aba2d86ed17f587eb6d57e6c75f64f05

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2016-Feb-06 21:24:54
Detected languages English - United States
TLS Callbacks 3 callback(s) detected.

Plugin Output

Suspicious PEiD Signature: UPolyX V0.1 -> Delikon
PolyEnE 0.01+ by Lennart Hedlund
Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • %TEMP%
  • CurrentVersion\Run
Suspicious The PE is possibly packed. Unusual section name found: .eh_fram
Info The PE contains common functions which appear in legitimate applications. Possibly launches other programs:
  • ShellExecuteA
Has Internet access capabilities:
  • InternetCloseHandle
  • InternetConnectA
  • InternetFindNextFileA
  • InternetOpenA
  • InternetOpenUrlA
  • InternetReadFile
  • InternetSetOptionA
Malicious The PE is possibly a dropper. Resource RCDATA1 detected as a PE Executable.
Resources amount for 93.6665% of the executable.
Malicious VirusTotal score: 61/65 (Scanned on 2017-09-05 08:33:45) Bkav: W32.DotomchASAO.Trojan
MicroWorld-eScan: Trojan.AgentWDCR.HWR
nProtect: Trojan/W32.BitCoinMiner.1578496
CAT-QuickHeal: Risktool.BitCoinMiner.DR9
ALYac: Misc.Riskware.BitCoinMiner
Malwarebytes: Trojan.BitCoinMiner
Zillya: Trojan.Black.Win32.46302
SUPERAntiSpyware: Ransom.Locky/Variant
TheHacker: Trojan/CoinMiner.zt
K7GW: Unwanted-Program ( 004bb37d1 )
K7AntiVirus: Unwanted-Program ( 004bb37d1 )
Arcabit: Trojan.AgentWDCR.HWR
Invincea: heuristic
Baidu: Win32.HackTool.CoinMiner.a
F-Prot: W32/Coinminer.A
Symantec: SMG.Heur!gen
TotalDefense: Win32/Tnega.XAUQ!suspicious
TrendMicro-HouseCall: WORM_COINMINE.NC
Paloalto: generic.ml
ClamAV: Win.Malware.Locky-9361
VBA32: Worm.Remoh
Kaspersky: Trojan.Win32.Agentb.btdr
BitDefender: Trojan.AgentWDCR.HWR
NANO-Antivirus: Trojan.Win32.DownLoad3.eopqgg
AegisLab: Risktool.W32.Bitcoinminer!c
Avast: Win32:Malware-gen
Tencent: Win32.Trojan.Agentb.Lpla
Endgame: malicious (high confidence)
Emsisoft: Trojan.AgentWDCR.HWR (B)
Comodo: TrojWare.Win32.CoinMiner.B
F-Secure: Trojan.AgentWDCR.HWR
DrWeb: Trojan.BtcMine.1214
VIPRE: Trojan.Win32.Generic!BT
TrendMicro: WORM_COINMINE.NC
McAfee-GW-Edition: BehavesLike.Win32.Worm.tc
Sophos: Troj/Miner-CZ
Cyren: W32/Coinminer.DWZG-8697
Jiangmin: RiskTool.BitCoinMiner.ab
Webroot: W32.Bitcoinminer
Avira: TR/BitCoinMiner.fra
Antiy-AVL: Trojan[PSW]/Win32.Tepfer
Microsoft: Trojan:Win32/CoinMiner.BB!bit
ViRobot: Trojan.Win32.R.Agent.1578496
ZoneAlarm: Trojan.Win32.Agentb.btdr
GData: Win32.Trojan.Agent.ER3HBX
AhnLab-V3: Trojan/Win32.CoinMiner.C1363390
McAfee: Generic.zn
AVware: Trojan.Win32.Generic!BT
MAX: malware (ai score=100)
Ad-Aware: Trojan.AgentWDCR.HWR
Cylance: Unsafe
Zoner: Trojan.Bitcoinminer
ESET-NOD32: Win32/Crytes.AA
Rising: Trojan.Win32.CoinMiner.c (ktse)
Yandex: Trojan.Miner!8na/85u4hbs
Ikarus: Worm.Win32.Crytes
Fortinet: W32/Generic.AC.21C85C!tr
AVG: Win32:Malware-gen
Panda: Trj/WLT.C
CrowdStrike: malicious_confidence_100% (W)
Qihoo-360: Win32/Trojan.cb4

