951a3c2d7e253f6a9aebceec1f49799105585829f6289c112e95257587868f92

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 1970-Jan-01 00:00:00
Debug artifacts Embedded COFF debugging symbols

Plugin Output

Suspicious PEiD Signature: HQR data file
Suspicious The PE is possibly packed. Unusual section name found: .xdata
Unusual section name found: /4
Unusual section name found: /19
Unusual section name found: /32
Unusual section name found: /46
Unusual section name found: /65
Unusual section name found: /78
Unusual section name found: /95
Unusual section name found: /112
Unusual section name found: .symtab
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 458349e04aa653def1ad70fd20cf6da4
SHA1 029ed923b8e0e57cb52c203494894b9fda605e3d
SHA256 951a3c2d7e253f6a9aebceec1f49799105585829f6289c112e95257587868f92
SHA3 ddb96f335a633f691d08becd34eae2e0713c2ce50dff106c1cbd04b86119e9d3
SSDeep 49152:3NompEc3BpSsRGipA3tcHjiPxYSd7PFtxno5/:3NwqatjFFtRW/
Imports Hash 9b763104e1c7e7b7334a1e9ed4235cd3

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0x8b
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 17
TimeDateStamp 1970-Jan-01 00:00:00
PointerToSymbolTable 0x23be00
NumberOfSymbols 2720
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 3.0
SizeOfCode 0xa3c00
SizeOfInitializedData 0x32e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000007D400 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 1.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0x2d2000
SizeOfHeaders 0x600
Checksum 0x2803f6
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 0e86cfafddb99778fd2720c837b9b418
SHA1 5f89e8891496d5aba7bd4684c38617e83e929baf
SHA256 77502da55813d373e60a0e8da8e8f017b39a145f95d9a7c2124419ed9150f0cc
SHA3 f2005830ee097fca0f4f81252830d381570071d88c3f9501c1d50402a3ac9be2
VirtualSize 0xa3a91
VirtualAddress 0x1000
SizeOfRawData 0xa3c00
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.25458

.rdata

MD5 4427f3964e6b61a9037c769a2a6a5d35
SHA1 c7bf19b3ab81aafb5397442718785b650ea1bc45
SHA256 0a7288a81fc32f79c7ce10ea354f6e0917b7bd9264d20c5944990bf0b9b38002
SHA3 2d9294ffcbb8e1c1da703eeb299f3dae196d0b180b0aeb8305e3332e3b827163
VirtualSize 0xdd168
VirtualAddress 0xa5000
SizeOfRawData 0xdd200
PointerToRawData 0xa4200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.50684

.data

MD5 a406e785315e00fb42dfd0bb74908478
SHA1 a334fa3310f0824c3a38e69a42610a8955bef70f
SHA256 284a19c633a2181109df6c38d028b14c5a4770a2ef26c474421bfe1f615a3c49
SHA3 758f508840dd8a6c6dfebdb50dced794861637d7b19b94e4c92bc4d754d18abb
VirtualSize 0x57808
VirtualAddress 0x183000
SizeOfRawData 0xda00
PointerToRawData 0x181400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.11786

.pdata

MD5 d2e015e40449a78a24f23bc012a897c1
SHA1 9ead727b31754c15643caeb0e2817f14fc266e6c
SHA256 02812f7dec19a9f09f36f974b94036e91ec46b2198264cf4733a9ffe303e5656
SHA3 77c1e93d1d7c5013cab5de4e6901aad4b9fbaa1d05d7c8c5dde7985751fd2946
VirtualSize 0x4be4
VirtualAddress 0x1db000
SizeOfRawData 0x4c00
PointerToRawData 0x18ee00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.86386

.xdata

MD5 3f337d2572ea9beb7f47f58dac5feb0c
SHA1 554783d4c50f15949706e35060f5e415dc80be33
SHA256 8ca8cff0fffbd5c0489b5339f4352dab98f5fdbebc23bfe2e4c26f59f0b19000
SHA3 39ab8950e8a7a3ca1eeafb1b8ca1ddd716902f2596e5308ff4e7b253de32ffcb
VirtualSize 0xa8
VirtualAddress 0x1e0000
SizeOfRawData 0x200
PointerToRawData 0x193a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.67294

/4

MD5 bcddef00414a946919302442928e542e
SHA1 b0fbeae40093e8241edcbdeae94ba06880dedf04
SHA256 fb7bf682d27ba8920146a9b134a183cd2109b202916488b9b3a4f7d623f0b484
SHA3 7d5b252590738bde977b6dfab9c3034c2ad82b952980a3585c1dc88e1f06f005
VirtualSize 0x154
VirtualAddress 0x1e1000
SizeOfRawData 0x200
PointerToRawData 0x193c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.67257

