7eec456812e81284b421b624db2fec53bd08bcb7dda01c7271ae720ad37c5af7

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-27 05:01:32
Detected languages English - United States
CompanyName Microsoft Corporation
FileDescription Windows Executable
FileVersion 10.0.19041.1
InternalName WinExec
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename WinExec.exe
ProductName Microsoft Windows Operating System
ProductVersion 10.0.19041.1

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Tries to detect virtualized environments:
  • HARDWARE\DESCRIPTION\System
Looks for VMWare presence:
  • VMware
May have dropper capabilities:
  • CurrentControlSet\Services
  • CurrentVersion\Run
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • https://api.gofile.io
  • https://api.gofile.io/servers
Malicious The file headers were tampered with. Unusual section name found: 6MQQ4
Unusual section name found: To36E
Unusual section name found: dTH2eW6
Unusual section name found: IjOWm
Unusual section name found: l1GgZADk
Unusual section name found: SrxW
Unusual section name found: HqZWPd
The RICH header checksum is invalid.
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • GetTempPathA
  • CreateFileA
  • GetTempPathW
  • CreateFileW
Leverages the raw socket API to access the Internet:
  • freeaddrinfo
  • inet_ntop
  • getaddrinfo
Enumerates local disk drives:
  • GetVolumeInformationA
Manipulates other processes:
  • Process32First
  • Process32Next
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 20/69 (Scanned on 2026-07-27 09:09:20) ALYac: Gen:Variant.Yogi.25083
APEX: Malicious
Arcabit: Trojan.Yogi.D61FB
BitDefender: Gen:Variant.Yogi.25083
Bkav: W32.Malware.C861BE3C
CTX: exe.unknown.yogi
CrowdStrike: win/malicious_confidence_90% (D)
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Yogi.25083 (B)
GData: Gen:Variant.Yogi.25083
Kaspersky: VHO:Trojan-PSW.Win32.Stealer.gen
Malwarebytes: Malware.AI.4109038465
MicroWorld-eScan: Gen:Variant.Yogi.25083
Microsoft: Trojan:Win32/Wacatac.C!ml
Sangfor: Virus.Win32.Save.a
SentinelOne: Static AI - Suspicious PE
Sophos: Generic ML PUA (PUA)
Symantec: ML.Attribute.HighConfidence
Trapmine: suspicious.low.ml.score
VIPRE: Gen:Variant.Yogi.25083

Hashes

MD5 de506e1ea48f711de5ceb3a92be8e28b
SHA1 354da41eed03531091fe30b0ec7fb25397f251e1
SHA256 7eec456812e81284b421b624db2fec53bd08bcb7dda01c7271ae720ad37c5af7
SHA3 688ce3dd25057fd03651fa985e219b3f86309c571665d8ffeafec42bd2a3979e
SSDeep 24576:8/TtN7ZX9D5d8X+q9YHvu4GFmzCFsH10AMnUWj4AgM447/f5Sy:85h37MYHvuLA3MnUWj4AgMXjT
Imports Hash bcc33afff7b7ca155c02bb0985562f7e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x72ee
e_minalloc 0x5506
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Jul-27 05:01:32
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x13c600
SizeOfInitializedData 0x53a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000011C150 (Section: 6MQQ4)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x196000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

6MQQ4

MD5 d7fabe38d5724b02e45cb5e4f99c445f
SHA1 68d359f3b59357516981772f8b51d6867273d6d1
SHA256 698081b0b225b1e0e23b09e2ad9639e1c1d92a10b725ecccf957666fca4916fd
SHA3 cf5ffabeb1277c5568dc75866e6a9e709af3ee9304d15da865c1579b5c767002
VirtualSize 0x13c57a
VirtualAddress 0x1000
SizeOfRawData 0x13c600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.53682

