| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2021-Nov-26 10:22:21 |
| Detected languages |
English - United States
|
| Suspicious | PEiD Signature: |
UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX v2.0 -> Markus, Laszlo & Reiser (h) UPX -> www.upx.sourceforge.net UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA256 Uses known Mersenne Twister constants |
| Suspicious | The PE is packed with UPX |
Unusual section name found: UPX0
Section UPX0 is both writable and executable. Unusual section name found: UPX1 Section UPX1 is both writable and executable. |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: WZTeam
Issuer: WZTeam |
| Malicious | VirusTotal score: 53/71 (Scanned on 2026-09-28 17:30:41) |
ALYac:
Gen:Variant.Application.HackTool.KMS.355
APEX: Malicious AhnLab-V3: Unwanted/Win.KMSAuto.C5725446 Antiy-AVL: HackTool/Win32.KMSAuto Arcabit: Trojan.Application.HackTool.KMS.355 Avira: APPL/AgentW32.Tool BitDefender: Gen:Variant.Application.HackTool.KMS.355 Bkav: W32.Malware.2120D759 CAT-QuickHeal: Trojan.IGENERIC CTX: exe.hacktool.kmsauto ClamAV: Win.Malware.Autokms-7051856-0 CrowdStrike: win/grayware_confidence_100% (W) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS ESET-NOD32: Win32/HackTool.KMSAuto.M potentially unsafe application Elastic: malicious (moderate confidence) Emsisoft: Gen:Variant.Application.HackTool.KMS.355 (B) F-Secure: Program.APPL/AgentW32.Tool Fortinet: Riskware/KMSAuto GData: Gen:Variant.Application.HackTool.KMS.355 Gridinsoft: Crack.Win32.KMS.vl!c Ikarus: PUA.HackTool.Kmsauto Jiangmin: HackTool.KMSAuto.yr K7AntiVirus: Hacktool ( 005d10d01 ) K7GW: Hacktool ( 000047b11 ) Kaspersky: UDS:Trojan.Win32.Injuke Kingsoft: Win32.Troj.Activator.ac Lionic: Virus.Win32.Neshta.mXJb Malwarebytes: HackKMS.HackTool.RiskWare.DDS MaxSecure: Trojan.Malware.325361196.susgen MicroWorld-eScan: Gen:Variant.Application.HackTool.KMS.355 Microsoft: HackTool:Win32/AutoKMS NANO-Antivirus: Riskware.Win32.KMSAuto.jijuzs Panda: HackingTool/AutoKMS Rising: HackTool.KMSActivator!1.14304 (CLOUD) Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Suspicious PE Skyhigh: Crack-KMS Sophos: WZTeam Software Cracks (PUA) Symantec: ML.Attribute.HighConfidence Tencent: Malware.Win32.Gencirc.14a4fe34 TrellixENS: Crack-KMS TrendMicro: HackTool.Win32.AutoKMS.AUSZW TrendMicro-HouseCall: HackTool.Win32.AutoKMS.AUSZW VBA32: TrojanDownloader.PowerShell.Generic VIPRE: Gen:Variant.Application.HackTool.KMS.355 Varist: W32/S-a7c29f8e!Eldorado Xcitium: ApplicUnwnt@#2vwq7cxhb55hq Yandex: Trojan.Igent.bW76tM.23 Zillya: Tool.KMSAuto.Win32.5521 alibabacloud: Hacktool:Win/Winactivator tehtris: Generic.Malware |
| MD5 | f047284bfddc942292d93ed86fdb20fd 🔍 |
|---|---|
| SHA1 | 56dc945674cf4f941cf17a9ac9c1c9718cf9d18e 🔍 |
| SHA256 | 793731bcfd6cc4faf4244e2353d6d068a0720c601117e464f28c6e6e88de5c46 🔍 |
| SHA3 | e45bff359bd32145c61ed9f6ce3a855a2cecff31894f2fbeaf219bfefc2b0612 🔍 |
| SSDeep | 393216:VlCstmv0U9PyCqaOgqjae0LNz9jqNWZsa0MvHM+wZ8YuG1JsyD14VLPlT2sK0lC:Vo0mvb9vOggaeuNz9jMWZZ7vHMH85G1H 🔍 |
| Imports Hash | d29e692e5f450ea8ffeda50487dfe8c1 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 3 |
| TimeDateStamp | 2021-Nov-26 10:22:21 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x1119000 |
| SizeOfInitializedData | 0xc000 |
| SizeOfUninitializedData | 0x1ed000 |
| AddressOfEntryPoint | 0x01306CA0 (Section: UPX1) |
| BaseOfCode | 0x1ee000 |