Hashes

MD5 aba2d86ed17f587eb6d57e6c75f64f05
SHA1 aeccba64f4dd19033ac2226b4445faac05c88b76
SHA256 807126cbae47c03c99590d081b82d5761e0b9c57a92736fc8516cf41bc564a7d
SHA3 5456620ea17f0476180e348ced0df268478591846ce03a688eeac2217b20af6c
SSDeep 24576:pWKqa4hnzP3w7L3rmZmpk7FSQFW2iJ+N07/TwYV1CdZdQ+4lT+iFgiGTtswAtdz:pSrwf3aZmpOFU2iQNIUc1LxGTtswgd
Imports Hash 60da00e1cd73bcdc78866dfc77676d4b

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 9
TimeDateStamp 2016-Feb-06 21:24:54
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x13800
SizeOfInitializedData 0x181200
SizeOfUninitializedData 0x4c00
AddressOfEntryPoint 0x12a0 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x15000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 1.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x18c000
SizeOfHeaders 0x400
Checksum 0x18a65e
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics (EMPTY)
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 39157f6164a3e966d93a9e54bfd55e5d
SHA1 e4f3b05c2cb72a3a9bb4e5bacd63788c2b5490c5
SHA256 c9e1fd77e2e7720cf06e96a999d6dac15968a224270deff5b1f4865209f9d0c1
SHA3 7e465e12a78e2c7aebb11fb1d72c0f5943b1583d42eed0fddee3db88da8f9778
VirtualSize 0x137d0
VirtualAddress 0x1000
SizeOfRawData 0x13800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.10382

.data

MD5 4fc8adf7c869a3dc80426fcded1e27c6
SHA1 256e5fd77471c28593995ca3c04c6bd381484a7e
SHA256 73ce5d3a44495b392987790dacd55271faf9908b4e1fc1048792f2ab0149001d
SHA3 364998b9a158425bcfd8ce4c4e49fd5bd5b1cf4b6d9613a9febd8add7a3b045c
VirtualSize 0x464
VirtualAddress 0x15000
SizeOfRawData 0x600
PointerToRawData 0x13c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.15393

.rdata

MD5 01869b2ba05653efc7e6e179ffc28524
SHA1 404f81af522150235967c7ea3605dc7ec5deff1d
SHA256 dce8dfb0f1da35d68ba8fe57ef9080da81bf94ebb4b5232092ad7a095e2c8e24
SHA3 7225c2cac1c7e58fbcf1808cf0b95019b2f2d156f889f3a509d29670af056163
VirtualSize 0x2814
VirtualAddress 0x16000
SizeOfRawData 0x2a00
PointerToRawData 0x14200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.20732

.eh_fram

MD5 a5fe82dca0728310905bb6a8e4d0bc89
SHA1 38077d7eac73791ed56a875f762607f420a30eea
SHA256 f6e908e0cc1cf9cd791fff1e3cd23095b00fd6f973bf5aac470fa3d0d00c7415
SHA3 182178ba907ce95c6d57b223c39b69a4ba061f348efe7da7f6481b6a31c0d205
VirtualSize 0x3f8
VirtualAddress 0x19000
SizeOfRawData 0x400
PointerToRawData 0x16c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.59707

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 c5d2460186f7233c927e7db2dcc703c0e500b653ca82273b7bfad8045d85a470
VirtualSize 0x4b4c
VirtualAddress 0x1a000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.idata

MD5 e5e1e8c03c9fe706cebf7ad22484fd9c
SHA1 851ac9544791955aa0578aca1df9a4d4611cedff
SHA256 1f614431275a752a873941865ec9a32c43ea563f703fda9732ca13bf1c1f1caa
SHA3 fadbde0c63f8da83fe5e980429b693e4362a6b2442d76adba4f534b33f737c3f
VirtualSize 0xd98
VirtualAddress 0x1f000
SizeOfRawData 0xe00
PointerToRawData 0x17000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.20616

.CRT

MD5 9d082062f4e4e509453fecdae3c43c45
SHA1 017fb7e9f533038de83933b0d5cb232b45bedb9b
SHA256 ed16f4769b9a7d4c4036d8f31b267afba5453e3dd8348567d1a67e8c09d01371
SHA3 1d94ebfcaa891f0c74a9b2447f96f8fb666458b360a228d3423929691c71e022
VirtualSize 0x1c
VirtualAddress 0x20000
SizeOfRawData 0x200
PointerToRawData 0x17e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.170146

