8c5563f28d7e630c746f7ece68e8c7b9c8abf952f195bd8d69f8e96c3cf21fdf

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2021-Aug-14 18:32:30
Detected languages English - United States

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0
Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Contains domain names:
  • 04.jp.org
  • www.04.jp
  • www.04.jp.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Malicious VirusTotal score: 31/70 (Scanned on 2026-07-12 23:03:23) AVG: Win32:MalwareX-gen [Trj]
AhnLab-V3: Trojan/Win.Generic.R683476
Alibaba: HackTool:Win32/Generic.b7179c09
Antiy-AVL: Trojan/Win32.Agent
Avast: Win32:MalwareX-gen [Trj]
Avira: TR/W32.MalwareX
Bkav: W32.Malware.53D8178A
CTX: dll.trojan.generic
CrowdStrike: win/grayware_confidence_100% (W)
Cylance: Unsafe
Cynet: Malicious (score: 100)
DrWeb: Trojan.Siggen16.19619
Elastic: malicious (high confidence)
F-Secure: Trojan.TR/W32.MalwareX
Google: Detected
Lionic: Trojan.Win32.Generic.4!c
MaxSecure: Trojan.Malware.318522439.susgen
McAfeeD: ti!8C5563F28D7E
Microsoft: HackTool:Win32/Keygen
Paloalto: generic.ml
Rising: Hacktool.Keygen!8.B29 (CLOUD)
Sangfor: Suspicious.Win32.Save.a
Skyhigh: GenericRXQP-OG!E3C18DD5C84D
Sophos: Generic Reputation PUA (PUA)
Symantec: Trojan.Gen.MBT
TrellixENS: GenericRXQP-OG!E3C18DD5C84D
TrendMicro: PUA.Win32.GameHack.AVGO
TrendMicro-HouseCall: PUA.Win32.GameHack.AVGO
VBA32: Trojan.Wacatac
Varist: W32/ABApplication.KETR-2979
Xcitium: Malware@#9sod1q8n2loq

Hashes

MD5 e3c18dd5c84dc9b9ca5bf0aa10d26f95 🔍
SHA1 2f17493f23e9aee959f90c66db2e71c08328bfde 🔍
SHA256 8c5563f28d7e630c746f7ece68e8c7b9c8abf952f195bd8d69f8e96c3cf21fdf 🔍
SHA3 61c3b16415f603c65deab8b233addcf225cde083871372dd6672aeabc6a7b30b 🔍
SSDeep 49152:rfNunO7TbwVQc6A5RY7kw2R5TU2yqDCfFhdjN22Lj:TNunO7TbwVz6UY7kwApyqDCfjdT 🔍
Imports Hash 250a6454a31b8bb10418492cb9057108 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2021-Aug-14 18:32:30
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0xf600
SizeOfInitializedData 0x18f000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00002AFC (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x11000
ImageBase 0x10000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1a2000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 b5a521e3c48c3a3bfeefdf7157e766c2 🔍
SHA1 900053f24faccd6ccd94c338e53242e1496db454 🔍
SHA256 43fc0eee4868824d06ea6b3c5ff7e8c591bdf94e0336da1e71efa001a7a3fc45 🔍
SHA3 7cc430cf0cfa3471820801e4f01cf79b4ec6266b908844dc8dc6f3c1afa90b0c 🔍
VirtualSize 0xf5f5
VirtualAddress 0x1000
SizeOfRawData 0xf600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.36642

.rdata

MD5 30f5a6bd0aac7553af8be6be3ba15b14 🔍
SHA1 2a0305a4f078f2da59f00ce3f4ed85998dd4f9d0 🔍
SHA256 bfcba7ccbb388520ba5c31e20c7be46b2da016d802542fdd23e76e0d70943e12 🔍
SHA3 312b32b3750745bb3dc2bfe345b2126e9e25719e8d07236bb4d7b44cdc3bfb42 🔍
VirtualSize 0x18dff4
VirtualAddress 0x11000
SizeOfRawData 0x18e000
PointerToRawData 0xfa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.67252

