster.co.uk/Cartix
  • https://www.ticketmaster.co.uk/api/cookieshttps
  • https://www.ticketmaster.co.uk/api/eventinfo/%v?language
  • https://www.ticketmaster.co.uk/api/quickpicks/%v/list?%vd
  • https://www.ticketmaster.co.uk/api/quickpicks/%v/resale?qty
  • https://www.ticketmaster.co.uk/api/seatmap/seatmapoffered/%v?primary
  • https://www.ticketmaster.co.uk/api/unlockToken/%v?%serrors
  • https://www.ticketmaster.co.uk/bba/checkout/reserve/captcha?%sreflect.ArrayOf
  • https://www.ticketmaster.co.uk/bba/checkout/reserve/polling?%shttps
  • https://www.ticketmaster.co.uk/checkout/order?v
  • https://www.ticketmaster.co.uk/checkout/orderreflect
  • https://www.ticketmaster.co.uk/json/isc?%shttps
  • https://www.ticketmaster.co.ukFailed
  • https://www.ticketmaster.nl
  • https://www.ticketmaster.nl/api/unlock/294875?password
  • https://www.ticketone.it
  • https://www.ticketone.it.event-list-item-wrapperNo
  • https://www.ticketone.it/VRLSqA5JiNlO6NpDQQ/Ep3hhQEOOEhw/MmhnbHgB/dgV0SU/9IeTEreflect
  • https://www.ticketone.it/obj/media/IT-eventim/teaser/Unauthorized
  • https://www.ticketswap
  • https://www.tickio.euPushover
  • https://www.uefa.com
  • https://www.uefa.com/%s
  • i.imgur.com
  • identity.ticketmaster.co.uk
  • idpassets.uefa.com
  • imgur.com
  • kindgoogle.golang.org
  • lwtheatres.co.uk
  • messagegoogle.golang.org
  • mg.eventim.de
  • mg.oeticket.com
  • oeticket.com
  • paris2024.org
  • pdc.seetickets.com
  • pushover.net
  • queue-it.net
  • sTERM.com
  • sales.tickets.uefa.com
  • secure.ticketmaster.co.uk
  • secure.ticketmaster.de
  • secure.ticketmaster.es
  • secure.ticketmaster.nl
  • seetickets.com
  • services.ticketmaster.co.uk
  • sms-activate.org
  • style.top
  • thing.org
  • tibbaa.com
  • ticketcorner.ch
  • ticketing.lwtheatres.co.uk
  • ticketmaster.co.uk
  • ticketmaster.com
  • ticketmaster.de
  • ticketmaster.es
  • ticketmaster.nl
  • ticketone.it
  • tickets.paris2024.org
  • tickets.uefa.com
  • unknowngoogle.golang.org
  • upload.wikimedia.org
  • wikimedia.org
  • www.banquetrecords.com
  • www.eventim.co.uk
  • www.eventim.de
  • www.ibm.com
  • www.oeticket.com
  • www.ticketcorner.ch
  • www.ticketmaster.co.uk
  • www.ticketmaster.nl
  • www.ticketone.it
  • www.uefa.com
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Suspicious The PE is possibly packed. Unusual section name found: .xdata
Unusual section name found: .symtab
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • LoadLibraryExW
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 89a360c62e561016550c5a52df446296
SHA1 2cfb05159aa653d3cd6e721ae212f9726ae1a83e
SHA256 788a1c56dc633b273cec6cb5553fd6c095c410f27aaa17853157e581edbe9f05
SHA3 32f8bce2d6a62525d8ce713b80d7899215412a0273354e3e21b18ac0bcc2c96c
SSDeep 196608:zJIzO5wi/I3zqU2tIimyDGNHB4WEPtata:tIzyX/62KqDGG
Imports Hash c2d457ad8ac36fc9f18d45bffcd450c2

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0x8b
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 9
TimeDateStamp 1970-Jan-01 00:00:00
PointerToSymbolTable 0x1958800
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 3.0
SizeOfCode 0x900c00
SizeOfInitializedData 0x1c1c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000071F20 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 1.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0x1a08000
SizeOfHeaders 0x600
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 ae64fde832db60af36c2c9111ec5b17e
SHA1 9b83ffe656ccd52edb3729a990fc1dca00c3dbf2
SHA256 42ac461bf83dabae51572b2ae4088fb1deb9270f5dfedf247193c136104bcd08
SHA3 b21a6abc2a64d3b71b2b3566da6337d81ab34974165c222c24b422434414d273
VirtualSize 0x900a19
VirtualAddress 0x1000
SizeOfRawData 0x900c00
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.1506