| BaseOfData | 0x1307000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1313000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0x11328cb |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | d41d8cd98f00b204e9800998ecf8427e 🔍 |
|---|---|
| SHA1 | da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍 |
| SHA256 | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍 |
| SHA3 | a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍 |
| VirtualSize | 0x1ed000 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0 |
| PointerToRawData | 0x200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| MD5 | c0be6705cd2ada04ff043cbd083211a7 🔍 |
|---|---|
| SHA1 | b148e4c360e0ad299fce05ee51cf802a7b1d43d2 🔍 |
| SHA256 | e68f7d3cc46f7a6473c29076e5ba4deafac174767b8972a99a942dc7ecd26dda 🔍 |
| SHA3 | e27035802d4cedf5e2c3697b457df5d4ce784bde96139e2760dbb8b75f70806e 🔍 |
| VirtualSize | 0x1119000 |
| VirtualAddress | 0x1ee000 |
| SizeOfRawData | 0x1119000 |
| PointerToRawData | 0x200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 7.78427 |
| MD5 | 548f0091026ac58fefc665d5df585c3c 🔍 |
|---|---|
| SHA1 | e45f1716d2059f1c1b2097e70e61cec9d7bac1a2 🔍 |
| SHA256 | 191431b4fa52824d6a02ee44758c6174e9ac16302410634ec7b1b5c3c6e8610e 🔍 |
| SHA3 | e5de27eead1a35e36966aa1662bcf8f5f8afe88ea3653e16ffe49fa1beecf522 🔍 |
| VirtualSize | 0xc000 |
| VirtualAddress | 0x1307000 |
| SizeOfRawData | 0xb800 |
| PointerToRawData | 0x1119200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 4.54475 |
| ADVAPI32.dll |
IsValidSid
|
|---|---|
| COMCTL32.dll |
ImageList_Add
|
| COMDLG32.dll |
GetSaveFileNameW
|
| GDI32.dll |
BitBlt
|
| gdiplus.dll |
GdipFree
|
| imagehlp.dll |
MakeSureDirectoryPathExists
|
| IPHLPAPI.DLL |
IcmpSendEcho
|
| KERNEL32.DLL |
LoadLibraryA
ExitProcess GetProcAddress VirtualProtect |
| msi.dll |
#70
|
| MSVCRT.dll |
cos
|
| NETAPI32.dll |
NetUserDel
|
| ole32.dll |
CoInitialize
|
| OLEAUT32.dll |
SafeArrayGetElement
|
| SETUPAPI.dll |
SetupIterateCabinetW
|
| SHELL32.dll |
#524
|
| SHLWAPI.dll |
PathMatchSpecW
|
| urlmon.dll |
URLDownloadToFileW
|
| USER32.dll |
GetDC
|
| USERENV.dll |
GetDefaultUserProfileDirectoryW
|
| WININET.dll |
InternetOpenW
|
| WINMM.dll |
timeBeginPeriod
|
| WINSPOOL.DRV |
SetPrinterW
|
| WS2_32.dll |
sendto
|
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0xea8 |
| TimeDateStamp | 2021-Nov-26 10:22:21 |
| Entropy | 4.77266 |
| MD5 | b91dfb58d28a620ce5903736baafed0d 🔍 |
| SHA1 | 399ea2003cb06393d4d8552d4d3ed308e0da2e28 🔍 |
| SHA256 | a5b578dd05dd966b8154c45589d9f4c4997c388f89cd1615f0507594f9671b8f 🔍 |
| SHA3 | e328d0612cf1ff38c411927390b44e130149cd7243e12f75a63fdd839e8c4ec1 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x8a8 |
| TimeDateStamp | 2021-Nov-26 10:22:21 |
| Entropy | 5.29604 |
| MD5 | eeedec0e99eddbf26b17e36eea0b76ac 🔍 |
| SHA1 | 25826ac568237b22e43f8ceb021f333514be19d5 🔍 |
| SHA256 | 2902fad50697e55603cdf43006ecb62a518dcb01872ba79d11ea1719c04868ff 🔍 |
| SHA3 | 30003259647b920d96f05125f691c5d511004413bd48216d057ce914ff8448f0 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x6c8 |
| TimeDateStamp | 2021-Nov-26 10:22:21 |
| Entropy | 4.35071 |
| MD5 | 7abe8c176dbe2ae2ad5f9b41b39da62d 🔍 |
| SHA1 | fdacd53099ada70fcf91988cef9e29e4b490ca81 🔍 |
| SHA256 | cc3506eadd7e416b621899c23c435280f2869dc45a66b99b95ac0d92df654261 🔍 |
| SHA3 | 6a4bdcca2822234763e90d596747bd97dbfc1e2019ccd4900eb92f5f586b31f6 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x568 |
| TimeDateStamp | 2021-Nov-26 10:22:21 |
| Entropy | 3.03007 |
| MD5 | 02a09b53b53c0e3b0f82977eb58ab5b9 🔍 |
