a54dfacc1098735b4001c9e9aeab1698

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2021-Aug-05 15:53:40
FileDescription
FileVersion 1.3
InternalName TestProcedimientoW10.exe
LegalCopyright
OriginalFilename TestProcedimientoW10.exe
ProductVersion 1.3
Assembly Version 1.3.0.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C# v7.0 / Basic .NET
.NET executable -> Microsoft
Suspicious The PE is possibly a dropper. Resources amount for 86.3847% of the executable.
Malicious VirusTotal score: 15/67 (Scanned on 2021-11-24 18:14:41) CAT-QuickHeal: Trojan.WacatacFC.S12096838
McAfee: RDN/Generic.dx
Cybereason: malicious.fcbc97
Cyren: W32/MSIL_Kryptik.BWA.gen!Eldorado
APEX: Malicious
Paloalto: generic.ml
McAfee-GW-Edition: RDN/Generic.dx
FireEye: Generic.mg.a54dfacc1098735b
Microsoft: Trojan:Win32/Zpevdo.B
AhnLab-V3: Malware/Win32.RL_Generic.C3792642
Cylance: Unsafe
TrendMicro-HouseCall: TROJ_GEN.R002H06IG21
SentinelOne: Static AI - Suspicious PE
BitDefenderTheta: Gen:NN.ZemsilF.34294.Am0@a0NlRWk
MaxSecure: Trojan.Malware.300983.susgen

Hashes

MD5 a54dfacc1098735b4001c9e9aeab1698
SHA1 83277a6fcbc97cb6e335d341665cb63e1bf9b8c1
SHA256 4c98bfdeda91b7bcb6682a43294a94c26731db0147b679a6fc6212879e1e401b
SHA3 c4c34eb5314e28d3c0599913f2b3ff3a5f36b96bfbef1900bdac58b2c3b63856
SSDeep 3072:LM7ja62Bsf7n0pezlOSBf5v8ojlW0jsUWLPkPogDnTtWJNwG:Ua72I4Rv8yA4jWLPngDnTtWg
Imports Hash f34d5f2d4577ed6d9ceec516c1f5a744

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 3
TimeDateStamp 2021-Aug-05 15:53:40
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 11.0
SizeOfCode 0xde00
SizeOfInitializedData 0x5ae00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000FD4E (Section: .text)
BaseOfCode 0x2000
BaseOfData 0x10000
ImageBase 0x400000
SectionAlignment 0x2000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x6e000
SizeOfHeaders 0x200
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e7a0e1d905ec0885c77c3b8ceb253882
SHA1 3c43fc198c7b7fd1b5c6ffbeda0c9742a2590d72
SHA256 6b182843428412c1af30be80448f9e001f6531fb8026df4f5607dd7bceabfd81
SHA3 596fa3c38b5f503038c4acfe2d4422d2591827c357a7d330d7c9fa71d89fc250
VirtualSize 0xdd54
VirtualAddress 0x2000
SizeOfRawData 0xde00
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.1276

.rsrc

MD5 31c3044328ce68c2b6e171e9e6f72a6b
SHA1 23e429fba40ce1fa02192de453494b151ef77f93
SHA256 105ea9a47ebff707fd9ba424b491c6098c613c7679ad93afcf2d5eb8b777ff1e
SHA3 e8d5ece3f4dde457132b620c1451e6fdffb4ebd00823b4654352b617f8a29585
VirtualSize 0x5abb8
VirtualAddress 0x10000
SizeOfRawData 0x5ac00
PointerToRawData 0xe000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.19511

.reloc

MD5 1ba9167273751ab2f45265dde0d92f79
SHA1 5601f2a0d86229a3190b93ea66d1c56c263147de
SHA256 862709c38f1a7e451ec2adc99abb971946cf4cca16ca2927fbb64eb858d284bc
SHA3 754d73b992305f7bf8bb635280de2de20430074a233a80ba2c37d97f6fba91e2
VirtualSize 0xc
VirtualAddress 0x6c000
SizeOfRawData 0x200
PointerToRawData 0x68c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.0815394

