9fc5c56438c659fb4563b12ae8186608

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2023-Jun-08 01:09:43
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.

Plugin Output

Suspicious The PE is possibly packed. Unusual section name found: .buildid
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryW
Suspicious The PE is possibly a dropper. Resources amount for 84.8058% of the executable.
Safe VirusTotal score: 0/72 (Scanned on 2026-02-15 22:14:34) All the AVs think this file is safe.

Hashes

MD5 9fc5c56438c659fb4563b12ae8186608
SHA1 51c1d56b47e30c95d9151378a7bbb2b93e74708b
SHA256 19390c0eedcd974e57a13cc03f78454f6de4e2f36d85f412249d1c04841dd0ec
SHA3 cac3f2538481e7b77c727660ef10497d541627e94dd67eae934ab4c44d1d7f8c
SSDeep 3072:V3Yj+8JlFCumUbyJlKP8HRvkduTK5Nrh2o9Dj0fmoQ:xQ+IFCumUGekHRvEuO3go9kfnQ
Imports Hash a9563ca2ee659a9314820bead4ec962b

DOS Header

e_magic MZ
e_cblp 0x78
e_cp 0x1
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x78

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2023-Jun-08 01:09:43
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x1e00
SizeOfInitializedData 0x17600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001140 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1f000
SizeOfHeaders 0x400
Checksum 0x2060a
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 612f13b1a20949bba1c805c638495c00
SHA1 8e74a79958acf6488fe615dee4173a4b96e39fae
SHA256 4ab9a6254f73f4956601a46361357f0ad92d238a43ae6f8eab200fa5047c1415
SHA3 1e7a84cf73f8503dee0f05389252d65ec5d8e1cb349fe970a29a24a6db3def5a
VirtualSize 0x1c86
VirtualAddress 0x1000
SizeOfRawData 0x1e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.77527

.rdata

MD5 dcb7faae7abc7c1dfadac4c2855067fa
SHA1 cae7ca686a9024d78f8289ce8674185151ec9550
SHA256 38d9791ed6ef45149712782f4a0ccfb42f23c02b3a4492ca7f03e53b9cbdecdc
SHA3 7f6f0f51025e8dd9feeb07420ea2050bd7396785845219b11465ff5de10d62bc
VirtualSize 0x114c
VirtualAddress 0x3000
SizeOfRawData 0x1200
PointerToRawData 0x2200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.35065

.buildid

MD5 c9953ee3f619c480e0c6ac294282f33d
SHA1 b78d4f87afadd36124948caecc7ab85ecf6ddcf9
SHA256 eb161533b3d278acc55e36c8ea0b8b2f88f2c8be709940d26c36d163a1249df1
SHA3 5cb63fa93131c77e339658cfc16cc03e9f3cc3451086b6a894e2e801623d6fc0
VirtualSize 0x35
VirtualAddress 0x5000
SizeOfRawData 0x200
PointerToRawData 0x3400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.600755

.data

MD5 d36e8e0be902e9d81289ba090cc311e5
SHA1 6d2c8cf042080bc1196e5565f5b2aa7854c74458
SHA256 a028f657d3a4672e79bfecb170e886116cbd0b06e428d842c91c20f05784ec66
SHA3 eb6eebff34b04427a10388b0c0285cbd5904f812b78d60a49dbd74bd6afa4325
VirtualSize 0x1bc
VirtualAddress 0x6000
SizeOfRawData 0x200
PointerToRawData 0x3600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.42505

.pdata

MD5 96b91119ce3f4f34345e33b607b00a4d
SHA1 47f375ecbcc5dee11fcadc69f4f66feaa2812e65
SHA256 6b6d61042d983cc28576e611fed69c351522e7188a7fe4ad6b870276bff8351d
SHA3 f839da7b9cf99a56b06fe69b6fc83d09a617654109243f8a352898a60c299d0c
VirtualSize 0x18c
VirtualAddress 0x7000
SizeOfRawData 0x200
PointerToRawData 0x3800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.12203

