| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Apr-26 11:35:40 |
| Detected languages |
English - United States
|
| FileDescription | Top Family |
| FileVersion | |
| ProductVersion | |
| LegalCopyright | Abstract Righteous Top Family 2018-2026 |
| ProductName | Top Family |
| CompanyName | Abstract Righteous Top Family |
| Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to AES Uses known Mersenne Twister constants |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 21/69 (Scanned on 2026-05-13 16:13:22) |
AhnLab-V3:
Malware/Win.Generic.C5878287
Alibaba: AdWare:Win32/AdLoad.e05ad7a0 CTX: exe.trojan.adload CrowdStrike: win/grayware_confidence_100% (D) DeepInstinct: MALICIOUS Google: Detected Gridinsoft: Adware.Win32.Adload.cl Kaspersky: Trojan-Downloader.Win32.Adload.vjpu Kingsoft: Win32.Trojan-Downloader.Adload.vjpu Lionic: Trojan.Win32.Adload.a!c McAfeeD: ti!7A87FCB3B4A0 Microsoft: PUA:Win32/Presenoker Rising: Downloader.Adload!8.D1 (LESS:bWQ1Okfa4zXAKIXu) Skyhigh: Artemis Sophos: Generic Reputation PUA (PUA) Symantec: Trojan.Gen.MBT Tencent: Win32.Trojan-Downloader.Adload.Xtjl TrellixENS: Artemis!0A437C4161B4 Varist: W32/ABApplication.EINQ-5188 Xcitium: ApplicUnwnt@#38ecsarqus12m alibabacloud: Trojan[downloader]:Win/Presenoker.Gen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x120 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2026-Apr-26 11:35:40 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x3fd200 |
| SizeOfInitializedData | 0x48200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00384AE0 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x3ff000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x449000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x1584d4e |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
SetEnvironmentVariableW
GetCommandLineW GetLastError QueryPerformanceFrequency FormatMessageW InitializeCriticalSectionAndSpinCount LoadLibraryExW SetStdHandle VerSetConditionMask FreeLibraryAndExitThread GetModuleHandleW InitializeSListHead LocalFree MoveFileA AreFileApisANSI SetPriorityClass CreateDirectoryW IsProcessorFeaturePresent SystemTimeToTzSpecificLocalTime FileTimeToSystemTime TerminateProcess SetFileTime GetTimeFormatW GetCurrentDirectoryA CreateDirectoryA GlobalMemoryStatus RaiseException PeekNamedPipe SetUnhandledExceptionFilter GetModuleFileNameW GetTickCount CompareFileTime GetProcAddress FileTimeToLocalFileTime GetCurrentThreadId TryEnterCriticalSection SleepConditionVariableSRW VirtualQuery WaitForSingleObject WriteConsoleW GetUserDefaultLCID GetACP EncodePointer InitializeCriticalSectionEx FreeEnvironmentStringsW GetSystemInfo ExitThread GetProcessHeap SetFilePointerEx InitializeSRWLock FindNextFileW DeleteFileA CreateSemaphoreA GetSystemDirectoryW GetFileSizeEx GetLocaleInfoW RemoveDirectoryW GetStartupInfoW CreateFileW GetFileInformationByHandle GetModuleHandleExW SleepEx DeleteFileW LoadLibraryW TlsAlloc WaitForMultipleObjects FindClose ReadFile HeapReAlloc GetConsoleOutputCP GetDriveTypeW RemoveDirectoryA GetOEMCP QueryPerformanceCounter IsDebuggerPresent FindFirstFileW SetFileAttributesW WakeAllConditionVariable TlsGetValue GetCurrentProcessId ReleaseSemaphore SetEvent GetFileAttributesA SetFileAttributesA GetFileAttributesExW GetStdHandle GetModuleHandleA LCMapStringW SetEndOfFile DecodePointer CreateThread GetFullPathNameW RtlUnwind SetLastError CloseHandle ResetEvent TlsSetValue SleepConditionVariableCS CreateEventA EnterCriticalSection GetSystemTimeAsFileTime FreeLibrary GetConsoleMode GetCommandLineA CreateFileA GlobalFree VerifyVersionInfoW GetCurrentDirectoryW HeapSize FindFirstFileA WaitForSingleObjectEx WriteFile IsValidLocale EnumSystemLocalesW GetModuleFileNameA UnhandledExceptionFilter GetFileAttributesW ReleaseSRWLockExclusive LeaveCriticalSection Sleep DeleteCriticalSection GetDateFormatW LoadLibraryA