To36E

MD5 002f2985ef51827c9f37d6f1a815527e
SHA1 a36405870718c04d90328dd4bf2d80dd1eb8a8c1
SHA256 c8eac6d08fab6cd898f30f397d17c1a1790ab50c303ee2e6e56933ba457549e7
SHA3 b466d75595e432ab71c8e1ea8b4fd907625483fd8ce19cf92e3f881082f3be1d
VirtualSize 0x2e262
VirtualAddress 0x13e000
SizeOfRawData 0x2e400
PointerToRawData 0x13ca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.88617

dTH2eW6

MD5 fe1ae99a21690619243ebd096f96144f
SHA1 9f74c41e8b1234500ceb0aa44426771ac0227e0e
SHA256 7fdac6faa92fb2ca257ac226b19adc4b18d0f54aeb37301507ecd510aad4229a
SHA3 feed867d7579f37725100f7e9d7ae970039c3faa92fd7e4f1385b4c5f3449775
VirtualSize 0x17744
VirtualAddress 0x16d000
SizeOfRawData 0x5200
PointerToRawData 0x16ae00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.00892

IjOWm

MD5 406b4bfa9fb3915f71e3dc982c51a9c1
SHA1 ec1e06e521e7a39343f87506e08045914f47ef1c
SHA256 33509702e7f0c9441490973c1c70ad3fc37ce231dd5d250d91eab6309f75e6e4
SHA3 24131ef1304370fc8f77ee6702088d1e687ccd271c7adbdf21ac068da4071e6c
VirtualSize 0xc204
VirtualAddress 0x185000
SizeOfRawData 0xc400
PointerToRawData 0x170000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.15507

l1GgZADk

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x100
VirtualAddress 0x192000
SizeOfRawData 0x200
PointerToRawData 0x17c400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

SrxW

MD5 cc22baedbf99c2961e087c62436f715c
SHA1 a3685a10a3aea72882034fcaa9df95bf6ea9c405
SHA256 b87b51847081dc62c9d22ad6bd83c184efc23f2ec4a07a4630102bc18e75ca26
SHA3 1968e7397e9b79ddde92ee01977d9ce293c0a5f483b07f08426c0578b5182ade
VirtualSize 0x3b0
VirtualAddress 0x193000
SizeOfRawData 0x400
PointerToRawData 0x17c600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.09515

HqZWPd

MD5 bfc84610b2f1628bb38450101408758e
SHA1 9d1475b1fffc981a76ec85f239fde7a30bc95c14
SHA256 a535b560a593bacc22beb7d89808a27bafa1442652e59f22627caa724914b4ce
SHA3 8991737886b9a7c51bb877e6aceb3b94d670d06d3f24e1d58184c71ee1b432a2
VirtualSize 0x12c0
VirtualAddress 0x194000
SizeOfRawData 0x1400
PointerToRawData 0x17ca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.34913