.rdata

MD5 fb696c12e7f41c2550d7b3c30abf2c30
SHA1 c0c268ac27b67215ff4f333d00eac427c0c5ba12
SHA256 1beccc87fd159140157feafab702a72f6aabae50a4918f7db366316760e97695
SHA3 2245a1374059f55b4b0fc7430b0ec1d1ef3a993188e99ec904d26b3b195b7d01
VirtualSize 0xe24be0
VirtualAddress 0x902000
SizeOfRawData 0xe24c00
PointerToRawData 0x901200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.4798

.data

MD5 823fcf90b266d6044371898599d150cf
SHA1 77d03f2786739c88fb55bcf76d1863c77fd4c7c7
SHA256 7f6bda88cc75c9ed44171ab674c618a8e08b577df2108ef10c58514c4e569474
SHA3 7e087f06094cb2ec2a18ba0713afec612298e4f6f19682843ce7653b50f469b3
VirtualSize 0x25e930
VirtualAddress 0x1727000
SizeOfRawData 0x1c1c00
PointerToRawData 0x1725e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.87309

.pdata

MD5 0d15c0899842f49f6a4715fd1ce8c606
SHA1 64a5ccdf361457bca8da1cb7d4799ea3704d06a1
SHA256 964a568b05809719157af6c5ddeef7460891f478ac0724a6faa4050df6439282
SHA3 045c20346009f8785dd7a9300ebc649cdfbd5cf88f5a1c50ddbd101aa01ba443
VirtualSize 0x3d89c
VirtualAddress 0x1986000
SizeOfRawData 0x3da00
PointerToRawData 0x18e7a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.88301

.xdata

MD5 cd8355a17f8c365f42ee74dd0565e6e2
SHA1 4494d58cb3edc0d8dee358d520bf46e75fc7e967
SHA256 b4a8fc94d7debf094da0ca35cf4911f4f0cf78f1775debd3a1cdec1f9b825c2a
SHA3 92ecc7af971a665a2cceb00516cdbedc5060209a8b42bfeeadf0f2d5bdde50a8
VirtualSize 0xb4
VirtualAddress 0x19c4000
SizeOfRawData 0x200
PointerToRawData 0x1925400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.76358

.idata

MD5 b5bd65d523827f85138075dc5cfa1c15
SHA1 55f10cdd9701a7dcee171d38b52c60e286ad9a04
SHA256 d847038ffbbfc84f11c062865bcd6c54c4a86a63c6f775a532d7d907c6593892
SHA3 1743e5e76efe0bf0d7d4bca3bf3cc9492824342d70073b61447de9c94bf30cae
VirtualSize 0x554
VirtualAddress 0x19c5000
SizeOfRawData 0x600
PointerToRawData 0x1925600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.16152

.reloc

MD5 480269b50377d10980e43da321c6ceb3
SHA1 cfa00296b820835e4621c09ba21683dcf497c9c6
SHA256 7975aaa46c17a449f6da448351091e2f9eecbcb910e90015fa296bd103cbc5e8
SHA3 518c72fc4a141e92787f0a94873671d334e4126a3ec336878f70ccf95728f81c
VirtualSize 0x32a6c
VirtualAddress 0x19c6000
SizeOfRawData 0x32c00
PointerToRawData 0x1925c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.42081

.symtab

MD5 07b5472d347d42780469fb2654b7fc54
SHA1 943ae54f4818e52409fbbaf60ffd71318d966b0d
SHA256 3e67f4a7d14b832ff2a2433e9cf0f6f5720821f67148a87c0ee2595a20c96c68
SHA3 a70a3e18515c06557b62676f2a8eb6d7d41962d8c9c7c49f4641c429cc65b977
VirtualSize 0x4
VirtualAddress 0x19f9000
SizeOfRawData 0x200
PointerToRawData 0x1958800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.0203931

.rsrc

MD5 1eecf4c42e329972c523db28c7f288f9
SHA1 824a548ceb21af637c86d828809130adec6cbc22
SHA256 871de428421796a02a7bc04a575e381a708f6477bd1e4a031c19d926ae69e2aa
SHA3 9fde25bc9776b3b6079c3b99c4ba31e3bff9541bea5f5698cc3df1edee3c9cea
VirtualSize 0xd2b0
VirtualAddress 0x19fa000
SizeOfRawData 0xd400
PointerToRawData 0x1958a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.949

