b5380d069dc0f1096101d102f6b7fce312844fdad299abfdce4363e6bb1fb507

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-28 17:43:52
Detected languages English - United States
CompanyName Sims4Updater
FileDescription Sims 4 Updater (beta)
FileVersion 2.6.5.0
InternalName Sims 4 Updater (beta)
LegalCopyright Sims4Updater
OriginalFilename sims-4-updater-v2.6.5-beta.exe
ProductName Sims 4 Updater (beta)
ProductVersion 2.6.5.0

Plugin Output

Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Suspicious The PE is possibly packed. Unusual section name found: .fptable
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Functions related to the privilege level:
  • OpenProcessToken
Enumerates local disk drives:
  • GetDriveTypeW
Info The PE is digitally signed. Signer: Sims4Updater
Issuer: Sims4Updater
Malicious VirusTotal score: 4/70 (Scanned on 2026-07-28 17:45:00) APEX: Malicious
Bkav: W32.Malware.D54389A0
Microsoft: Trojan:Win32/Wacatac.B!ml
Zillya: Backdoor.XWorm.Win32.3294

Hashes

MD5 04de7e503a4d03c3b44e2ebbf92c7cdb
SHA1 3e023b68e7b7ec9a718b5489df8cf5e8fe915a5d
SHA256 b5380d069dc0f1096101d102f6b7fce312844fdad299abfdce4363e6bb1fb507
SHA3 b88dc3c4467a47eae3d2d801457cb11136925a80c7de2d9145d367c81a973176
SSDeep 786432:5W8Fgfa7KZCaolCMw1LgtAiGVn7gzZhVQb9cVPpje+BPBsr:5Woqa7KZQlhw1Utl27gzJ+9cVPpje+H
Imports Hash dcaf48c1f10b0efa0a4472200f3850ed

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Jul-28 17:43:52
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x2c600
SizeOfInitializedData 0x18c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000000DFC0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x4f000
SizeOfHeaders 0x400
Checksum 0x193f67b
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x1e8480
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e0c77dbbcbcab802310739b87b1cb097
SHA1 10eafc7c2241b49e98c00f013fb74650f3854120
SHA256 b6384a19c8e7951b27929ff0febeef11246d385ee5f6e0f3931b7e985597b701
SHA3 3f5b56135638f16b13c4c8a490e720e61de121c52bba72fbd451ae835e632e2f
VirtualSize 0x2c490
VirtualAddress 0x1000
SizeOfRawData 0x2c600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.4654

.rdata

MD5 fe2e7d42531f81dffed145b297cdf77d
SHA1 792b96ca285d28337d3c5eb79275ca1fc2ddf5c5
SHA256 2d22dba8f642d919dae511eede66a79ff8c8d16a70f6abf1d9ff6b264f788755
SHA3 d599b0fc62774915a57f560593fa54d7b19429aada729cb3dbf1e719fa4bcf2f
VirtualSize 0x13b68
VirtualAddress 0x2e000
SizeOfRawData 0x13c00
PointerToRawData 0x2ca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.75344

.data

MD5 480ab7be9be730afcebb349cd1d2328a
SHA1 ded45b1e3b731c13795e36c5d7e8f3dac03f9634
SHA256 5bf16564eab136ff8a49b29867918b49a778978cd4c5acf2fb5ccdd19340831c
SHA3 665776fd9e8a604af79a90d67204a109fae9ce0d6a01405a4d85231867f7a494
VirtualSize 0x50b0
VirtualAddress 0x42000
SizeOfRawData 0xe00
PointerToRawData 0x40600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.8161

.pdata

MD5 375cd8e9e26fc1b25836640492a05048
SHA1 891f2e3ab5a219364450e77d8c8a80ef3074fa42
SHA256 520b0ee170e11e6d90932f9eca616049f1bbd16f36f0f9299325574c3077d010
SHA3 475e9b70a96d08c08df845b116e9c2218b1ae2cf08b189d000ec155e6a10b731
VirtualSize 0x240c
VirtualAddress 0x48000
SizeOfRawData 0x2600
PointerToRawData 0x41400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.31534

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x100
VirtualAddress 0x4b000
SizeOfRawData 0x200
PointerToRawData 0x43a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 a171f85ade02b953d1e1d86c8db25ff4
SHA1 aeaa6eb6aa4d641020657eadbb4d8e04fe38c485
SHA256 311392123c9fd51729f5cef5555d11c822878ab9a777554b5b5d28f86f02d3f8
SHA3 31a0811fc60ff5e630cb809a113ef912c86897ad9daf45bf4fde8076d0be882b
VirtualSize 0x1058
VirtualAddress 0x4c000
SizeOfRawData 0x1200
PointerToRawData 0x43c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.71306

.reloc

MD5 2b6e08476851652d83b5fd30f90f9ad7
SHA1 b61504ed73820ed543f7df51e5227d17e517badb
SHA256 c80cd8828e3293d84bf4a1764b2d6611ca75492eef2fbf318645b9dbe3731db6
SHA3 403fee35fd8e088c0269d849358d33217081fa4c577a1530a25d0911ed5bcf3e
VirtualSize 0x774
VirtualAddress 0x4e000
SizeOfRawData 0x800
PointerToRawData 0x44e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.26439