Imports

USER32.dll GetSystemMetrics
EnumDisplaySettingsA
CloseClipboard
OpenClipboard
ShowWindow
EnumDisplayDevicesA
GetClipboardData
KERNEL32.dll SetEnvironmentVariableW
FreeEnvironmentStringsW
ReadFile
GetModuleFileNameA
GetLogicalDrives
GetFileSizeEx
Process32First
FindFirstFileA
GetCurrentProcess
WriteFile
FindNextFileA
ExpandEnvironmentStringsA
lstrlenA
GetEnvironmentVariableA
FindClose
GetVolumeInformationA
GetFileAttributesW
lstrcatA
GetModuleHandleA
GetLocaleInfoA
CreateToolhelp32Snapshot
MultiByteToWideChar
Sleep
GetTempPathA
GetDiskFreeSpaceA
CopyFileA
GetLastError
GetFileAttributesA
CreateFileA
LoadLibraryA
DeleteFileA
Process32Next
lstrcpyA
CloseHandle
FreeConsole
GetSystemInfo
GetProcAddress
GlobalLock
LocalFree
ExitProcess
GlobalMemoryStatusEx
FreeLibrary
WideCharToMultiByte
GetConsoleWindow
GetEnvironmentStrings
GetTempFileNameA
GetTickCount
GlobalUnlock
FreeEnvironmentStringsA
IsDebuggerPresent
GetComputerNameA
AreFileApisANSI
TryEnterCriticalSection
GetStringTypeW
EnterCriticalSection
GetFullPathNameW
GetDiskFreeSpaceW
OutputDebugStringA
LockFile
LeaveCriticalSection
InitializeCriticalSection
SetFilePointer
GetFullPathNameA
SetEndOfFile
UnlockFileEx
GetTempPathW
CreateMutexW
WaitForSingleObject
CreateFileW
GetCurrentThreadId
UnmapViewOfFile
HeapValidate
HeapSize
FormatMessageW
GetFileAttributesExW
OutputDebugStringW
FlushViewOfFile
WaitForSingleObjectEx
DeleteFileW
HeapReAlloc
RaiseException
LoadLibraryW
HeapAlloc
HeapCompact
HeapDestroy
UnlockFile
GetFileSize
DeleteCriticalSection
GetCurrentProcessId
GetProcessHeap
SystemTimeToFileTime
GetSystemTimeAsFileTime
GetSystemTime
FormatMessageA
CreateFileMappingW
MapViewOfFile
QueryPerformanceCounter
FlushFileBuffers
GetEnvironmentStringsW
GetConsoleOutputCP
WriteConsoleW
GetCommandLineW
GetCommandLineA
GetCPInfo
GetOEMCP
HeapCreate
SetStdHandle
GetACP
IsValidCodePage
FindNextFileW
FindFirstFileExW
HeapFree
LockFileEx
SetUnhandledExceptionFilter
GetStartupInfoW
GetModuleHandleW
InitializeSListHead
RtlUnwindEx
RtlPcToFileHeader
SetLastError
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
InitializeCriticalSectionEx
RtlLookupFunctionEntry
EncodePointer
DuplicateHandle
CreateProcessW
CreateThread
ExitThread
FreeLibraryAndExitThread
GetModuleHandleExW
TerminateProcess
GetModuleFileNameW
GetStdHandle
IsProcessorFeaturePresent
RtlCaptureContext
RtlVirtualUnwind
UnhandledExceptionFilter
SetFilePointerEx
GetConsoleMode
ReadConsoleW
GetFileType
GetExitCodeProcess
CreatePipe
VirtualProtect
LoadLibraryExW
CompareStringW
LCMapStringW
GetTimeZoneInformation
ADVAPI32.dll GetUserNameA
WS2_32.dll freeaddrinfo
inet_ntop
getaddrinfo
IPHLPAPI.DLL GetAdaptersInfo

Delayed Imports

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x34c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.43376
MD5 916f8cb8d12ef0d8e95e11fac6c35f59
SHA1 2e0ec657456e6b559bd94e50786ca95ae219f5dc
SHA256 38fd409aa00036a96c0b37148698fbea120e4fd8b5c4767a673447320b7dff9a
SHA3 e0df2bc728e33306001c28f390c271c9d8ad16db15ac788a7383286f2ded6604

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 10.0.19041.1
ProductVersion 10.0.19041.1
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Microsoft Corporation
FileDescription Windows Executable
FileVersion (#2) 10.0.19041.1
InternalName WinExec
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename WinExec.exe
ProductName Microsoft Windows Operating System
ProductVersion (#2) 10.0.19041.1
Resource LangID English - United States

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-27 05:01:32
Version 0.0
SizeofData 900
AddressOfRawData 0x15c060
PointerToRawData 0x15aa60

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14016d040

RICH Header

XOR Key 0x9eda397a
Unmarked objects 0
C++ objects (35222) 179
C objects (35222) 14
ASM objects (35222) 10
ASM objects (35721) 10
C objects (35721) 17
C++ objects (35721) 44
Imports (35222) 17
Total imports 179
C++ objects (LTCG) (36248) 2
Resource objects (36248) 1
Linker (36248) 1

Errors

Leave a comment

No comments yet.