| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Oct-02 16:49:37 |
| Detected languages |
English - United States
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA256 Uses known Mersenne Twister constants |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 13/66 (Scanned on 2026-10-09 01:15:26) |
APEX:
Malicious
Bkav: W32.Malware.FCAE41CD CrowdStrike: win/malicious_confidence_70% (D) Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS ESET-NOD32: Win64/GenKryptik.HRKX trojan Elastic: malicious (high confidence) Google: Detected Ikarus: Trojan.Win64.Krypt McAfeeD: ti!9149EB20B820 Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Suspicious PE Symantec: ML.Attribute.HighConfidence |
| MD5 | 6132ea5d4f86d82def2a631587eb525f 🔍 |
|---|---|
| SHA1 | 883f254d654d39eabb6173cd7e4c6a3f33c1ab14 🔍 |
| SHA256 | 9149eb20b820f6426f7636447a303116962c93eaabc0d2a01762a7f4d13217cc 🔍 |
| SHA3 | 314f00ebb868e278e1f596e008dfabde67af2c9753a391970cfddaa1fddd01ae 🔍 |
| SSDeep | 49152:Pp8efx67U77xe0s/t4y3VkT8+HE3uxuMvAKrTZrNyA+2dzsmw3uu7ZXNGqhT8p5:BKU77xAjVMxdAGTZ33El03 🔍 |
| Imports Hash | 1babdafcff3cbaf1e28003fe3073504d 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Oct-02 16:49:37 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x108800 |
| SizeOfInitializedData | 0x2f4c00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000C5EC8 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x403000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 8054ca192b49c33642808b5438a9a6e6 🔍 |
|---|---|
| SHA1 | 8f48039717c9d87259c59774e3d0c369a6177144 🔍 |
| SHA256 | 5625d54040db14a509100f4a46df6938a93ce0d8bde22f09028b811c067cb95d 🔍 |
| SHA3 | 0312ff04c7e5200ab0f154a7c3e010645a44397e228f70f64c9662fa450f3916 🔍 |
| VirtualSize | 0x1087b8 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x108800 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.53169 |
| MD5 | 34075e7c218304e6316cd626baa5bce1 🔍 |
|---|---|
| SHA1 | 7566322ae0dcb6fa58f4ff0d5bcb23c9b280e8ac 🔍 |
| SHA256 | 4784f23076e2baeab63ea780d1596f1cb2643a39e46fc38846a1a556edbc53a4 🔍 |
| SHA3 | 71207518bee1303a806e2bc7c301e87d65cc8194a2102c25622f645355862e74 🔍 |
| VirtualSize | 0x2e4358 |
| VirtualAddress | 0x10a000 |
| SizeOfRawData | 0x2e4400 |
| PointerToRawData | 0x108c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 7.18559 |
| MD5 | 995c5cc2efcc8e89aceec58a1167d402 🔍 |
|---|---|
| SHA1 | f086e1b8bc22ce1b4594d4d6c6b89d390ebe8152 🔍 |
| SHA256 | c26950d817fbe7c81e4508b6c381b2f2d4b2f4d89e2b62ee2ee612ab42a48f7d 🔍 |
| SHA3 | 3d28bf9b7f5de58f0103691b2e50e94b6ef7297e82cd5e9389e0621fe3d4c56a 🔍 |
| VirtualSize | 0x4d24 |
| VirtualAddress | 0x3ef000 |
| SizeOfRawData | 0x2e00 |
| PointerToRawData | 0x3ed000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.46766 |
| MD5 | 369e6948641c184cdc44a745ff037236 🔍 |
|---|---|
| SHA1 | f32c942318cd214340aa26aaa33466c3fa7e6cf9 🔍 |
| SHA256 | 7dfa81bbe5d3b5498e28031d47ff458a41c5ad66abbcaa5ad923e8015284e4da 🔍 |
| SHA3 | 795e652c4d4a664c0eb1909fa8849b18141bb86de884c292b504e4963cfd87aa 🔍 |
| VirtualSize | 0xa29c |
| VirtualAddress | 0x3f4000 |
| SizeOfRawData | 0xa400 |
| PointerToRawData | 0x3efe00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.08475 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x100 |
