| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date |
2026-Sep-09 20:20:13
|
| Detected languages |
English - United States
French - France
Spanish - Guatemala
|
| CompanyName |
MPT
|
| FileDescription |
MPT-Proxy x64
|
| FileVersion |
1.0.0.0
|
| InternalName |
version
|
| LegalCopyright |
MPT
|
| OriginalFilename |
mpt.dll
|
| ProductName |
version.dll
|
| ProductVersion |
1.0.0.0
|
|
Suspicious
|
The PE is packed with UPX |
Unusual section name found: UPX0
Section UPX0 is both writable and executable.
Unusual section name found: UPX1
Section UPX1 is both writable and executable.
The PE only has 3 import(s).
|
|
Info
|
The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
- LoadLibraryA
- GetProcAddress
|
|
Malicious
|
VirusTotal score: 17/70 (Scanned on 2026-10-04 09:51:19) |
AhnLab-V3:
Trojan/Win.Generic.R797117
Antiy-AVL:
Trojan/Win32.Agent
CTX:
dll.trojan.wacatac
CrowdStrike:
win/malicious_confidence_60% (D)
Gridinsoft:
Trojan.Win64.Wacatac.cl
Ikarus:
Trojan.W64.MalwareX
Lionic:
Trojan.Win32.Generic.4!c
MaxSecure:
Trojan.Malware.338148470.susgen
McAfeeD:
ti!A85CE849C111
Skyhigh:
BehavesLike.Win64.Trojan.qc
Sophos:
Mal/Generic-S
Symantec:
ML.Attribute.HighConfidence
TrellixENS:
Artemis!8BE35AE10806
TrendMicro:
Trojan.Win32.MALWAREX.USBLIG26
TrendMicro-HouseCall:
Trojan.Win32.MALWAREX.USBLIG26
Varist:
W64/ABTrojan.YWNC-7453
alibabacloud:
Trojan:Win/Wacatac.B9nj
|
| MD5 |
8be35ae1080622004a9e7f6ea3b19f4f
🔍
|
| SHA1 |
8a50e50831792ef3d58e827423568e0754ea0858
🔍
|
| SHA256 |
a85ce849c111376b4c0f501ab193b12b9e741e74e13f5a2ebba9ed6bea875367
🔍
|
| SHA3 |
7eee730588c57ce1a6eb8ca87086dfb2f28be9f4385b8ebd02596f21e117db17
🔍
|
| SSDeep |
1536:b2xodyzTENkjn3/UQFcz/j299CBZY5fKrKUXofpajNv/XmckVPxIiT2Om1nBa0r:ixod1NDQFczW4rEfNUCpWnWckVPxIiT
🔍
|
| Imports Hash |
6859c1fbd5011b39e2b3c5ccd6eda491
🔍
|
| e_magic |
MZ
|
| e_cblp |
0x90
|
| e_cp |
0x3
|
| e_crlc |
0
|
| e_cparhdr |
0x4
|
| e_minalloc |
0
|
| e_maxalloc |
0xffff
|
| e_ss |
0
|
| e_sp |
0xb8
|
| e_csum |
0
|
| e_ip |
0
|
| e_cs |
0
|
| e_ovno |
0
|
| e_oemid |
0
|
| e_oeminfo |
0
|
| e_lfanew |
0x108
|
| Signature |
PE
|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections |
3
|
| TimeDateStamp |
2026-Sep-09 20:20:13
|
| PointerToSymbolTable |
0
|
| NumberOfSymbols |
0
|
| SizeOfOptionalHeader |
0xf0
|
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic |
PE32+
|
| LinkerVersion |
14.0
|
| SizeOfCode |
0xc000
|
| SizeOfInitializedData |
0x1000
|
| SizeOfUninitializedData |
0x16000
|
| AddressOfEntryPoint |
0x0000000000022BD0 (Section: UPX1)
|
| BaseOfCode |
0x17000
|
| ImageBase |
0x180000000
|
| SectionAlignment |
0x1000
|
| FileAlignment |
0x200
|
| OperatingSystemVersion |
6.0
|
| ImageVersion |
0.0
|
| SubsystemVersion |
6.0
|
| Win32VersionValue |
0
|
| SizeOfImage |
0x24000
