915c7ffe45ce6056d0a97b2302775ac5c08b0e473490e8670deb25e35852133c

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-13 15:27:00
Detected languages English - United States
CompanyName Sensible Software Solutions
FileDescription System Resource Loader
FileVersion 1.0.0.0
InternalName sysrsldr
LegalCopyright Copyright © 2025 Sensible Software Solutions. All rights reserved.
OriginalFilename sysrsldr.exe
ProductName System Resource Loader
ProductVersion 1.0.0.0

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Cryptographic algorithms detected in the binary: Uses constants related to RC5 or RC6
Suspicious The PE contains functions most legitimate programs don't use. Leverages the raw socket API to access the Internet:
  • inet_addr
Malicious VirusTotal score: 15/65 (Scanned on 2026-07-22 00:10:25) ALYac: Trojan.GenericKD.80836534
APEX: Malicious
Arcabit: Trojan.Generic.D4D177B6
BitDefender: Trojan.GenericKD.80836534
CTX: exe.trojan.generic
CrowdStrike: win/malicious_confidence_70% (W)
Emsisoft: Trojan.GenericKD.80836534 (B)
GData: Trojan.GenericKD.80836534
Lionic: Trojan.UKP.Generic.4!c
MicroWorld-eScan: Trojan.GenericKD.80836534
Microsoft: Trojan:Win32/Sabsik.EN.A!ml
Panda: Trj/PhxIK.A
TrellixENS: Artemis!234606545B38
TrendMicro-HouseCall: TROJ_GEN.R002H09GI26
VIPRE: Trojan.GenericKD.80836534

Hashes

MD5 234606545b3891d29f2db0d4e51453d8
SHA1 b4204bc28ee23c88abb71cf02c90699daa2ddf6a
SHA256 915c7ffe45ce6056d0a97b2302775ac5c08b0e473490e8670deb25e35852133c
SHA3 eb5349af1fbbf4f8cd8f464ee396cd772ab062f4c1755414bf95d3f0d0f5f8f8
SSDeep 3072:+zd35JtzPJnRQSLAYHSNrWQ5EySc00b88:45v
Imports Hash c4badf11c29f0c30d8ce21deb255bf14

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jul-13 15:27:00
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x14e00
SizeOfInitializedData 0x5200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000014E40 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1e000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 60f4aa042c966159009b5f14d6d2d6a9
SHA1 e12c4fb617fdc9de0d3719b0ee55131153caaceb
SHA256 6ef16ae1047489eebaa8572db7892086130ddfb323733bf02352ce8c7f880ed8
SHA3 1b94a1f072cb0746d14cb30429a3a2bf8b04d7e4acfa9bf5774513e0222b94ac
VirtualSize 0x14d52
VirtualAddress 0x1000
SizeOfRawData 0x14e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.33355

.rdata

MD5 db080c0fd00c26a6ec94ebc8aca9d856
SHA1 80ecb1bffbada9edfb196e368c73193f8c00db0a
SHA256 cd38c06e80063b19edbfe9b821b1fb7912ad5aa7f8caf7103314d054f21be989
SHA3 85ba4cef9bd2baab5da13c1a5924be8d70d28369248abd6e95642c049024ef22
VirtualSize 0x3440
VirtualAddress 0x16000
SizeOfRawData 0x3600
PointerToRawData 0x15200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.80546

.data

MD5 139a23d1f48cbfe3c1114b66f9280462
SHA1 c9325f02f7a4843d0fbe07f6548984540a1bb57d
SHA256 7b689d9059c302510edf45f7915ea36d754780446b59440c57841dc55c61dc39
SHA3 1f03be639ff3716f6a7c7ce2490adb6943b7aee968e1dbc34e6557ac1db96236
VirtualSize 0x7c0
VirtualAddress 0x1a000
SizeOfRawData 0x200
PointerToRawData 0x18800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.10506