| VirtualAddress | 0x3ff000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x3fa200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 6dd94cea5f7bc6e5906103e87f09fab7 🔍 |
|---|---|
| SHA1 | 8a3494f44695d06f6b450eb5e67918b6c0af0b35 🔍 |
| SHA256 | 54e332f4c151db488091c7afd5ae2cef770eeb1e2c349c0a7343234c07352701 🔍 |
| SHA3 | 7fd305a28670a3f9cf35e03aa320205f8353e360f70d11a39a3e4237c01ff036 🔍 |
| VirtualSize | 0x1e8 |
| VirtualAddress | 0x400000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x3fa400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.75615 |
| MD5 | bd6a17c3e3485b190fd2c9882f3485fc 🔍 |
|---|---|
| SHA1 | 07e7b252d2decf3a21fc0d37ff55756849386e25 🔍 |
| SHA256 | 6259c32f1803fcdfa91e0345595c4806e1bb860393d69255db69fca97c2ceffe 🔍 |
| SHA3 | c056ca8ad70649de6ce9846e7d88af7f4347c4c865dcea9d27644bf30c3953d0 🔍 |
| VirtualSize | 0x1018 |
| VirtualAddress | 0x401000 |
| SizeOfRawData | 0x1200 |
| PointerToRawData | 0x3fa600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.22065 |
| WINHTTP.dll |
WinHttpWebSocketSend
WinHttpWebSocketReceive WinHttpWebSocketClose WinHttpQueryDataAvailable WinHttpReceiveResponse WinHttpCrackUrl WinHttpQueryHeaders WinHttpReadData WinHttpOpenRequest WinHttpCloseHandle WinHttpSendRequest WinHttpSetTimeouts WinHttpConnect WinHttpOpen |
|---|---|
| ntdll.dll |
RtlVirtualUnwind
RtlLookupFunctionEntry RtlCaptureContext RtlUnwindEx RtlPcToFileHeader RtlUnwind |
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
| D3DCOMPILER_43.dll |
D3DCompile
|
| WINMM.dll |
timeEndPeriod
timeBeginPeriod |
| KERNEL32.dll |
ReadFile
FindFirstFileW GetFileSizeEx WriteProcessMemory VirtualProtect VirtualFree FindNextFileW GetCurrentProcess WriteFile DeviceIoControl VirtualAlloc RemoveDirectoryW GetModuleFileNameW SetFilePointer GetTempPathW FindClose WaitForSingleObject CreateFileW GetFileAttributesW UnmapViewOfFile GetModuleHandleA OpenProcess SetFileAttributesW CreateToolhelp32Snapshot MultiByteToWideChar Sleep Process32NextW GetCurrentThread QueryPerformanceFrequency DeleteFileW Process32FirstW CloseHandle GetSystemInfo GetLocalTime GetThreadContext GetProcAddress GetFileSize ExitProcess ReadProcessMemory GetCurrentProcessId CreateProcessW GetModuleHandleW CreateProcessA CreateFileMappingW MapViewOfFile QueryPerformanceCounter IsDebuggerPresent VirtualQueryEx CheckRemoteDebuggerPresent Process32First SetThreadPriority Process32Next K32QueryWorkingSetEx Module32FirstW Module32NextW IsWow64Process GlobalAlloc GlobalFree GlobalLock GlobalUnlock GetLocaleInfoA LoadLibraryA FreeLibrary WideCharToMultiByte GetTickCount64 CreateThread MoveFileExW GetTickCount MoveFileW GetExitCodeProcess WriteConsoleW GetFileType GetStdHandle GetModuleHandleExW FreeLibraryAndExitThread ExitThread LoadLibraryExW TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount SetLastError RaiseException TerminateProcess InitializeSListHead IsProcessorFeaturePresent GetStartupInfoW SetUnhandledExceptionFilter UnhandledExceptionFilter GetCPInfo CompareStringEx GetStringTypeW GetSystemTimeAsFileTime WakeAllConditionVariable LCMapStringEx DecodePointer EncodePointer GetUserDefaultLCID DeleteCriticalSection InitializeCriticalSectionEx LeaveCriticalSection EnterCriticalSection