/19

MD5 b3ed8a74ab2cb212ceab3711d6359634
SHA1 13f157253048724f339570eab20ae3fe8fb01e65
SHA256 677dfe4a5b04f99d5a361c859f3535d1500126363b332ba6a8ee39b41518aa49
SHA3 37f36a540d5f5df4933f9c29dc8fe1cea87dd683effb5ec417d09dfff51641bb
VirtualSize 0x277e6
VirtualAddress 0x1e2000
SizeOfRawData 0x27800
PointerToRawData 0x193e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.99454

/32

MD5 a55ccbd699d62d199b619610bbc59a16
SHA1 650dd12bb47437db8e75f70501252562e47ec073
SHA256 de6cdc154e88f5c141a2e0415216e440886ca72a2f3312a71596e79fdd581fac
SHA3 21ecaedec7369b6340b5dad5655e00176c3bd524588f2ac654a781d79f14ec66
VirtualSize 0x7806
VirtualAddress 0x20a000
SizeOfRawData 0x7a00
PointerToRawData 0x1bb600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.91273

/46

MD5 40cca7c46fc713b4f088e5d440ca7931
SHA1 3aaa1650bfaf5325fa9cb3a1a284aebcc92aebf4
SHA256 3e3c5f5d419b70e588da0ef0e3d9ce1a5863a5624febc16cd0c007cd14e89015
SHA3 a0e18fe9f6ac46417d52cdc99cf9ae56edb5a53f788995a085b10f88f348a0e4
VirtualSize 0x30
VirtualAddress 0x212000
SizeOfRawData 0x200
PointerToRawData 0x1c3000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.855685

/65

MD5 04e1f09ebba4e388e33d6c1a66a78738
SHA1 6ef74c59ce1a7b0cd56dec7e0e84c1a562fac63c
SHA256 2258d3fffebbf00bcd63675f3c798d9f6ee171949baf685f7ff486787e06c857
SHA3 c803f70ed3a40074ec9a4a3d1162e99a4fd464547b25ed89b9ef2a3509d1c6be
VirtualSize 0x47289
VirtualAddress 0x213000
SizeOfRawData 0x47400
PointerToRawData 0x1c3200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.99776

/78

MD5 41e9e8d9ab04f3115eace377edfdf03f
SHA1 48e4b68bee5e92f782413f9f4e509213fd11dd52
SHA256 2bf02c544c06731d0d2e391e5d0f6693b7b79455b6b790779b39a880d6e99c7f
SHA3 38ad2fe3c4de3f61b7bbe85efc17e60758f010ae3c211feb520ffc8619be063b
VirtualSize 0x1b654
VirtualAddress 0x25b000
SizeOfRawData 0x1b800
PointerToRawData 0x20a600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.99271

/95

MD5 65e8b98bdcb87389afb505d2042bb45e
SHA1 2cdf1d0f3f57ca974cdbcb64dd704c5bad8b496a
SHA256 8000d91e4255c113c1a096e12ce9d872309f32bfb472b55bbda41be33be2710f
SHA3 cf176b9c96caf2dbc8df72632aa54bc40f9e8f146baef848a14fb821e1608bf3
VirtualSize 0x10a4b
VirtualAddress 0x277000
SizeOfRawData 0x10c00
PointerToRawData 0x225e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.98739

/112

MD5 d7d5213b5529e83532ae41ee79293a92
SHA1 1dd341fe1d87c67be4c0177cd788ecb2452a7e81
SHA256 b7c9cd27d872b5b0a9c80df26af08c9562f61c792f3116ec0b71ff5f8a49546c
SHA3 7f9375c5dc40af1f5c707b7892e239ee934486e5bae3e4098f26714649fdc21e
VirtualSize 0xfd4
VirtualAddress 0x288000
SizeOfRawData 0x1000
PointerToRawData 0x236a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.75758

.idata

MD5 268f35c1043814c7ad9415ea38951381
SHA1 155cc55d3a0fa62f7905ae5151894a4327af41a8
SHA256 8e0b8943d01ca31eb196bbf69bfba360210897c2b05898428811e4b701ef938f
SHA3 f4fbf4203559cab297df2f89149396e0be435f073aa009dbc637103dc5fdfff2
VirtualSize 0x55a
VirtualAddress 0x289000
SizeOfRawData 0x600
PointerToRawData 0x237a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.07137

