c94845b8e1a4f5feac082ae216c01f5b9d7971dbea03a32f740bc06910a4ffe3

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2021-Dec-04 09:14:19
Detected languages English - United States

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • http://nsis.sf.net
  • http://nsis.sf.net/NSIS_Error
  • nsis.sf.net
Suspicious The PE is an NSIS installer Unusual section name found: .ndata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Can access the registry:
  • RegCloseKey
  • RegCreateKeyExW
  • RegDeleteKeyW
  • RegDeleteValueW
  • RegEnumKeyW
  • RegEnumValueW
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegSetValueExW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Changes object ACLs:
  • SetFileSecurityW
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 80054 bytes of data starting at offset 0x27800.
The overlay data has an entropy of 7.99034 and is possibly compressed or encrypted.
Malicious VirusTotal score: 4/69 (Scanned on 2026-06-30 07:18:07) CrowdStrike: win/malicious_confidence_60% (W)
Cylance: Unsafe
Jiangmin: Trojan.CMY3U.qd
Trapmine: suspicious.low.ml.score

Hashes

MD5 457ef6aaf9842917071dbd6f2c111b15
SHA1 af94053f060b1e9e07e88c1b028e9fa8bf5c0af2
SHA256 c94845b8e1a4f5feac082ae216c01f5b9d7971dbea03a32f740bc06910a4ffe3
SHA3 4818844adceec47a2eb7f9fb2fa75e3b1681df2bd7a3b8ec427570950131deb1
SSDeep 3072:T7TPzhqY0Oy76XjTKIkAf+5UjQ2YZH3y/7SkdnItrnWlnHfzrLHXklLHw:nTPlqYXi6auQt2gXzQIxnIfz/XkVw
Imports Hash 96ab939b3b55d317ed1968d099ccc72c

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 8
TimeDateStamp 2021-Dec-04 09:14:19
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x9400
SizeOfInitializedData 0xbe00
SizeOfUninitializedData 0x2ac00
AddressOfEntryPoint 0x00004506 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xb000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 6.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x77000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 2ad7da982d288ab69df2d237fff5f625
SHA1 2a983de683e03a3de863d7511f1152902b5be7c4
SHA256 554a49d9925a393347633a7f8a9c2ca0602130d0726026f5a09665bd7a470944
SHA3 e4b1b951ed4fa2bb4225cea3bf94b219bf87bc0e906d87cc93e971043bd4f534
VirtualSize 0x93a8
VirtualAddress 0x1000
SizeOfRawData 0x9400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.05048

.data

MD5 8dba9937bb5bb5b6f88fc0101b48492a
SHA1 9e6069db24a6651838da1158e55f7e099929887b
SHA256 38a9fddb04ff44d0ce22261d43b7cf83c4655a1cd36bcaf711c3dc23edc62036
SHA3 a05e22e7d3877998f3b354c70aa9ca05aa4ade9e705cacc1f8c7332ab9ab2626
VirtualSize 0xe8
VirtualAddress 0xb000
SizeOfRawData 0x200
PointerToRawData 0x9800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.50528

.rdata

MD5 1f8eb2cf297509a259cdf689127e9ad8
SHA1 6ca52263e2da679c8a6c4487dff451ec80f70594
SHA256 e94717ba427e7bb37bc07007c828d479bccb4f4368fb19417bda28d2e0ef44f1
SHA3 2dd2211e77e92fe21ea5eea4526a6086e6c037cf5e9d8e90b1be25ae00ef60f6
VirtualSize 0x895c
VirtualAddress 0xc000
SizeOfRawData 0x8a00
PointerToRawData 0x9a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.07211

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x2ab20
VirtualAddress 0x15000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 acbb7073d11d221621af7b1628be82ef
SHA1 1e8c87da33db1a4091178113c61bca11bf10f7a3
SHA256 62a8aa89730cb4317caa4ecfac565cf6131ef61d3ef990c66835659f0e758c7d
SHA3 92b18c34bf6a1a0a41094c49907e4277abb89afa9aab7250d5172a4745a73257
VirtualSize 0x13fc
VirtualAddress 0x40000
SizeOfRawData 0x1400
PointerToRawData 0x12400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.31212

.ndata

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x20000
VirtualAddress 0x42000
SizeOfRawData 0x200
PointerToRawData 0x13800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 f334c5d84ce8575768b51612210dc484
SHA1 47f40cdae26ca68481af1035648d3024c886a096
SHA256 51099cde74ead5f91c38e468e8570426a1fbb3d422efb0830fcee31e826eed40
SHA3 d1579940f25efacb64bfc2babece40b3dde70cfdb19e7a5ac7f5273818f66b9a
VirtualSize 0x13c50
VirtualAddress 0x62000
SizeOfRawData 0x13e00
PointerToRawData 0x13a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.51512