GetEnvironmentVariableA GetCurrentProcess GetExitCodeThread LCMapStringEx WideCharToMultiByte GetFileType GetLogicalDriveStringsW InitializeCriticalSection GlobalLock WakeConditionVariable SetFilePointer GetLogicalDriveStringsA GetProcessAffinityMask GetStringTypeW GetFileSize FormatMessageA InitializeConditionVariable FindNextFileA VirtualFree VirtualAlloc MoveFileW GetVersion MoveFileExW HeapFree HeapAlloc TlsFree GetTimeZoneInformation FlushFileBuffers CompareStringW GetEnvironmentStringsW ReadConsoleW AcquireSRWLockExclusive GetVersionExA GlobalUnlock MultiByteToWideChar IsValidCodePage FindFirstFileExW ExitProcess GetCPInfo GlobalAlloc |
|---|---|
| USER32.dll |
LoadStringA
SetTimer InvalidateRect CharUpperW DestroyIcon GetWindowTextA ScreenToClient SetWindowTextA GetWindowLongA SendMessageW CloseClipboard ShowWindow DialogBoxParamA GetWindowTextW GetFocus SendMessageA LoadStringW EndDialog SetFocus LoadIconA GetWindowTextLengthW MonitorFromWindow MessageBoxW SetClipboardData CheckDlgButton GetParent OpenClipboard MapDialogRect KillTimer GetWindowTextLengthA GetMonitorInfoA GetDlgItem SetWindowTextW PostMessageA EmptyClipboard IsDlgButtonChecked LoadCursorA SystemParametersInfoA MoveWindow EnableWindow CharUpperA SetWindowLongA DialogBoxParamW GetKeyState SetCursor GetWindowRect |
| ole32.dll |
CoUninitialize
OleInitialize CoInitialize CoTaskMemFree CoCreateInstance |
| OLEAUT32.dll |
SysStringLen
SysAllocStringLen SysAllocString VariantClear SysFreeString |
| SHELL32.dll |
SHGetPathFromIDListA
SHBrowseForFolderA SHGetFileInfoA |
| &Close |
| &Continue |
| &Foreground |
| Paused |
| Are you sure you want to cancel? |
| Modified |
| The system cannot allocate the required amount of memory |
| Cannot create folder '{0}' |
| Update operations are not supported for this archive. |
| Cannot open file '{0}' as archive |
| Cannot open encrypted archive '{0}'. Wrong password? |
| Unsupported archive type |
| Cannot open the file as {0} archive |
| The file is open as {0} archive |
| The archive is open with offset |
| Extracting |
| Skipping |
| Specify a location for extracted files. |
| Full pathnames |
| No pathnames |
| Absolute pathnames |
| Relative pathnames |
| Ask before overwrite |
| Overwrite without prompt |
| Skip existing files |
| Auto rename |
| Auto rename existing files |
| {0} bytes |
| Unsupported compression method for '{0}'. |
| Data error in '{0}'. File is broken |
| CRC failed in '{0}'. File is broken. |
| Data error in encrypted file '{0}'. Wrong password? |
| CRC failed in encrypted file '{0}'. Wrong password? |
| Wrong password? |
| Unsupported compression method |
| Data error |
| CRC failed |
| Unavailable data |
| Unexpected end of data |
| There are some data after the end of the payload data |
| Is not archive |
| Headers Error |
| Wrong password |
| Unavailable start of archive |
| Unconfirmed start of archive |
| Unsupported feature |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.4.1 |
| ProductVersion | 1.0.4.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileDescription | Top Family |
| FileVersion (#2) | |
| ProductVersion (#2) | |
| LegalCopyright | Abstract Righteous Top Family 2018-2026 |
| ProductName | Top Family |
| CompanyName | Abstract Righteous Top Family |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-26 11:35:40 |
| Version | 0.0 |
| SizeofData | 852 |
| AddressOfRawData | 0x427614 |
| PointerToRawData | 0x425c14 |
| Size | 0xbc |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x82f01c |
| SEHandlerTable | 0x827104 |
| SEHandlerCount | 216 |
| XOR Key | 0x15b2e28b |
|---|---|
| Unmarked objects | 0 |
| C objects (30623) | 1 |
| C objects (65501) | 5 |
| Imports (65501) | 7 |
| Total imports | 222 |
| C objects (25025) | 1 |
| C objects (LTCG) (25025) | 2 |
| Exports (25025) | 1 |
| Resource objects (25025) | 1 |
| Linker (25025) | 1 |
No comments yet.