.data

MD5 aa8d1299fcf0c4348e2e732668317043 🔍
SHA1 bdd2490af1d6e4a5759bd16259207d39781b17e5 🔍
SHA256 1281eb363ca7b1cd8259c7d9a6176cee534ab56438e6cdf83e2e4f1aaf42d4c3 🔍
SHA3 fa685abe18633e94a6ab837ae5d7a58f47a2115906a4643b78532e8730c028a1 🔍
VirtualSize 0x874
VirtualAddress 0x19f000
SizeOfRawData 0x200
PointerToRawData 0x19da00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.8985

.rsrc

MD5 2e1d696970bb326f1ea03ec316eb55a5 🔍
SHA1 ce81e169823a364638d8ae7532775b136273efb3 🔍
SHA256 ee4dff81aa052a46e48d30185f1bc90be7aa2c7acd9fea15f2b4dd8cb56ccdae 🔍
SHA3 9af95e9c62c47b00ccd404518bd29464bbc9395e25b0eef5ffa4d9fe1efe8adb 🔍
VirtualSize 0x1e0
VirtualAddress 0x1a0000
SizeOfRawData 0x200
PointerToRawData 0x19dc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.70855

.reloc

MD5 6d16216f7a955cc5636774b0937e193e 🔍
SHA1 a48fd3813a25cc634849c63a7e2f6a4d087d48b9 🔍
SHA256 2010a26d00efe6793007df2619408a90820865b460d867a72d96bf6685a413f5 🔍
SHA3 209f2fc70dece4690437469c717b5dcf64988d09a26426ce5a76bd0d028c7366 🔍
VirtualSize 0x3c4
VirtualAddress 0x1a1000
SizeOfRawData 0x400
PointerToRawData 0x19de00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.18367

Imports

KERNEL32.dll DisableThreadLibraryCalls
LoadLibraryA
CloseHandle
CreateThread
GetProcAddress
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
SetEvent
ResetEvent
WaitForSingleObjectEx
CreateEventW
GetModuleHandleW
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
GetCurrentProcess
EnterCriticalSection
TerminateProcess
MSVCP140.dll ?_Xout_of_range@std@@YAXPBD@Z
?_Xlength_error@std@@YAXPBD@Z
VCRUNTIME140.dll memmove
__std_exception_copy
strstr
memset
_CxxThrowException
_except_handler4_common
memcpy
__std_exception_destroy
__CxxFrameHandler3
__std_type_info_destroy_list
api-ms-win-crt-heap-l1-1-0.dll free
_callnewh
malloc
api-ms-win-crt-string-l1-1-0.dll isdigit
tolower
api-ms-win-crt-runtime-l1-1-0.dll _initterm
_execute_onexit_table
_register_onexit_function
_initialize_onexit_table
_configure_narrow_argv
_seh_filter_dll
_initterm_e
_cexit
_crt_atexit
_initialize_narrow_environment
_invalid_parameter_noinfo_noreturn
api-ms-win-crt-convert-l1-1-0.dll strtoul
atoi

Delayed Imports

2

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2021-Aug-14 18:32:30
Version 0.0
SizeofData 780
AddressOfRawData 0x19e4b8
PointerToRawData 0x19ceb8

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2021-Aug-14 18:32:30
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1019e7d4
EndAddressOfRawData 0x1019e7dc
AddressOfIndex 0x1019f0f4
AddressOfCallbacks 0x10011118
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0xa4
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1019f014
SEHandlerTable 0x1019e4b0
SEHandlerCount 2

RICH Header

XOR Key 0x26fe30b6
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 8
C++ objects (VS2019 Update 2 (16.2) compiler 27905) 18
C objects (VS2019 Update 2 (16.2) compiler 27905) 10
ASM objects (VS2019 Update 2 (16.2) compiler 27905) 3
Imports (VS2019 Update 2 (16.2) compiler 27905) 4
Imports (VS2017 v14.15 compiler 26715) 3
Total imports 68
C++ objects (LTCG) (VS2019 Update 3 (16.3) compiler 28107) 5
Resource objects (VS2019 Update 3 (16.3) compiler 28107) 1
Linker (VS2019 Update 3 (16.3) compiler 28107) 1

Errors

Leave a comment

No comments yet.