.tls

MD5 f8afb1bfec2ae1670831e201203150b4
SHA1 997b5806a26eb53fe57011ba617d9de51785c1ee
SHA256 327103325f3c39f8b74e3c5732a1ae3de171013265204687e5449ec7979aa181
SHA3 1b9c9c2125e57bd0ba1a470a2eddee82324270585a9cf1c61465899ea7f9c2ad
VirtualSize 0x20
VirtualAddress 0x21000
SizeOfRawData 0x200
PointerToRawData 0x18000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.210826

.rsrc

MD5 2a2c87b0b8e62eec304b57f76d5904de
SHA1 7cdf9e1c2ee86aa3d95a06b23898cac34b5e4005
SHA256 0f91da91c1341080d247e77e1dd9213d1cc12a17a6c9813746908aded4c8ba4b
SHA3 16db69b52d75cd2dd6a88996bc2df5d5b2eab618c1ae319adc9714770f2b0050
VirtualSize 0x169230
VirtualAddress 0x22000
SizeOfRawData 0x169400
PointerToRawData 0x18200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.91453

Imports

WININET.DLL FtpFindFirstFileA
FtpGetFileA
FtpOpenFileA
FtpPutFileA
InternetCloseHandle
InternetConnectA
InternetFindNextFileA
InternetOpenA
InternetOpenUrlA
InternetReadFile
InternetSetOptionA
KERNEL32.dll AddAtomA
CloseHandle
CreateEventA
CreateFileA
CreateMutexA
CreateSemaphoreA
DeleteCriticalSection
DeleteFileA
DuplicateHandle
EnterCriticalSection
ExitProcess
ExpandEnvironmentStringsA
FindAtomA
FindResourceA
GetAtomNameA
GetCommandLineA
GetCurrentProcess
GetCurrentThread
GetCurrentThreadId
GetHandleInformation
GetLastError
GetModuleFileNameA
GetModuleHandleA
GetProcAddress
GetProcessAffinityMask
GetStartupInfoA
GetThreadContext
GetThreadPriority
GetTickCount
InitializeCriticalSection
InterlockedDecrement
InterlockedExchangeAdd
InterlockedIncrement
LeaveCriticalSection
LoadResource
LockResource
QueryPerformanceCounter
QueryPerformanceFrequency
ReleaseMutex
ReleaseSemaphore
ResetEvent
ResumeThread
SetEvent
SetLastError
SetProcessAffinityMask
SetThreadContext
SetThreadPriority
SetUnhandledExceptionFilter
SizeofResource
Sleep
SuspendThread
TlsAlloc
TlsGetValue
TlsSetValue
TryEnterCriticalSection
VirtualProtect
VirtualQuery
WaitForMultipleObjects
WaitForSingleObject
WriteFile
msvcrt.dll _write
msvcrt.dll (#2) _write
SHELL32.DLL ShellExecuteA

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x668
Entropy 2.74783
MD5 a58a5f4e299ea44443844ec56ff431a0
SHA1 852b83d5557013154757d29827a573002e59f67d
SHA256 207fd544b13bc13b41e30330f34cbed99be2d8bc96e0fbf1642bf87e539c5b04
SHA3 6dc2f1f2b7eda14cf635db22ca68fe7f8b6a31c089d660b90bb4b939ca79eedd

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
Entropy 2.9036
MD5 e0f156b0f823ca4e0e11172a0ecf24c9
SHA1 7ff0c03ee06cfb5597c0f813e24eb9a38c900b2c
SHA256 7fe772dbc0d6f69e097bfe0f0e5960e282fd7217c7bc5584ba83b406efa9383d
SHA3 2014a0a114a2883748ed10dbab347937d35a46919050a700de3c431563363c09

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
Entropy 3.25525
MD5 a4fc028f5163ed8bf14a8c0b0206dd93
SHA1 0bab66220262c08d859aa5e28fc62c131aff7cb6
SHA256 b7b57d5c06be8ef2a85dc3f9faadb2572c61354aefb43c6c05f313c2061e9d38
SHA3 15c165c587e35c729b9a65f332fca7c5b664d80643e04ac3588130682572ef82