| SHA1 | 712bf54be3ee3c2daabe4ad730c08dd76e73a55d 🔍 |
| SHA256 | 8d20d73af732650caa2467f207905a0f30af8270243306f84afba87102301462 🔍 |
| SHA3 | e2924a6b8cf26ed892fbb368c2cd1423155690dd3d822ac372aa75971e43868b 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x4228 |
| TimeDateStamp | 2021-Nov-26 10:22:21 |
| Entropy | 3.79019 |
| MD5 | 79f34f59a1682db69ce1a1b9014771dc 🔍 |
| SHA1 | adbb3afafeaffdf99402d9ad49ed0cbdeef13c46 🔍 |
| SHA256 | 737f61d83e94b9f96fa7d8a2e341e0120eee33b4aa0ddb24e61fca4d8ed60090 🔍 |
| SHA3 | 537e0ab314bce8c179111115d97e55e9082e85650d88110671068425e8b21e13 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x25a8 |
| TimeDateStamp | 2021-Nov-26 10:22:21 |
| Entropy | 4.1678 |
| MD5 | 24a1e7e7c6e045aefe1a55e777d0818a 🔍 |
| SHA1 | d3c6c274f87d67ab2ebcafc22c80d8b5c6bf30ab 🔍 |
| SHA256 | 2371b811ce9e67be6371eb03cc6693973e6ba95483c177406be4165aa6a7fe5c 🔍 |
| SHA3 | 50660bb5a0d1bcc535069946db77f2f63e58f26aabbafc7c11050fbb7dcb4f19 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x10a8 |
| TimeDateStamp | 2021-Nov-26 10:22:21 |
| Entropy | 4.32586 |
| MD5 | f1e11368814679b45bf408938a83d89c 🔍 |
| SHA1 | 4ff9edddd0b7255764a20c559615107207bd4388 🔍 |
| SHA256 | d98b9f4207a4ed1122444a0f4d6ff15da9b99d65621491c6780b93bcddd0bbd1 🔍 |
| SHA3 | cc25469871061919e8aaa8992c2b437c235dc3ac4f4855b51a4f90da37a08fc6 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x988 |
| TimeDateStamp | 2021-Nov-26 10:22:21 |
| Entropy | 4.672 |
| MD5 | 95476d8cba2b0fc425a45b23f962492e 🔍 |
| SHA1 | 79786f5ca7ecac9fc5a4be0f4e65310c4f349cd6 🔍 |
| SHA256 | 5d3d4d5c58ccd81cee4b20fbaf65a19ba7abaa340c3239e51c47fcf1be349d54 🔍 |
| SHA3 | b920b15629910073d9b7072ae22d53243abc449536d5b368068cbc836c823004 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x468 |
| TimeDateStamp | 2021-Nov-26 10:22:21 |
| Entropy | 5.05539 |
| MD5 | de7d3bc3dcac36f1b115df41c3667658 🔍 |
| SHA1 | 6b8192c80e09243cb2085806d23d6dd6d1908317 🔍 |
| SHA256 | 72781296cf166c7ee02dd8af1e646ba2f931e3cc3c225c35808d0046ab42b352 🔍 |
| SHA3 | be8c8278836f822ae0e684bd418b6dcf9c9a1b27fefea531c59915c6ce8369f5 🔍 |
| Type |
RT_GROUP_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x84 |
| TimeDateStamp | 2021-Nov-26 10:22:21 |
| Entropy | 2.96193 |
| Detected Filetype | Icon file |
| MD5 | f2ead720e26aea3a53ab0840ceb93532 🔍 |
| SHA1 | 877ecc189bf14a4099f528ad5db16aa69d16c9b2 🔍 |
| SHA256 | acf711e5149fd94f1e8f573fde716526e9fae613de09caecc0bd36d3f6379b8e 🔍 |
| SHA3 | 34781bb9ede25f9cd457c5451b0c6c37e8e3af30b96455bf3171318e843a237d 🔍 |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0xdc |
| TimeDateStamp | 2021-Nov-26 10:22:21 |
| Entropy | 2.8401 |
| MD5 | 61c2d539142494e260eb8f59d7305c2a 🔍 |
| SHA1 | 1ad871c438d93ecff8987625891a268afc69565e 🔍 |
| SHA256 | 8c7bc0bdc943cd5772bbdd1c7be396c4c58e512253a426087c5f409a91c05bae 🔍 |
| SHA3 | e9201342749dcaed0bb50e453855cca275d172cea8618f8769a8f2241731081f 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x45d |
| TimeDateStamp | 2021-Nov-26 10:22:21 |
| Entropy | 4.94291 |
| MD5 | 667ee0f31d872eb834e8eee3eb03b08d 🔍 |
| SHA1 | 65ed2d5bc3909aa61658875136d1b749945f6c32 🔍 |
| SHA256 | 60a9685101e42cbadb8cc08e0c65eb66d4a2777b929590cbc0f9fe0f3b8e12be 🔍 |
| SHA3 | c7fdef6b9222847b1edc26fdc67f521ac539f92e93f558acb0c267084f84fb34 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.6.4.0 |
| ProductVersion | 1.6.4.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| Resource LangID | English - United States |
|---|
No comments yet.