.pdata

MD5 6ad4707f46b5a7d6b4c6fd9dafc66c06
SHA1 8f082974ed6bb402eb4e63731ab830e019ea71cf
SHA256 4f0559ffa1638f355729e5be2b11b8b1df04e74ec27140e23123fac4d02809b7
SHA3 6b3cc504ebafcfabe11fc02663bf25505cb12aaed5366dcacb2a8fbda34944c2
VirtualSize 0xa08
VirtualAddress 0x1b000
SizeOfRawData 0xc00
PointerToRawData 0x18a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.41753

.rsrc

MD5 546e62a33e5b946d636433c3fa797a62
SHA1 9685ca0dbb979d72ddcfabf5d5a452287e670f85
SHA256 7c1438aae9f62b1587416888606dab99e7be521d172d3df101e12f4f6b9b6632
SHA3 205eee41507029992149c2eabadf5958165f5796a66a9f74d31f79cc803d58bb
VirtualSize 0x590
VirtualAddress 0x1c000
SizeOfRawData 0x600
PointerToRawData 0x19600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.8746

.reloc

MD5 ec56c1e813e1683db2b5d3ca5470de2d
SHA1 16fa263ad6384d5d56462305917f776e0ffe38e5
SHA256 b8ae3d61dc4ef75fb64794ca1ad795477682e89d60d101db3859a40859b36160
SHA3 72a49163f68cb0f8438bd1135896bd1402061f589fec412f3db310e3c29bfe92
VirtualSize 0x78
VirtualAddress 0x1d000
SizeOfRawData 0x200
PointerToRawData 0x19c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.59686

Imports

MSVCP140.dll ?_Xlength_error@std@@YAXPEBD@Z
?_Xinvalid_argument@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z
WS2_32.dll inet_addr
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll _CxxThrowException
__C_specific_handler
__std_exception_destroy
__current_exception
__std_terminate
memchr
memcmp
memcpy
__current_exception_context
__std_exception_copy
memset
memmove
api-ms-win-crt-runtime-l1-1-0.dll _crt_atexit
_cexit
terminate
_c_exit
_register_onexit_function
exit
_initterm_e
_initterm
_get_wide_winmain_command_line
_initialize_wide_environment
_configure_wide_argv
_set_app_type
_seh_filter_exe
_initialize_onexit_table
_errno
_invalid_parameter_noinfo_noreturn
_register_thread_local_exe_atexit_callback
_exit
api-ms-win-crt-convert-l1-1-0.dll strtoull
api-ms-win-crt-heap-l1-1-0.dll free
_callnewh
malloc
_set_new_mode
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
api-ms-win-crt-stdio-l1-1-0.dll _set_fmode
__p__commode
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
KERNEL32.dll RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW

Delayed Imports

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x364
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33357
MD5 9d8c5e4dfe30230f2232dd8ba49ee1b0
SHA1 d2446f6cb7e08d46a2e4542af6cf81f801e96534
SHA256 0800804a3575f6b175e354be27892c6845ba9d2c36fed5471b192a73845b30c2
SHA3 9cfcc859037f5cab860df0f4ac5bf4e53df56095f11fc1cf8bd05d80872e1b0c

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Sensible Software Solutions
FileDescription System Resource Loader
FileVersion (#2) 1.0.0.0
InternalName sysrsldr
LegalCopyright Copyright © 2025 Sensible Software Solutions. All rights reserved.
OriginalFilename sysrsldr.exe
ProductName System Resource Loader
ProductVersion (#2) 1.0.0.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-13 15:27:00
Version 0.0
SizeofData 720
AddressOfRawData 0x177dc
PointerToRawData 0x169dc

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jul-13 15:27:00
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14001a000

RICH Header

XOR Key 0xe65bcf0e
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 12
ASM objects (33808) 4
C objects (33808) 10
C++ objects (33808) 25
Imports (33808) 7
Imports (33138) 4
Total imports 66
C++ objects (LTCG) (34120) 11
ASM objects (34120) 1
Resource objects (34120) 1
151 1
Linker (34120) 1

Errors

Leave a comment

No comments yet.