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
Entropy 4.06801
MD5 ca4e261bdba41965f948d3827ef59103
SHA1 3767a90b477302367bfd27d23ac38e1d31280563
SHA256 6e9b7d5b674577fe5bd14b0d91bed50fa0ed0d9f56d90a2545793217d0f34a5f
SHA3 42fefec095e94be62388714e5d07391dec5663897d6fe58146ceea47012a472e

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
Entropy 4.19807
MD5 58b16941eafbee4512ad166d471665ac
SHA1 934c6803805a23b7b12fa0c9a5aaa94d4b4523d4
SHA256 da431d25b19fe5a3a67aac04530d7bea72a0fa2bdf24bfa7f315b41a724536fe
SHA3 e266dd006d3fbee530d3f775b8e1c79220125a16298e4bff1f470219f4118dcd

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
Entropy 3.00266
MD5 5f839904d1f830ca14f3535a66bdc503
SHA1 557cfe9cd7067d515d62b08b2e1ba48b270a3a3e
SHA256 d49dbac01bbe40db013314532e76eaf2040145269db9e42f38d67a685fe3b7f4
SHA3 afed45066efae68ccc960bc6d5551c061c248bf41bc460b34dd07e8ba6d23f4f

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4d00
Entropy 7.95778
Detected Filetype PNG graphic file
MD5 f9de2d94f87ce697327e8f6bc5664895
SHA1 c1a0f0f2f683857a9ee6931b7dbae2b9db67c7f3
SHA256 c29b2796c9604393dfb0d33b26f5ad719c6e468efeb6e2b2eafe651a1e3f2e29
SHA3 106db15b0e55169fb54ca1dc18047ea8c69e8b41a7a30c729817cef6bc298df7

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
Entropy 3.87831
MD5 33fbf612b11e891563f7e9a3cce85632
SHA1 d135645db90279e96a460452623b11fda4209873
SHA256 639b5182dcf8c0bb7b5666256ae0635b9db4c5cb86e4401198b31765cbf65adf
SHA3 b5468bf480ae78c13399a139f24d98c8e7608aad2c984f1c1867cc6d2b58e5ac

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
Entropy 4.41844
MD5 4dd6a47783da4f97a1356d24da5f38f4
SHA1 e44c8fc8a536c08e1535dcc80a9a84123fc54517
SHA256 1d62ec45a12db8f620e8a7f42ee9a5851557dc47a1898a0c351c2c8b971f108b
SHA3 bd86dc48b35c4722c71dff1dca8a992d87b8df157d6518735a138d7ea5388e36

10

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
Entropy 5.09697
MD5 4a5a9568dd29f98a988bad6018a8cc27
SHA1 69d88ea0ef59928d840b0a29240256f60e6965a4
SHA256 6baa65aaa1fd1da200ae4b536e76d733a232e1a92d1fd47b346a1dab98882ab5
SHA3 2ba649fa6474fe21584af8beebab62c24e5f27a3f54d3c7dd5f9b7b7d0821dae

RCDATA1

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x15e000
Entropy 7.93024
Detected Filetype PE Executable
MD5 3afeb8e9af02a33ff71bf2f6751cae3a
SHA1 fd358cfe41c7aa3aa9e4cf62f832d8ae6baa8107
SHA256 a0eba3fda0d7b22a5d694105ec700df7c7012ddc4ae611c3071ef858e2c69f08
SHA3 bbc01be251ab1190672c768ec20446853c0a1896e882d24b19e24b0bc754495e

ICON1

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x92
Entropy 2.85059
Detected Filetype Icon file
MD5 3e8667ee9310f4e5ee5b45ffaac60a4c
SHA1 39d7460007158fa2fa45727b0e97bb2852db48ea
SHA256 0151fc81c92419fc254e47334416d9b7ca0a6bb63a76680e947705f60caec41f
SHA3 28b1b92dad10170ec07ff8908a15c986dcb704ba95d79f25ed04ee12bd801fc2

Version Info

TLS Callbacks

StartAddressOfRawData 0x421019
EndAddressOfRawData 0x42101c
AddressOfIndex 0x41ea78
AddressOfCallbacks 0x420004
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks 0x40c2b0
0x40c260
0x40fae0

Load Configuration

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .bss has a size of 0!