Imports

mscoree.dll _CorExeMain

Delayed Imports

2

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.09732
MD5 1b9381020deff9709fddf1e78f6f8290
SHA1 2fa60b1d63daad0356b61a77bb3aa96865b19a4d
SHA256 7d2e5be6f75e23fb5f7c121c2b4b8faec6e8ea05186ab4a479d3b0957eb30844
SHA3 26537b61b59a637a127dd5d532b16fde217c4b520b1533b9ab086fa38fed81aa

3

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.09826
MD5 b9bc7cc85b8b10847c19329d562207bb
SHA1 3452c6dbcf381ac3bad8d2af972c5409acd63be1
SHA256 91d18141378a6167bfec89800ac2b311a94d6be5bc3574a0028278f249456b5f
SHA3 3d5babd54aaa7951fbd5f37c9ced73dab4d174e69ed412a5c2d8f939edd505c0

4

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.0518
MD5 ea8d47be4b97da066ad7d74463ec9127
SHA1 c756a0e79b08be9b84073efa93776e09e2b4ad18
SHA256 a4354b360af62e5ebfeaa3a377e91be640f5ee88799e07537931ba9bed0b24ad
SHA3 bcee22fdae04e5a37628a93aee3602faa56159375281a67bf289a465a717fba7

5

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.9304
MD5 8cc8e48e10c28cd53cb3ae4d31795b46
SHA1 f78ccfaebfcb1747983ccf87d7fde309bdadd4d3
SHA256 84e948b68e31c4f69a446e6162e3e371f0a8e7edb2fb0be5d417ac6489530d77
SHA3 5c564f182f2133be0e30e5e3139edb089c001f30aa30f31ae412b9513da75afb

6

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.43868
MD5 7f03b49400f6f5e299ba57ddca653e97
SHA1 3e37995325e72a631ea7826a197dadbbbf872db2
SHA256 6ec2ab00fe5ae746b13f174e41b5e7cdd3a1dbbbacf7315d1178df263aeefb34
SHA3 31a9ab3d9419d6c6d8e441b86a6ad5e0f38b048b798d573cc5a6a0fe0e4476e3

7

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.96865
MD5 8ddeba8bb74a1a2a66f69123a2d8167d
SHA1 21cc0f1c682670e1e2bbfc66983543dd49df669e
SHA256 2f1fc1f1fc38899bdf6874fdbc8793538bb7be4e368ae48c5cf27406be53d71a
SHA3 f464dbc5987eb8798ff02f015f9172c37ded754c3054abc97dfd6562aab554e5

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.81543
Detected Filetype Icon file
MD5 a5b0b0860daebacd7f90c4200bf72c88
SHA1 a6f321a2778d946d63c3b7266c3cda0b888f2cea
SHA256 09fa78cbe61e110f574e7523919c2394570d96d62f5e0afbb9e11588e1635ccf
SHA3 b5a41d514aa033b824375f5f2dc4d46d23fbc96be8051a83d231f4712b9a73b1

1

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x26c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25458
MD5 d74c26d18aa96ef2ab35d16790cab831
SHA1 f58d2758c6f5f1d760bc68bb0902cf50e739c887
SHA256 0934ba9942e37c94aa9c5eb74907e85624e9f44e4e054411504f4c86ff284ee8
SHA3 489ad5555c87458839fdec81201bc6ff348a660039314ee9b021cfc9f0809796

1 (#2)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x193
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.9886
MD5 19d70dfcdeb812833de7ba67472845d5
SHA1 e8f6ebb0080572042c7cf97a8a3911e1aec364ad
SHA256 6a6690c7e7400672941c6ed0cdde6f5119e5bf49956706bea9d4a442b1213d7d
SHA3 2f85c1eb489631f2bf6527b77f95783569bcc288c4d1fbcdd6cb2ee7e7c68ab4

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.3.0.0
ProductVersion 1.3.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
FileDescription
FileVersion (#2) 1.3
InternalName TestProcedimientoW10.exe
LegalCopyright
OriginalFilename TestProcedimientoW10.exe
ProductVersion (#2) 1.3
Assembly Version 1.3.0.0
Resource LangID UNKNOWN

TLS Callbacks

Load Configuration

RICH Header

Errors

<-- -->