c13c799859df2613d22405805f5bc0abccb57fdcde24a23ec99418de87570223

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 1970-Jan-01 00:00:00
Debug artifacts Embedded COFF debugging symbols

Plugin Output

Suspicious PEiD Signature: HQR data file
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Suspicious The PE is possibly packed. Unusual section name found: .vers
Unusual section name found: .xdata
Unusual section name found: /4
Unusual section name found: /19
Unusual section name found: /32
Unusual section name found: /46
Unusual section name found: /65
Unusual section name found: /78
Unusual section name found: /95
Unusual section name found: /112
Unusual section name found: .junk
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • LoadLibraryExW
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Malicious VirusTotal score: 5/72 (Scanned on 2026-04-12 15:09:49) Bkav: W64.AIDetectMalware
CrowdStrike: win/malicious_confidence_60% (D)
Elastic: malicious (moderate confidence)
Gridinsoft: Trojan.Heur!.0201212F
Trapmine: malicious.high.ml.score

Hashes

MD5 c815614efd29dd521634afc3f79c8aaa
SHA1 4a6753230f4e730ba758a5a7fe0a4a98bcb95da8
SHA256 c13c799859df2613d22405805f5bc0abccb57fdcde24a23ec99418de87570223
SHA3 010a4ddcfe3e0359db5c9076b3ee6d60cceb08a973d1324dfad79a765e94e7c2
SSDeep 49152:F7nvMmrcHnDPxozNcVJX6sOi3DblqivZC+ATjLGwB:F7kyMFVhlqivZZATj
Imports Hash d42595b695fc008ef2c56aabd8efd68e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0x8b
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 16
TimeDateStamp 1970-Jan-01 00:00:00
PointerToSymbolTable 0x2ff600
NumberOfSymbols 3366
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 3.0
SizeOfCode 0xf6800
SizeOfInitializedData 0x13200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000749E0 (Section: .code)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 1.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0x378000
SizeOfHeaders 0x600
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.code

MD5 4be6d5a98fe63b49fdfd735ccd2d6138
SHA1 32db5b2a1df37428eebc5913d931d622fa079a3f
SHA256 76b777118b3107713eb5d26f5df228b19413cc865a97cb521410cb476d036411
SHA3 bb2dd1327c3a50a0c9d5577d28d4f99e26232d423423503529ca289ca8698320
VirtualSize 0xf67d1
VirtualAddress 0x1000
SizeOfRawData 0xf6800
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.28277

.rsrc

MD5 73ad213ccc72caee1b6dfe7415be083a
SHA1 de3e45274ffbafe374bdab25e84e81a8b23868e8
SHA256 2c07ea64f53c27a1dd590ca6e257d31b3c24adec02379002e8bf3ba3f33a355d
SHA3 429ae6ffa07ac402e03d6b74cbec39bd99fad19958d8f7944566ee8a883cce56
VirtualSize 0x11c0e0
VirtualAddress 0xf8000
SizeOfRawData 0x11c200
PointerToRawData 0xf6e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.43603

.vers

MD5 a15f66b71ffdee801f7d5750879803e8
SHA1 182974ab3e4b20d668284fb66b5405c20b8cab4b
SHA256 8a92244feb1127e6de867ae7dcbc2bc796a616a41963c8235ed04ead9591c152
SHA3 f63cb437da71147100d616f1828b83d06c7a049d8e1ac6648dcb76feddd8d239
VirtualSize 0x5c828
VirtualAddress 0x215000
SizeOfRawData 0x13200
PointerToRawData 0x213000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.79377

.pdata

MD5 3b064574474910855dce562fdb7295a8
SHA1 1174bdedc77874316965526d30903427ad3cf3ea
SHA256 07a4937c67d6f6b2b848ba8192cfb3f325ac41e14a28e88ef60c2e4c99576294
SHA3 412d6c49ae4755847a21b3780d97f01d125cb54420c8566f5b7be6dee23c77ab
VirtualSize 0x6aec
VirtualAddress 0x272000
SizeOfRawData 0x6c00
PointerToRawData 0x226200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.27142