|
| SizeOfHeaders |
0x400
|
| Checksum |
0
|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve |
0x100000
|
| SizeofStackCommit |
0x1000
|
| SizeofHeapReserve |
0x100000
|
| SizeofHeapCommit |
0x1000
|
| LoaderFlags |
0
|
| NumberOfRvaAndSizes |
16
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
🔍
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
🔍
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
🔍
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
🔍
|
| VirtualSize |
0x16000
|
| VirtualAddress |
0x1000
|
| SizeOfRawData |
0
|
| PointerToRawData |
0x400
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| MD5 |
e9da3eb223dcde93eb61c22c26e758d7
🔍
|
| SHA1 |
dbeb052b5698bf347416c55a0e70223d5bde07a2
🔍
|
| SHA256 |
2951e892b543028a3f5a11118079d1d6af37167e16174fbde127d35ced878604
🔍
|
| SHA3 |
4eb0c6bea36996f37eaefaada690ace9f92a7a482f13d4cdfb94d2ece9eab32f
🔍
|
| VirtualSize |
0xc000
|
| VirtualAddress |
0x17000
|
| SizeOfRawData |
0xc000
|
| PointerToRawData |
0x400
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
7.88868
|
| MD5 |
44ecaf5b792a6d1a5eb2dea05100e0cb
🔍
|
| SHA1 |
15de4d63cd3e937cc0b919ad5e0724e3ea554d9c
🔍
|
| SHA256 |
20a4166ac619f120ded3a426fc6e41baeee181b6eb7d0455ab8bc690025bf081
🔍
|
| SHA3 |
dbd0e687b81a00660246e713c50a6af900f6c53f943ed866e0b9e91c2b90fec4
🔍
|
| VirtualSize |
0x1000
|
| VirtualAddress |
0x23000
|
| SizeOfRawData |
0xc00
|
| PointerToRawData |
0xc400
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
4.71161
|
| KERNEL32.DLL |
LoadLibraryA
GetProcAddress
VirtualProtect
|
| Ordinal |
1
|
| Address |
0x23747
|
| ForwardName |
C:\\Windows\\System32\\version.GetFileVersionInfoA
|
| Ordinal |
2
|
| Address |
0x2377a
|
| ForwardName |
C:\\Windows\\System32\\version.GetFileVersionInfoByHandle
|
| Ordinal |
3
|
| Address |
0x237b4
|
| ForwardName |
C:\\Windows\\System32\\version.GetFileVersionInfoExA
|
| Ordinal |
4
|
| Address |
0x237e9
|
| ForwardName |
C:\\Windows\\System32\\version.GetFileVersionInfoExW
|
| Ordinal |
5
|
| Address |
0x2381e
|
| ForwardName |
C:\\Windows\\System32\\version.GetFileVersionInfoSizeA
|
| Ordinal |
6
|
| Address |
0x23855
|
| ForwardName |
C:\\Windows\\System32\\version.GetFileVersionInfoSizeExA
|
| Ordinal |
7
|
| Address |
0x2388e
|
| ForwardName |
C:\\Windows\\System32\\version.GetFileVersionInfoSizeExW
|
| Ordinal |
8
|
| Address |
0x238c7
|
| ForwardName |
C:\\Windows\\System32\\version.GetFileVersionInfoSizeW
|
| Ordinal |
9
|
| Address |
0x238fe
|
| ForwardName |
C:\\Windows\\System32\\version.GetFileVersionInfoW
|
| Ordinal |
10
|
| Address |
0x23931
|
| ForwardName |
C:\\Windows\\System32\\version.VerFindFileA
|
| Ordinal |
11
|
| Address |
0x2395d
|
| ForwardName |
C:\\Windows\\System32\\version.VerFindFileW
|
| Ordinal |
12
|
| Address |
0x23989
|