SleepConditionVariableSRW GetComputerNameW GetLastError GetVolumeInformationW HeapReAlloc IsValidCodePage GetACP GetOEMCP GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW GetProcessHeap SetStdHandle HeapSize SetEndOfFile HeapAlloc GetTimeZoneInformation HeapFree FlsAlloc FlsGetValue FlsSetValue FlsFree GetDateFormatW GetTimeFormatW GetNativeSystemInfo GetExitCodeThread OutputDebugStringW ReadConsoleW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale OutputDebugStringA GetConsoleMode GetConsoleOutputCP FlushFileBuffers SetFilePointerEx EnumSystemLocalesW InitOnceComplete InitOnceBeginInitialize FormatMessageA GetLocaleInfoEx LocalFree FindFirstFileExW GetFileAttributesExW SetFileInformationByHandle AreFileApisANSI GetFileInformationByHandleEx ReleaseSRWLockExclusive AcquireSRWLockExclusive TryAcquireSRWLockExclusive GetCurrentThreadId WaitForSingleObjectEx |
| USER32.dll |
CharLowerW
DefWindowProcW DispatchMessageA GetWindowRect DestroyWindow SetWindowPos GetSystemMetrics UnregisterClassW RegisterClassExW ShowWindow GetAsyncKeyState SetWindowLongA GetWindowLongA SetWindowDisplayAffinity MoveWindow SetLayeredWindowAttributes TranslateMessage PeekMessageA PostQuitMessage UpdateWindow SendInput GetKeyState GetMessageExtraInfo LoadCursorA ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow SetCapture SetCursor GetClientRect IsWindowUnicode ReleaseCapture SetCursorPos GetCursorPos OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData GetWindowThreadProcessId FindWindowExA GetWindowTextA CreateWindowExW |
| ADVAPI32.dll |
OpenProcessToken
OpenServiceA RegEnumValueW RegQueryValueExW RegOpenKeyExW QueryServiceStatusEx AdjustTokenPrivileges QueryServiceStatus CloseServiceHandle ClearEventLogW OpenSCManagerW LookupPrivilegeValueA OpenSCManagerA CloseEventLog ControlService RegEnumKeyExW RegDeleteTreeW OpenServiceW StartServiceW OpenEventLogW RegDeleteValueW RegCloseKey |
| SHELL32.dll |
SHGetKnownFolderPath
SHGetFolderPathW ShellExecuteExW |
| ole32.dll |
CoTaskMemFree
|
| IMM32.dll |
ImmReleaseContext
ImmGetContext ImmSetCompositionWindow ImmSetCandidateWindow |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x188 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.89623 |
| MD5 | b8e76ddb52d0eb41e972599ff3ca431b 🔍 |
| SHA1 | fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍 |
| SHA256 | 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍 |
| SHA3 | 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Oct-02 16:49:37 |
| Version | 0.0 |
| SizeofData | 1052 |
| AddressOfRawData | 0x3dbb34 |
| PointerToRawData | 0x3da734 |
| StartAddressOfRawData | 0x1403dbf98 |
|---|---|
| EndAddressOfRawData | 0x1403dc008 |
| AddressOfIndex | 0x1403f2520 |
| AddressOfCallbacks | 0x14010a9b8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1403ef100 |
| XOR Key | 0x2ab6cdb5 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 191 |
| C objects (33145) | 31 |
| ASM objects (33145) | 23 |
| C objects (35207) | 19 |
| ASM objects (35207) | 12 |
| C++ objects (35207) | 95 |
| C objects (CVTCIL) (33145) | 1 |
| Imports (21202) | 4 |
| Imports (33145) | 23 |
| Total imports | 308 |
| C++ objects (LTCG) (35228) | 17 |
| Resource objects (35228) | 1 |
| Linker (35228) | 1 |
No comments yet.