8561c3d7137dc25bbf204abbd2317fab4f1c3b9649b21f7b4ba4291e58e70dbe

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2016-Jun-08 15:49:23
Detected languages English - United States
Turkish - Turkey

Plugin Output

Info Libraries used to perform cryptographic operations: Microsoft's Cryptography API
Suspicious This PE is packed with Themida Unusual section name found:
Unusual section name found:
Unusual section name found:
Unusual section name found:
Unusual section name found:
Unusual section name found:
Unusual section name found:
Unusual section name found: .themida
Section .themida is both writable and executable.
Unusual section name found: .boot
Suspicious The PE contains functions most legitimate programs don't use. Possibly launches other programs:
  • ShellExecuteW
Uses Microsoft's cryptographic API:
  • CryptReleaseContext
Leverages the raw socket API to access the Internet:
  • WSARecvFrom
Interacts with the certificate store:
  • CertOpenStore
Malicious VirusTotal score: 20/62 (Scanned on 2026-05-13 08:07:10) Alibaba: Backdoor:Win64/Themida.0c827396
Antiy-AVL: Trojan[Packed]/Win64.Themida
Avira: TR/W64.Agent
Bkav: W32.Malware.245D1C67
CrowdStrike: win/malicious_confidence_100% (W)
Cylance: Unsafe
Cynet: Malicious (score: 99)
DeepInstinct: MALICIOUS
ESET-NOD32: Win64/Packed.Themida.Q suspicious application
Elastic: malicious (high confidence)
Fortinet: Riskware/Application
Google: Detected
Malwarebytes: Malware.Heuristic.2025
McAfeeD: ti!8561C3D7137D
Microsoft: Trojan:Win32/Wacatac.B!ml
Paloalto: generic.ml
SentinelOne: Static AI - Suspicious PE
Symantec: ML.Attribute.HighConfidence
Varist: W64/ABApplication.AIYA-5350
alibabacloud: VirTool:Win/Wacatac.B9nj

Hashes

MD5 203ac1195a623a074487ee4641b96e90
SHA1 59cab0592011f220ca73aae66076c59bdf8c6cc4
SHA256 8561c3d7137dc25bbf204abbd2317fab4f1c3b9649b21f7b4ba4291e58e70dbe
SHA3 a17a3df1841f2f4a60af2d3782a5199f89313240fe3ef7e0cf8e614ebffbb25d
SSDeep 196608:jHHI0LgfclIYHJVYZlnQVl8EgRBSU/U133C/zhzaCK+9QsJfcWH6X0HWhx67kYH3:tLVbpSeltgRBHU5CFmCHimcWH6CM6YYX
Imports Hash 8035a7c5c5d639e233b8747b988484fd

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x138

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 13
TimeDateStamp 2016-Jun-08 15:49:23
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x6e3400
SizeOfInitializedData 0x35fa00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000001988058 (Section: .boot)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x22d1000
SizeOfHeaders 0x600
Checksum 0xd95e50
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

MD5 565d0e6f07b51e406572fcb70b5572b4
SHA1 3a81863bc85d6047807482d6b22a951e0d3346fe
SHA256 08cc54a5b8f81d605b176e0b8e629b2deaea58445a17d2ecd8cfad975c076f8d
SHA3 2dc8d98a34ad1f1602bde6d666b63ad72e92ff6e9f69020a29f32b825a2dc835
VirtualSize 0x6e3204
VirtualAddress 0x1000
SizeOfRawData 0x2b4c00
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 7.98283

(#2)

MD5 859f3b4abc68bbbbd3b5d3e5cb89fdd0
SHA1 db2c701a86f17bb5cd23d160029ca405146d4284
SHA256 e80b4810871e5a3619faefdc0543b871e8d1aafd576b221e8cf1230ffb5532a1
SHA3 17e2f81c577fefe6cce60be72afc63e08de2f2be18ec0803c1a3d117a2836df2
VirtualSize 0x22743c
VirtualAddress 0x6e5000
SizeOfRawData 0xdde00
PointerToRawData 0x2b5200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.97544