.xdata

MD5 14cdf26ed307bfbee4b6ecc940d27b11
SHA1 439811f3a542c1ec54ca8159e24d0fd2e1ab1ab3
SHA256 5b5e56c5f2ee61d501cc09cd7eae428b9212f67a768cccdedaf86d1eab71a6ad
SHA3 7b4f4aae6fdac0be420fcbfa83ed680264c5add7b419e79ee678effb21e1acf6
VirtualSize 0xb4
VirtualAddress 0x279000
SizeOfRawData 0x200
PointerToRawData 0x22ce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.78321

/4

MD5 bcddef00414a946919302442928e542e
SHA1 b0fbeae40093e8241edcbdeae94ba06880dedf04
SHA256 fb7bf682d27ba8920146a9b134a183cd2109b202916488b9b3a4f7d623f0b484
SHA3 7d5b252590738bde977b6dfab9c3034c2ad82b952980a3585c1dc88e1f06f005
VirtualSize 0x154
VirtualAddress 0x27a000
SizeOfRawData 0x200
PointerToRawData 0x22d000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.67257

/19

MD5 f0d8b4b6a1a1cfc2a45b15c814f9110c
SHA1 ea4ba1b25434fab6605c1a47d3d44f548771e891
SHA256 30704d472866967a5086e67dd4cfc5b4334b37d3271138dd6f4c82345526e7d4
SHA3 02e74915371813096a758a8e9bd33aa7bb83caa3b68d7c477ab534a1a31a20a9
VirtualSize 0x314f9
VirtualAddress 0x27b000
SizeOfRawData 0x31600
PointerToRawData 0x22d200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.99375

/32

MD5 fb4cfe5390d1ba3f67222e1da1aac5cb
SHA1 9ee04508ef1f22d7c7201f5db34631ef943849f6
SHA256 d891a6eee33479b29923f4ba6e3ab9f6e4b42d1003eded3e61316d975e2d8e8f
SHA3 51705d7e949ef74618fe5304e41f9cf75d91f60d15f2548a6915775290f70a00
VirtualSize 0x9a66
VirtualAddress 0x2ad000
SizeOfRawData 0x9c00
PointerToRawData 0x25e800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.9174

/46

MD5 40cca7c46fc713b4f088e5d440ca7931
SHA1 3aaa1650bfaf5325fa9cb3a1a284aebcc92aebf4
SHA256 3e3c5f5d419b70e588da0ef0e3d9ce1a5863a5624febc16cd0c007cd14e89015
SHA3 a0e18fe9f6ac46417d52cdc99cf9ae56edb5a53f788995a085b10f88f348a0e4
VirtualSize 0x30
VirtualAddress 0x2b7000
SizeOfRawData 0x200
PointerToRawData 0x268400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.855685

/65

MD5 c7908c2446b9326a62021a061cf54c6d
SHA1 e4bf8cc3cfc26b2b72d433c2ebac96aa03422928
SHA256 9931ea91791c8aa041a4658f34cabe0d10dfb77c0ae885605c7ad6ad19a67eac
SHA3 db41fbfbdeec50ff942fde87b9dd7a6d3f224f8f33d6a8aa9ca01030d4988083
VirtualSize 0x55e33
VirtualAddress 0x2b8000
SizeOfRawData 0x56000
PointerToRawData 0x268600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.99773

/78

MD5 3b1794294d542a8513b329639f25ec5c
SHA1 747eb650e7f31c686de6618783b2720918807c1b
SHA256 54cb4ebe942ef7279c4c7832d532d07ee1aabe957028ecd4730ce8c98002a7c1
SHA3 5fff273391bbfb8cf55a9cbbef98c8bf7c1d3ebdc78e8b8089d99f57b5cd28f7
VirtualSize 0x25a83
VirtualAddress 0x30e000
SizeOfRawData 0x25c00
PointerToRawData 0x2be600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.99566

/95

MD5 27e06deb53a5b559729ab5e615b9e3eb
SHA1 d9c0690780cfab36e0091aba31e486ae2b289072
SHA256 bd7c31c4850ed23579b2b8e1511cf701b4736117c9a0d133e9dbb4dffed8a19b
SHA3 2a5cd6fd0fd9412da836578f4ddfb3d33173ce2fa8ab6baabf6df6e335265fd6
VirtualSize 0x139da
VirtualAddress 0x334000
SizeOfRawData 0x13a00
PointerToRawData 0x2e4200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.99335