.reloc

MD5 91584437a4b2529a421c380dd74eeba3
SHA1 214e3ff733fbabe7e68b6af92a17fc43b01274f6
SHA256 3921a113f69154ceac9ddd68f7d2cd13d05999e80ebe9a7e873d0e809594af58
SHA3 6e02827e9d88152b53d22ea86f99576032280eb302ad1c2280167df0d6280dd3
VirtualSize 0x3d34
VirtualAddress 0x28a000
SizeOfRawData 0x3e00
PointerToRawData 0x238000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.41999

.symtab

MD5 10808d0b25bd1b0a9ffa464b4fcc75a1
SHA1 97b6b65319b6b78720bc70878aa189741c44721b
SHA256 727c0e32ef56449bc073d4a95d5c677a62f6098a513b10af7078461c102b8985
SHA3 4435219ca576f94cbeabd3779942ca3215ba2f8c911f52c8e60d4c85d38b772a
VirtualSize 0x1d120
VirtualAddress 0x28e000
SizeOfRawData 0x1d200
PointerToRawData 0x23be00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.11991

.rsrc

MD5 b3dc7cdf0d5306ffdb904c570ffa3ce5
SHA1 f52fe67fad219ee682f856d363d3fd8fa35d36aa
SHA256 272be4ca6c14b88917be6fcf697f0f923e6af1ba9854143938759c47eaae1b44
SHA3 e3e000cb5711c4a1a4cf025e7d246af51f3edda75818ce0e753a71a06fee8bc5
VirtualSize 0x252f0
VirtualAddress 0x2ac000
SizeOfRawData 0x25400
PointerToRawData 0x259000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.922423

Imports

kernel32.dll GetProcAddress
LoadLibraryExW
WriteFile
WriteConsoleW
WerSetFlags
WerGetFlags
WaitForMultipleObjects
WaitForSingleObject
VirtualQuery
VirtualFree
VirtualAlloc
TlsAlloc
SwitchToThread
SuspendThread
SetWaitableTimer
SetProcessPriorityBoost
SetEvent
SetErrorMode
SetConsoleCtrlHandler
RtlVirtualUnwind
RtlLookupFunctionEntry
ResumeThread
RaiseFailFastException
PostQueuedCompletionStatus
LoadLibraryExW
SetThreadContext
GetThreadContext
GetSystemInfo
GetSystemDirectoryA
GetStdHandle
GetQueuedCompletionStatusEx
GetProcessAffinityMask
GetProcAddress
GetErrorMode
GetEnvironmentStringsW
GetCurrentThreadId
GetConsoleMode
FreeEnvironmentStringsW
ExitProcess
DuplicateHandle
CreateWaitableTimerExW
CreateThread
CreateIoCompletionPort
CreateEventA
CloseHandle
AddVectoredExceptionHandler
AddVectoredContinueHandler

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.906942
MD5 6319324b04dd4d6f3e1b30e074954772
SHA1 f088249df914b447e54df149e6573b98739b06f0
SHA256 12e36b85d60f30dbf45434dbaf31de0a871e1971979558bd5b140913ae288db1
SHA3 d3edefbdbb9918ebb7b98ecd0d303946e7c22c71c01bd759944dfcc53bb18da8

UNTITLED

Type RT_GROUP_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Icon file
MD5 b6fbd51577e509ca1c2aab34610269bb
SHA1 23dbace902b2ceaa431f915630ac0b3cfcabc4f7
SHA256 5f24b65d17b02f76445995cca7fbd40709fbd303f935b01b4f997bba93edb6aa
SHA3 df2cabec2cffe1c5d93d1618947490d2a1fd608f05f7d8b9f2b6a6664359b895

Version Info

TLS Callbacks

Load Configuration

RICH Header

Errors

[*] Warning: Tried to read outside the COFF string table to get the name of section /4! [*] Warning: Tried to read outside the COFF string table to get the name of section /19! [*] Warning: Tried to read outside the COFF string table to get the name of section /32! [*] Warning: Tried to read outside the COFF string table to get the name of section /46! [*] Warning: Tried to read outside the COFF string table to get the name of section /65! [*] Warning: Tried to read outside the COFF string table to get the name of section /78! [*] Warning: Tried to read outside the COFF string table to get the name of section /95! [*] Warning: Tried to read outside the COFF string table to get the name of section /112!
Leave a comment

No comments yet.