(#3)

MD5 e71d1353d320afbfcc7f4556e3a448f4
SHA1 e4526d43bee36819e8f50c58376589430bce5328
SHA256 668eb8a36a02205b94a144831c4812dad9ef81cec95679b6b360ecaf7904cfc4
SHA3 759045e6259e29d51d3e7235efef35313b131684a6ee4a7034d8584057e6aebb
VirtualSize 0x5a454
VirtualAddress 0x90d000
SizeOfRawData 0x4c00
PointerToRawData 0x393000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.9482

(#4)

MD5 b7ec04a7e59abbad6dd80b9f27bd61bb
SHA1 32ad60034e93fd5c5909308b3bacbb0173ab09c6
SHA256 3d8cee847718c63ac52adebe619e0a98e21b90baaa20c3175c8ae9da35b40107
SHA3 11574e797fc7e7ff2853757d4aa13cc6c3b836368903ff58cf47078ad48099f7
VirtualSize 0x4b8ac
VirtualAddress 0x968000
SizeOfRawData 0x2b400
PointerToRawData 0x397c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.65456

(#5)

MD5 b65cc5af555f3064e9de2467e2a52c07
SHA1 0233b4c6aca694fb4c67c90d93421ed463396a5e
SHA256 80b53678d0ff621a9d3af363d5b05b23c2babae5a05e570fc5fcfc69354a54c4
SHA3 f8b7d7a7992abd35086c4f1780088094b43fa9704bc8a061e47c0f0f07c695f0
VirtualSize 0x100
VirtualAddress 0x9b4000
SizeOfRawData 0x200
PointerToRawData 0x3c3000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.10191

(#6)

MD5 f64be7889b04f325f4ba0723fb8e1984
SHA1 f10dca46a388833d3506ff18f302151b54b84a6a
SHA256 09e052594f5b6eb080254f68e7869251c3e4cf508a764a4dbe8e70381ede9cde
SHA3 434a4f9eebb965cf6efce244fa78572fd5eea48dd71adc795a845a8c00a527af
VirtualSize 0x81958
VirtualAddress 0x9b5000
SizeOfRawData 0x43200
PointerToRawData 0x3c3200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.98125

(#7)

MD5 55969dfc25c320c6248bee992928b91d
SHA1 fdf30252424d35fd9cf5700325a6123beb33b142
SHA256 3afe0d19a79151e8d2e07e17ef6f92a82cdaee2ee33dd606abaa540738a69474
SHA3 c68c10f598ed582236d64dac8e68b56643f25af7d85ee01e2f26bced01bee0bb
VirtualSize 0x107d0
VirtualAddress 0xa37000
SizeOfRawData 0x7a00
PointerToRawData 0x406400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.84702

.idata

MD5 e514014d61ca48777232a337c8efd03d
SHA1 6db5e775248ee77c8a3547236eaf5221203e032e
SHA256 f3a189aa5fee64e6adac711636ab746a69c901f7916aef9d8ed4f25f799850bc
SHA3 294b8677179487c28bea1aa6f6e99ba0bce0c1ce9872b734894632e607454cc9
VirtualSize 0x1000
VirtualAddress 0xa48000
SizeOfRawData 0x600
PointerToRawData 0x40de00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.12627

.tls

MD5 aa5dabd96f2271b5d0678a84cb1314de
SHA1 398ef26f3a97d93819d777cc661127cffe271af6
SHA256 f9aa5a9b3c789f0e6025fca79f37ea4b4404e2737f71b7f22a92cf9ec627aa5b
SHA3 f2dbebf944ad7b2f864ec22541d1249c94e857b28762828a1b7b937f2c588c2d
VirtualSize 0x1000
VirtualAddress 0xa49000
SizeOfRawData 0x200
PointerToRawData 0x40e400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.367015

