7e25a4d3816ba30096157100b32fc87c143b7e71bf6ac7b85712823f491480c7

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Apr-02 17:42:21
Detected languages English - United States

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Malicious The PE contains functions mostly used by malware. Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Code injection capabilities:
  • CreateRemoteThread
  • OpenProcess
  • VirtualAllocEx
  • WriteProcessMemory
Possibly launches other programs:
  • system
Manipulates other processes:
  • OpenProcess
  • WriteProcessMemory
  • Process32First
  • Process32Next
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 46703b3ef7fd7ffadb3effccfec5331f
SHA1 72cf1bdccf99bef97775e8121898f3f253fbe33c
SHA256 7e25a4d3816ba30096157100b32fc87c143b7e71bf6ac7b85712823f491480c7
SHA3 db3f2b30eddba6df79955e2021999dee062a5ecbfa7daa202cc7fd9d41431960
SSDeep 384:1+KrkoQdyYW8Ntstj+BEzWefXv2duUmdeG8OghKKiMNRTcoJujrFpV0Lo7dHQsk:UCTYptstyBonfX+dGbL2oJHQsk
Imports Hash 85c194eb7b6143c238af3e8b6f49eaf4

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Apr-02 17:42:21
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x3a00
SizeOfInitializedData 0x3200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000037AC (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xb000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 ca59ae2eff3df4293b5d024c25d650f3
SHA1 2b82a42e6063b22c91ebc1682721d76f20b34ea4
SHA256 6819eec2347532921d5db4b090404753d0f0b0f556098a875dc47bf4cc276324
SHA3 f0cb23ba39faa14646885f71ad7969255824c8b9772f626ee597e10eb0484f93
VirtualSize 0x39d4
VirtualAddress 0x1000
SizeOfRawData 0x3a00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.2129

.rdata

MD5 33759f92a595187b83afd31fe0e64a2a
SHA1 6d83c23130e7dacde84e6d9ad475c8b0a5222d50
SHA256 d9b0a5ba28040cf7e090edfe8922e0261f756d82b0da35679ba0aff0a6ad7b0a
SHA3 2d2059f6fa543933a97cbe8acb253cb1c1b94c5c2e32ba8d56802b50550043a5
VirtualSize 0x1fa0
VirtualAddress 0x5000
SizeOfRawData 0x2000
PointerToRawData 0x3e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.41833

.data

MD5 cd6045d246a269d54f995a4ec7e82afc
SHA1 7fcd9a089e16308ab00ff3386af41a94a0a3f7f4
SHA256 91859f0904acc8cdc883f29e757ed8ce8c2d6b4c969094c089e6e515c7c56217
SHA3 afbef083a8a44b2291a20a6d750b936e3da52b2ab956241e6b2bc788b847f523
VirtualSize 0x9f0
VirtualAddress 0x7000
SizeOfRawData 0x200
PointerToRawData 0x5e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.09313

.pdata

MD5 5b04ab75975db0025eff972ae1be521e
SHA1 fc1fac984af39f716f54806cc541378e7cca520a
SHA256 20b567a17aa56e13ff934d46c0f4f046bbe9109ea90959b08c4192b04d977fb9
SHA3 f26ffbe7beec74ba96943716d57f7706fec87b8a485135b549f4b6e37bb2a7fc
VirtualSize 0x390
VirtualAddress 0x8000
SizeOfRawData 0x400
PointerToRawData 0x6000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.64508

.rsrc

MD5 fb20ae2a7910d36ef7e1ed0b22953dbf
SHA1 53b0a43a879cf778730d8bd7309f76d73d40a678
SHA256 3ecd84e2d8e73672dba01382283fde59898dcd230ee8af5d9870cef983142e6a
SHA3 6d192e7d311d72fa64237646e50ec96550f5043fa0e8a3ed75069671657a6958
VirtualSize 0x1e0
VirtualAddress 0x9000
SizeOfRawData 0x200
PointerToRawData 0x6400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.7015

.reloc

MD5 deab370a07ebf19ef1b19225be396507
SHA1 9159601ceb6e8a312661ea9537a6be4fbce3960b
SHA256 9442b148db12958b1c9ca07384286420d4ab832e7747b6026a74a95bd1077f65
SHA3 8cade1ee228807e1b1494136b74858cb25686a9f9d3d77c0dbe7bccd89c89f44
VirtualSize 0x60
VirtualAddress 0xa000
SizeOfRawData 0x200
PointerToRawData 0x6600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.32723

Imports

KERNEL32.dll GetFileAttributesA
GetFullPathNameA
CloseHandle
WaitForSingleObject
Sleep
CreateRemoteThread
GetExitCodeThread
OpenProcess
VirtualAllocEx
WriteProcessMemory
VirtualFreeEx
GetModuleHandleA
GetProcAddress
CreateToolhelp32Snapshot
Process32First
Process32Next
GetSystemTimeAsFileTime
GetCurrentThreadId
GetCurrentProcessId
QueryPerformanceCounter
TerminateProcess
GetCurrentProcess
GetModuleHandleW
IsProcessorFeaturePresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
IsDebuggerPresent
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
SleepConditionVariableSRW
WakeAllConditionVariable
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
InitializeSListHead
MSVCP140.dll ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ
?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?width@ios_base@std@@QEAA_J_J@Z
?width@ios_base@std@@QEBA_JXZ
?flags@ios_base@std@@QEBAHXZ
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?_Xlength_error@std@@YAXPEBD@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?uncaught_exceptions@std@@YAHXZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z
?good@ios_base@std@@QEBA_NXZ
VCRUNTIME140.dll __current_exception_context
__current_exception
__C_specific_handler
memset
memmove
memcpy
_CxxThrowException
__std_exception_destroy
__std_terminate
__std_exception_copy
VCRUNTIME140_1.dll __CxxFrameHandler4
api-ms-win-crt-runtime-l1-1-0.dll _exit
_register_thread_local_exe_atexit_callback
system
_c_exit
_invalid_parameter_noinfo_noreturn
__p___argc
_configure_narrow_argv
terminate
exit
_initterm_e
_initterm
_get_initial_narrow_environment
__p___argv
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
_register_onexit_function
_initialize_onexit_table
_initialize_narrow_environment
api-ms-win-crt-string-l1-1-0.dll _stricmp
api-ms-win-crt-heap-l1-1-0.dll _callnewh
free
malloc
_set_new_mode
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
api-ms-win-crt-stdio-l1-1-0.dll _set_fmode
__p__commode
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Apr-02 17:42:21
Version 0.0
SizeofData 852
AddressOfRawData 0x590c
PointerToRawData 0x470c

TLS Callbacks

StartAddressOfRawData 0x140005c80
EndAddressOfRawData 0x140005c88
AddressOfIndex 0x140007438
AddressOfCallbacks 0x1400053a8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140007040

RICH Header

XOR Key 0x40812f9a
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 12
ASM objects (33731) 3
C objects (33731) 10
C++ objects (33731) 27
Imports (33731) 6
Imports (33145) 3
Total imports 97
C++ objects (33821) 1
Resource objects (33821) 1
Linker (33821) 1

Errors

Leave a comment

No comments yet.