Imports

USER32.dll CreateWindowExW
ShutdownBlockReasonCreate
MsgWaitForMultipleObjects
ShowWindow
DestroyWindow
RegisterClassW
DefWindowProcW
PeekMessageW
DispatchMessageW
TranslateMessage
PostMessageW
GetMessageW
MessageBoxW
MessageBoxA
SystemParametersInfoW
DestroyIcon
SetWindowLongPtrW
GetWindowLongPtrW
GetClientRect
InvalidateRect
ReleaseDC
GetDC
DrawTextW
GetDialogBaseUnits
EndDialog
DialogBoxIndirectParamW
MoveWindow
SendMessageW
COMCTL32.dll #380
KERNEL32.dll GetACP
IsValidCodePage
GetStringTypeW
GetFileAttributesExW
SetEnvironmentVariableW
FlushFileBuffers
LCMapStringW
CompareStringW
VirtualProtect
InitializeCriticalSectionEx
GetOEMCP
GetCPInfo
GetLastError
FreeLibrary
GetProcAddress
LoadLibraryExW
GetModuleHandleW
MulDiv
FormatMessageW
GetModuleFileNameW
SetDllDirectoryW
GetEnvironmentStringsW
SetErrorMode
CreateDirectoryW
GetCommandLineW
GetEnvironmentVariableW
ExpandEnvironmentStringsW
DeleteFileW
FindClose
FindFirstFileW
FindNextFileW
GetDriveTypeW
RemoveDirectoryW
GetTempPathW
CloseHandle
QueryPerformanceCounter
QueryPerformanceFrequency
WaitForSingleObject
Sleep
GetCurrentProcess
TerminateProcess
GetExitCodeProcess
CreateProcessW
GetStartupInfoW
LocalFree
SetConsoleCtrlHandler
K32EnumProcessModules
K32GetModuleFileNameExW
CreateFileW
FindFirstFileExW
GetFinalPathNameByHandleW
MultiByteToWideChar
WideCharToMultiByte
FlsFree
FreeEnvironmentStringsW
GetProcessHeap
GetTimeZoneInformation
HeapSize
HeapReAlloc
WriteConsoleW
SetEndOfFile
CreateSymbolicLinkW
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
RtlUnwindEx
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
EncodePointer
RaiseException
RtlPcToFileHeader
GetCommandLineA
GetFileInformationByHandle
GetFileType
PeekNamedPipe
SystemTimeToTzSpecificLocalTime
FileTimeToSystemTime
ReadFile
GetFullPathNameW
SetStdHandle
GetStdHandle
WriteFile
ExitProcess
GetModuleHandleExW
HeapFree
GetConsoleMode
ReadConsoleW
SetFilePointerEx
GetConsoleOutputCP
GetFileSizeEx
HeapAlloc
GetCurrentDirectoryW
FlsAlloc
FlsGetValue
FlsSetValue
ADVAPI32.dll OpenProcessToken
GetTokenInformation
ConvertStringSecurityDescriptorToSecurityDescriptorW
ConvertSidToStringSidW
GDI32.dll SelectObject
DeleteObject
CreateFontIndirectW

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x6f3
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.85243
Detected Filetype PNG graphic file
MD5 290679c61b0a8db5941d25498c2b9503
SHA1 aafa7321140e17163fa8d31d6026503435033c81
SHA256 644b38ea2b7c870d3afd7122d54deab47ee6a4c277c5f74264e85dae84989281
SHA3 015508a778e2b5bb642e53654c7766a0101257163850c3e10b828b1306540804

1 (#2)

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.69546
Detected Filetype Icon file
MD5 b49113eee79b71dcd5092c70f86d1161
SHA1 600483622fc84e3d5f0fb70dc80138a2df038388
SHA256 8686104f462735bf639c5f400359d449ef276c4fbe781b5ff0d6b6574cb6c07c
SHA3 ca72da016c4cf0c6214433a1d8f8988b4331401dbd4d95d87d27c5d338295705

1 (#3)

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x310
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.42517
MD5 364118aa48bd359b1a59f303fbf20496
SHA1 0700a79a8f7ef2331672d25f0cbd72cf62c14283
SHA256 9fa4383949ad2b43d40e1baf23172f741c1a542a4e2bb28fe94e72695a994b13
SHA3 645d3eebd07bb5bbdd49c403b422ab2e5d715d7e3d55f3005f9f632fb83e1c44

1 (#4)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x50d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.25791
MD5 84da8dee6b319ea0b10b6de5489c6aae
SHA1 5f8991f3e065fd95614859a293f88b9c70e4bb23
SHA256 abf8f2022f12f350789d961aceaf9ccfd53e7ec58d8c9934cfce77779b4eac11
SHA3 08f0562915b54bedce5a84e9d32cb2efcc538268785103b1852338e20a3b4606

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2.6.5.0
ProductVersion 2.6.5.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Sims4Updater
FileDescription Sims 4 Updater (beta)
FileVersion (#2) 2.6.5.0
InternalName Sims 4 Updater (beta)
LegalCopyright Sims4Updater
OriginalFilename sims-4-updater-v2.6.5-beta.exe
ProductName Sims 4 Updater (beta)
ProductVersion (#2) 2.6.5.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-28 17:43:52
Version 0.0
SizeofData 816
AddressOfRawData 0x3e178
PointerToRawData 0x3cb78

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140042040
GuardCFCheckFunctionPointer 5368898744
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0xa6a371c3
Unmarked objects 0
C++ objects (33145) 183
C objects (33145) 12
ASM objects (33145) 11
253 (35207) 3
ASM objects (35207) 9
C objects (35207) 17
C++ objects (35207) 40
Imports (33145) 11
Total imports 159
C objects (35225) 27
Linker (35225) 1

Errors

Leave a comment

No comments yet.