.rsrc

MD5 98f3502cc229265661cc58bd7af4c376
SHA1 c68a457506dcc676ea10e27593340def0bedc680
SHA256 73742b7d07f24c9d29e1664304e18b3b97e6c3fabd879561667adf00279af0c0
SHA3 706c4229eef8556375453e0f9f535b81fbc6fdb55f7a9b834cf95910cfc7ce39
VirtualSize 0x33e00
VirtualAddress 0xa4a000
SizeOfRawData 0x33e00
PointerToRawData 0x40e600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.06465

.themida

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0xf0a000
VirtualAddress 0xa7e000
SizeOfRawData 0
PointerToRawData 0x442400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.boot

MD5 671cc09b4510e01a825f15d3303d880d
SHA1 244b31deb6cad379506c9ce2914eed2460c0ee6b
SHA256 80e959ee105946c5852493a61cf602ca8dc8e810a068e6a3374f8fae8b19c1e4
SHA3 3973d3eb50e0984231b441171dea1186544245822a35b96cdaa19fbea67eece2
VirtualSize 0x947c00
VirtualAddress 0x1988000
SizeOfRawData 0x947c00
PointerToRawData 0x442400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 7.95615

.reloc

MD5 45c27d6ec61fb2ae514db90b08c777af
SHA1 4ec5634cababdb8fac1f67ef5b41c03ffdb72be6
SHA256 38e9da3bd5e93556728f57f4bbeceb3902b4781857a603768112ddd85f44d5ee
SHA3 b3886ccf1a85a6e7d70de31e9f851b5f7696f9ca4a770e39afabc1668f3f4a9d
VirtualSize 0x1000
VirtualAddress 0x22d0000
SizeOfRawData 0x10
PointerToRawData 0xd8a000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
Entropy 2.6494

Imports

kernel32.dll GetModuleHandleA
d3d9.dll Direct3DCreate9
USER32.dll GetKeyState
GDI32.dll GetDeviceCaps
COMDLG32.dll GetOpenFileNameA
ADVAPI32.dll CryptReleaseContext
SHELL32.dll ShellExecuteW
ole32.dll CoCreateInstance
OLEAUT32.dll VariantClear
WS2_32.dll WSARecvFrom
bcrypt.dll BCryptGenRandom
WINMM.dll timeBeginPeriod
CRYPT32.dll CertOpenStore
Secur32.dll InitSecurityInterfaceW
IPHLPAPI.DLL if_nametoindex
IMM32.dll ImmSetCompositionWindow
api-ms-win-core-synch-l1-2-0.dll WakeByAddressAll

Delayed Imports

1

Type RT_ICON
Language Turkish - Turkey
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.17412
MD5 f6b4dbef1424e52a2bff52700583d482
SHA1 eedb8e58cbb263e635e122343ce3ed3d1a16e23b
SHA256 b98a69b1377620e0392de69376bb34dd69369f710330a64f994e30fdf95354c8
SHA3 04a9963ea5c3e79dc88fe017a623b12c6a08e815eb53b2e2dc89df0aa198a1cd

2

Type RT_ICON
Language Turkish - Turkey
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.28681
MD5 7519cac550ee9a849d620867ae38c4f2
SHA1 8853c5e74aa415f5f6f9361278bec9e9ee6db227
SHA256 332adcbdfe564bf5f08722b1e30cdb4aa9ba632b4a60f1a4376c792b8f243201
SHA3 cff6686379db36b3657f23c4286d8559912477d905787c63f4e9ab84ee04ce6a

3

Type RT_ICON
Language Turkish - Turkey
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.17309
MD5 c3d8b3fc624b492cc974a394bd1a1e82
SHA1 e881e470de83ab7e2d992b82d2c5ffee97b0aecd
SHA256 84e723512b90d88125531079aedb7a5631500142ad1ce20d7312810efc34100a
SHA3 3c7ca9113be6b797e9c8431dd7ab5ea49ea9532f667885377a1064d3f4b2d211

4

Type RT_ICON
Language Turkish - Turkey
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.14463
MD5 022ff7b89e3b4bdc60fcadd3524ae92c
SHA1 6e4b94880d8d368463b8c63f31878a6708f2d2de
SHA256 59a8787a685c7766b503006c6200475f2503dc7ba85e71e4a55db60502154f5c
SHA3 536e93890a0820a25b9920ac59270cf903c652c6a57eccf15691e2ce0d7254f1