Imports

kernel32.dll WriteFile
WriteConsoleW
WerSetFlags
WerGetFlags
WaitForMultipleObjects
WaitForSingleObject
VirtualQuery
VirtualFree
VirtualAlloc
TlsAlloc
SwitchToThread
SuspendThread
SetWaitableTimer
SetProcessPriorityBoost
SetEvent
SetErrorMode
SetConsoleCtrlHandler
RtlVirtualUnwind
RtlLookupFunctionEntry
ResumeThread
RaiseFailFastException
PostQueuedCompletionStatus
LoadLibraryW
LoadLibraryExW
SetThreadContext
GetThreadContext
GetSystemInfo
GetSystemDirectoryA
GetStdHandle
GetQueuedCompletionStatusEx
GetProcessAffinityMask
GetProcAddress
GetErrorMode
GetEnvironmentStringsW
GetCurrentThreadId
GetConsoleMode
FreeEnvironmentStringsW
ExitProcess
DuplicateHandle
CreateWaitableTimerExW
CreateThread
CreateIoCompletionPort
CreateFileA
CreateEventA
CloseHandle
AddVectoredExceptionHandler
AddVectoredContinueHandler

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x9b31
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97465
Detected Filetype PNG graphic file
MD5 5cc6c229972a5069e4bd7417f81d6d08
SHA1 2a2cdbb080d8250a0e400052f7a33645e2115fe8
SHA256 a060555d34d819a0dc78c5bfd8360ce3e99517fd088207ed36122307728840ad
SHA3 491f229f6cb004f2da7405e013882e26b30398aeade05f98ca45a7212cf26d35

2

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x16bc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.95023
Detected Filetype PNG graphic file
MD5 de7268c69a7a66346ee3fca4022cc7e0
SHA1 b535bf3a02c58287714c28000ff88186fa41974d
SHA256 fdc0dcac1a4830a8673eca22d2e0c57b152e2c2ff7368a350e498aab76052525
SHA3 d613d00f13be9ade593a4aed6e5d608a25b5bd3ddbbb818855a29fb4e128c1bf

3

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0xee5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.93198
Detected Filetype PNG graphic file
MD5 2afc47913f7ea869addc5ae45f00f1f3
SHA1 7799b4b8cb53c1c03f67a2266e626fcb7c0d9b2d
SHA256 6b304b1bc39b78e55ec2bb313fb3797981d31c4b584d378ae0f6548f0d2a7985
SHA3 9c8f254c84ffcc6420dae457f26bcf662981de966896f0037e8a6d14862d15cb

4

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x85c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87309
Detected Filetype PNG graphic file
MD5 9363279d63ec763555a0b68e668ac89e
SHA1 d6df97d78664578befd55fad3a3d99e2a2539ab8
SHA256 a55e7d2030da4d617d191ab42564750b8bc8126b17548105f2be09116a22341c
SHA3 e589025ca63340f7873553708332951fe6ef449aea7e1957972fc6030b62e451

5

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x33d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.73893
Detected Filetype PNG graphic file
MD5 4fe3c4d8741ba3ed088e4710f34effa0
SHA1 55b03341042ced973a2b452b9a05f880f80cab36
SHA256 b42810bcfcde16a89bc5adc7bcee3c27c0a423bdb29cfd8991634e7fbc519674
SHA3 8b8fbad79fd67daced940436828e66e5d33a99cdaea4221d44ad833444cf671c

1 (#2)

Type RT_GROUP_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70895
Detected Filetype Icon file
MD5 21f27f885092304e0c3b99bdf6bd5c33
SHA1 91f2bff8c28310f445ea4ae76184ea73dfe50331
SHA256 d66ffeba92156ca3718562aa32f0c5ff29052902fec4a96be57961ea9192bed0
SHA3 db2baaf7297f670ab24e3f4b81b2a6c5f8892b7b87c5925d275f53a5b7e71f12

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x434
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.2293
MD5 2119262f8a5b5f640e6ee70120dbd205
SHA1 8f4ff2b61a1f5545ef8ff60154bc50b0634d6223
SHA256 f192f2417d232eb6dc73806c1d6d70cb0136fa55e9e12a180b6bad0988ef5064
SHA3 8ab95a533d9dad03ed682ee873cbf7bdf885ecb929c6c572db3e8434dd27a422

Version Info

TLS Callbacks

Load Configuration

RICH Header

Errors

Leave a comment

No comments yet.