| ForwardName |
C:\\Windows\\System32\\version.VerInstallFileA
|
| Ordinal |
13
|
| Address |
0x239b8
|
| ForwardName |
C:\\Windows\\System32\\version.VerInstallFileW
|
| Ordinal |
14
|
| Address |
0x239e7
|
| ForwardName |
C:\\Windows\\System32\\version.VerLanguageNameA
|
| Ordinal |
15
|
| Address |
0x23a17
|
| ForwardName |
C:\\Windows\\System32\\version.VerLanguageNameW
|
| Ordinal |
16
|
| Address |
0x23a47
|
| ForwardName |
C:\\Windows\\System32\\version.VerQueryValueA
|
| Ordinal |
17
|
| Address |
0x23a75
|
| ForwardName |
C:\\Windows\\System32\\version.VerQueryValueW
|
| Type |
RT_VERSION
|
| Language |
French - France
|
| Codepage |
UNKNOWN
|
| Size |
0x278
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.29452
|
| MD5 |
ee76e953918ae8990eb9bbb4f17ef87a
🔍
|
| SHA1 |
4321d62683c4bfb56124039260d43a837c85df21
🔍
|
| SHA256 |
042b70bf5ae380b96a41fab23f4f7062ab73dafee13f83f6eb7359a0c64bb4b6
🔍
|
| SHA3 |
cca954219105fb61be4d4ce675786de0e27fbfe17e27e674b72e6bc3b3ed1955
🔍
|
| Type |
RT_MANIFEST
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x173
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
5.05368
|
| MD5 |
95ecd4b653fa71bb58c8cb06e4b9c02a
🔍
|
| SHA1 |
2572acbef32cee3cf3fbafb7101c51e52fc71284
🔍
|
| SHA256 |
492e3c8d40bde5bfb80cf9f611fc735b717009f7b3dc6994531fd865e16e3dd6
🔍
|
| SHA3 |
807530f20688414e48da1c1082d53a45ec10f566e19e7e2488ef5ad2b4d11f84
🔍
|
| Signature |
0xfeef04bd
|
| StructVersion |
0x10000
|
| FileVersion |
1.0.0.0
|
| ProductVersion |
1.0.0.0
|
| FileFlags |
(EMPTY)
|
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language |
Spanish - Guatemala
|
| CompanyName |
MPT
|
| FileDescription |
MPT-Proxy x64
|
| FileVersion (#2) |
1.0.0.0
|
| InternalName |
version
|
| LegalCopyright |
MPT
|
| OriginalFilename |
mpt.dll
|
| ProductName |
version.dll
|
| ProductVersion (#2) |
1.0.0.0
|
| Resource LangID |
French - France
|
| Size |
0x140
|
| TimeDateStamp |
1970-Jan-01 00:00:00
|
| Version |
0.0
|
| GlobalFlagsClear |
(EMPTY)
|
| GlobalFlagsSet |
(EMPTY)
|
| CriticalSectionDefaultTimeout |
0
|
| DeCommitFreeBlockThreshold |
0
|
| DeCommitTotalFreeThreshold |
0
|
| LockPrefixTable |
0
|
| MaximumAllocationSize |
0
|
| VirtualMemoryThreshold |
0
|
| ProcessAffinityMask |
0
|
| ProcessHeapFlags |
(EMPTY)
|
| CSDVersion |
0
|
| Reserved1 |
0
|
| EditList |
0
|
| SecurityCookie |
0x18001a000
|
| XOR Key |
0xfafae98b
|
| Unmarked objects |
0
|
| C++ objects (33145) |
137
|
| C objects (33145) |
12
|
| ASM objects (33145) |
6
|
| ASM objects (35721) |
9
|
| C objects (35721) |
15
|
| C++ objects (35721) |
31
|
| Imports (33145) |
3
|
| Total imports |
90
|
| C++ objects (LTCG) (36257) |
1
|
| Exports (36257) |
1
|
| Resource objects (36257) |
1
|
| 151 |
1
|
| Linker (36257) |
1
|
[*] Warning: Section UPX0 has a size of 0!