5

Type RT_ICON
Language Turkish - Turkey
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.14744
MD5 e92d18f8056f6eafe53948b519a914a9
SHA1 e36ef7186fcac48ea5fc401d1353a8256d61a810
SHA256 50c6d7906860bb178f220a82eb85f21afbd3a897590f54ad6c055ce6281dd613
SHA3 d6d9f980a11bf068f92466cd376016f939f8cd7a95997232f77d386e7bcb14f4

6

Type RT_ICON
Language Turkish - Turkey
Codepage UNKNOWN
Size 0x5488
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.08121
MD5 94054fae228fea0a3c4bdd784f1f81cc
SHA1 6d7f0409062caf3bebfbedbd20d6aa13412c62d4
SHA256 23f975647e1265c068aa6b5e84de83f5ddcf29efbf11c9af4c99f2d248726187
SHA3 f1969a4c300771f88adb1a0ffccb58d58db9ab38bc45dfa629e3b126298aca6b

7

Type RT_ICON
Language Turkish - Turkey
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.06214
MD5 f301f5705c90729931aa13648a391b27
SHA1 2a3767c27decca6623748616e01270628955967b
SHA256 d37ac0a2b9bd49996d58786cd71cbf03de3ee2982adc1a128230ce2e58e18ace
SHA3 7fd537399b1a1873999375d890ac2c4f6d96b6c72af701894581bb1a85aaa35c

8

Type RT_ICON
Language Turkish - Turkey
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.06948
MD5 ed0cddcfbcf3079d04d176e77eb76594
SHA1 5ac03b63e4821d39eca151a131a8981d6abfe7c4
SHA256 a2e2819e22c4c2306da98a3ae087f720b587ffb4f79c0a686d0270c199803559
SHA3 7451e35ffc455d2b71363c993e939a2ed73d358a7f4f47f7f7a20afd0e27bebc

9

Type RT_ICON
Language Turkish - Turkey
Codepage UNKNOWN
Size 0xbff0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9829
Detected Filetype PNG graphic file
MD5 6956c7dae0cb4273684e663e4ef00fa9
SHA1 d90e471e2e2f8f612b0a68997e6a744fb7a7a071
SHA256 e4fa7c44ed509e82df671ac73b512caf2375ecb7cb75781df81df56197474252
SHA3 1b6958c127e81dadff2298cab854486ab2070ea1a50750711b1d830b6de1110c

102

Type RT_GROUP_ICON
Language Turkish - Turkey
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.14903
Detected Filetype Icon file
MD5 8abcff3ed3bbd83bd6844283e82c11af
SHA1 0630d91241a4b48d0abe8cc4061d3153d31144df
SHA256 7f2b9ed327bdef6f9fedc8f6641ec8cb14e1a7f3ec60b6e2441513171fc54d0f
SHA3 18425b38839b495927366d8d812d8e298f27e55af06a09c9be4c21599b16498b

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353

Version Info

TLS Callbacks

StartAddressOfRawData 0x140a49000
EndAddressOfRawData 0x140a49168
AddressOfIndex 0x140a49168
AddressOfCallbacks 0x140a49170
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks (EMPTY)

Load Configuration

RICH Header

XOR Key 0x6e39301
Unmarked objects 0
C++ objects (33145) 225
ASM objects (33145) 33
Imports (VS2008 SP1 build 30729) 2
253 (35403) 1
ASM objects (35403) 12
C objects (35403) 20
C objects (33145) 49
C++ objects (35403) 113
Unmarked objects (#2) 42
C++ objects (35730) 1
C objects (35730) 1139
Imports (2207) 2
Imports (33145) 35
Total imports 423
C++ objects (LTCG) (35730) 73
Resource objects (35730) 1
151 1
Linker (35730) 1

Errors

[*] Warning: Section .themida has a size of 0!
Leave a comment

No comments yet.