/112

MD5 853bc3ff82841c07b36c5de2aa8e05d7
SHA1 86d7971345c0f24458bf710de6d44f4fb6fcfeb3
SHA256 afef9f485cff81d4675760e75439881b57dc9f39207244a22b4701a977251325
SHA3 4f774b93d3d44c2ef53eeaa4489c54a97ee10ffb54f50d33aef1f0eb94ae3951
VirtualSize 0x1562
VirtualAddress 0x348000
SizeOfRawData 0x1600
PointerToRawData 0x2f7c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.72306

.idata

MD5 2b169a44021e4ff17856a6d4d45e98ec
SHA1 7cb0028847b61bd1e99d5c53d0986f298908ee35
SHA256 ef934699af55633703f7c12473b9cc67436acd4bab7b9f578a6210a9f1a3e684
SHA3 b0edc24de0ca9727b86d7f785ac0c7f3e51a6eaa92b21b27d6b342fa89965d95
VirtualSize 0x53e
VirtualAddress 0x34a000
SizeOfRawData 0x600
PointerToRawData 0x2f9200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.00977

.reloc

MD5 f406ba36a9711b97c305c803bf0d65bc
SHA1 46ccd95b6f6d72f8a23daf6d9ea70eee74b18520
SHA256 d75e4d354be26e7c61a1b8b80099ae1752ed04dc4533d3f527d2f562226417f5
SHA3 72b09b72db8cf599a9df143c64af453cd88bf1ba6b7dc8af545f408f45363dc9
VirtualSize 0x5d08
VirtualAddress 0x34b000
SizeOfRawData 0x5e00
PointerToRawData 0x2f9800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.42309

.junk

MD5 b77f0d4a54d9f08968af021d46d8c520
SHA1 5b612d964285dfdaacd654ca14153798046556e5
SHA256 72e7abb09ce943cb5a855ca9957549406c50a38b8e1194806e00b52b3b4eb328
SHA3 461121ad15da52526b4652262584a0e46ea2cef00ac9f888ed63aa51e6132300
VirtualSize 0x26489
VirtualAddress 0x351000
SizeOfRawData 0x26600
PointerToRawData 0x2ff600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.23267

Imports

kernel32.dll WriteFile
WriteConsoleW
WerSetFlags
WerGetFlags
WaitForMultipleObjects
WaitForSingleObject
VirtualQuery
VirtualFree
VirtualAlloc
TlsAlloc
SwitchToThread
SuspendThread
SetWaitableTimer
SetProcessPriorityBoost
SetEvent
SetErrorMode
SetConsoleCtrlHandler
RtlVirtualUnwind
RtlLookupFunctionEntry
ResumeThread
RaiseFailFastException
PostQueuedCompletionStatus
LoadLibraryW
LoadLibraryExW
SetThreadContext
GetThreadContext
GetSystemInfo
GetSystemDirectoryA
GetStdHandle
GetQueuedCompletionStatusEx
GetProcessAffinityMask
GetProcAddress
GetErrorMode
GetEnvironmentStringsW
GetCurrentThreadId
GetConsoleMode
FreeEnvironmentStringsW
ExitProcess
DuplicateHandle
CreateWaitableTimerExW
CreateThread
CreateIoCompletionPort
CreateEventA
CloseHandle
AddVectoredExceptionHandler
AddVectoredContinueHandler

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

RICH Header

Errors

[*] Warning: Tried to read outside the COFF string table to get the name of section /4! [*] Warning: Tried to read outside the COFF string table to get the name of section /19! [*] Warning: Tried to read outside the COFF string table to get the name of section /32! [*] Warning: Tried to read outside the COFF string table to get the name of section /46! [*] Warning: Tried to read outside the COFF string table to get the name of section /65! [*] Warning: Tried to read outside the COFF string table to get the name of section /78! [*] Warning: Tried to read outside the COFF string table to get the name of section /95! [*] Warning: Tried to read outside the COFF string table to get the name of section /112!
Leave a comment

No comments yet.