.tls

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0x8000
SizeOfRawData 0x200
PointerToRawData 0x3a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 a5988c2b738114e49123bc8be4105e1a
SHA1 b9261d08d1d802247646dda59de3f5669dfa81e3
SHA256 5980b26d5b916e89fdb4b706e7a45cfcdeba9e5aac839af102304dd9ed583780
SHA3 24ae65a3e695d3c5a2935a63f19d1458725aaf10019f07b6597317cf3a3d5fa8
VirtualSize 0x15b38
VirtualAddress 0x9000
SizeOfRawData 0x15c00
PointerToRawData 0x3c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.72197

Imports

api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
calloc
free
malloc
api-ms-win-crt-private-l1-1-0.dll __C_specific_handler
memcpy
api-ms-win-crt-runtime-l1-1-0.dll __p___argc
__p___argv
__p___wargv
__p__wcmdln
_cexit
_configure_narrow_argv
_configure_wide_argv
_crt_at_quick_exit
_crt_atexit
_initialize_narrow_environment
_initialize_wide_environment
_initterm
_set_app_type
_set_invalid_parameter_handler
abort
exit
signal
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
__p__commode
__p__fmode
__stdio_common_vfprintf
__stdio_common_vfwprintf
__stdio_common_vswprintf
fwrite
api-ms-win-crt-string-l1-1-0.dll _wcsdup
memset
strlen
strncmp
wcslen
USER32.dll MessageBoxW
KERNEL32.dll DeleteCriticalSection
EnterCriticalSection
GetLastError
GetProcAddress
GetStartupInfoW
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryW
SetDllDirectoryW
SetUnhandledExceptionFilter
Sleep
TlsGetValue
VerSetConditionMask
VerifyVersionInfoW
VirtualProtect
VirtualQuery
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
api-ms-win-crt-environment-l1-1-0.dll __p__environ
__p__wenviron
api-ms-win-crt-time-l1-1-0.dll __daylight
__timezone
__tzname
_tzset

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x11f0c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.98525
Detected Filetype PNG graphic file
MD5 c9f2e144c594f125c93d67c8589f94cb
SHA1 3c83859ad32e00831d73c3e7e0ecf016ed70a8a2
SHA256 bb0f432405dd0146e10cad611fc2eacda864a4705a7cf27b7957c432ad437b7e
SHA3 0d561b06ed1cb8e63659c0d580b100365c851645a357d7701ff7d6a5eccb9895

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.11793
MD5 458152437bed22f7bd89dc69aaf15bd7
SHA1 e29320ba2f2fddd739a8d2237c3117450ac2011c
SHA256 b3192a18fb10675280f881680135b4f37d7fdc5af7d201069c1b3f47aa54d7e3
SHA3 39e2df21afb4ff57d701847ce8a9eca894ba53a5a29a7416cfe02e8b33cb142c

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.27096
MD5 534215cef211a152679a4cc7bd91b7e1
SHA1 62ba9c1c73df21644c609d3b5fd2edc946eafadb
SHA256 8ac5e2c08e72998d06b9e79cc3522364730330763554bbebdfabc9a7bf0d1b46
SHA3 6f560168e19f37e1a6310914163bc1e23f5da7da7910ed604eb5cd4ed3bdc84f

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.62596
MD5 bd322d31714690439d11eb16737f4821
SHA1 344bbc216eeb6eba8e5fc6ce9f6bf3ded62fa918
SHA256 3801536907d2cffe216dda35c7fab46e36f0802c9738d1d52f79a9d19ba9fc4a
SHA3 f99cbc3cc5967660460bcbeeda1c04d2155acb2e8e28b4148172cec5840beab1

0

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x3e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.48426
Detected Filetype Icon file
MD5 84f9c249f731e2e8756bc805e0eb83f0
SHA1 66821612a3fff9cd372d29d23f1a1132a759895e
SHA256 e5fadec1ca3f88b262845c6e300b837214a554eae5084921f3c5178b74c1796d
SHA3 51da84cac26f96fa9fab3f458ffedf84ba493a6be14cfd91df5dc3e6225aac8c

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2023-Jun-08 01:09:43
Version 0.0
SizeofData 25
AddressOfRawData 0x501c
PointerToRawData 0x341c

TLS Callbacks

StartAddressOfRawData 0x140008000
EndAddressOfRawData 0x140008008
AddressOfIndex 0x140006128
AddressOfCallbacks 0x140003530
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x0000000140001780
0x0000000140001800

Load Configuration

RICH Header

Errors

[!] Error: Could not reach the requested directory (offset=0x0).