.reloc

MD5 e4766cc3f5cf2354068bb1b9b7b885b9
SHA1 609a43d99e26cba0a497733289b00b92376ffe60
SHA256 36cc5eeaaed2fac8bd13154cc3a6f614d013ed22cf9bda98be6d035f21eb2a6b
SHA3 d13e251a2a0b26ae3e1d867f1de6db0d716746f0bf46eb53396ee19704fa6fef
VirtualSize 0x8e4
VirtualAddress 0x76000
SizeOfRawData 0xa00
PointerToRawData 0x14c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 2.22609

Imports

ADVAPI32.dll AdjustTokenPrivileges
LookupPrivilegeValueW
OpenProcessToken
RegCloseKey
RegCreateKeyExW
RegDeleteKeyW
RegDeleteValueW
RegEnumKeyW
RegEnumValueW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
SetFileSecurityW
COMCTL32.DLL ImageList_AddMasked
ImageList_Create
ImageList_Destroy
InitCommonControls
GDI32.dll CreateBrushIndirect
CreateFontIndirectW
DeleteObject
GetDeviceCaps
SelectObject
SetBkColor
SetBkMode
SetTextColor
KERNEL32.dll CloseHandle
CompareFileTime
CopyFileW
CreateDirectoryW
CreateFileW
CreateProcessW
CreateThread
DeleteFileW
ExitProcess
ExpandEnvironmentStringsW
FindClose
FindFirstFileW
FindNextFileW
FreeLibrary
GetCommandLineW
GetCurrentProcess
GetDiskFreeSpaceW
GetExitCodeProcess
GetFileAttributesW
GetFileSize
GetFullPathNameW
GetLastError
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
GetPrivateProfileStringW
GetProcAddress
GetShortPathNameW
GetSystemDirectoryW
GetTempFileNameW
GetTempPathW
GetTickCount
GetVersionExW
GetWindowsDirectoryW
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
LoadLibraryExW
MoveFileExW
MoveFileW
MulDiv
MultiByteToWideChar
ReadFile
RemoveDirectoryW
SearchPathW
SetCurrentDirectoryW
SetEnvironmentVariableW
SetErrorMode
SetFileAttributesW
SetFilePointer
SetFileTime
Sleep
WaitForSingleObject
WideCharToMultiByte
WriteFile
WritePrivateProfileStringW
lstrcatW
lstrcmpW
lstrcmpiA
lstrcmpiW
lstrcpyA
lstrcpynW
lstrlenA
lstrlenW
ole32.dll CoCreateInstance
CoTaskMemFree
IIDFromString
OleInitialize
OleUninitialize
SHELL32.dll SHBrowseForFolderW
SHFileOperationW
SHGetFileInfoW
SHGetPathFromIDListW
SHGetSpecialFolderLocation
ShellExecuteExW
USER32.dll AppendMenuW
BeginPaint
CallWindowProcW
CharNextA
CharNextW
CharPrevW
CheckDlgButton
CloseClipboard
CreateDialogParamW
CreatePopupMenu
CreateWindowExW
DefWindowProcW
DestroyWindow
DialogBoxParamW
DispatchMessageW
DrawTextW
EmptyClipboard
EnableMenuItem
EnableWindow
EndDialog
EndPaint
ExitWindowsEx
FillRect
FindWindowExW
GetClassInfoW
GetClientRect
GetDC
GetDlgItem
GetDlgItemTextW
GetMessagePos
GetSysColor
GetSystemMenu
GetSystemMetrics
GetWindowLongW
GetWindowRect
InvalidateRect
IsWindow
IsWindowEnabled
IsWindowVisible
LoadCursorW
LoadImageW
MessageBoxIndirectW
OpenClipboard
PeekMessageW
PostQuitMessage
RegisterClassW
ReleaseDC
ScreenToClient
SendMessageTimeoutW
SendMessageW
SetClassLongW
SetClipboardData
SetCursor
SetDlgItemTextW
SetForegroundWindow
SetTimer
SetWindowLongW
SetWindowPos
SetWindowTextW
ShowWindow
SystemParametersInfoW
TrackPopupMenu
wsprintfA
wsprintfW

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.54144
MD5 50ca370da186988f70c565bc7aef2609
SHA1 f4acb2e6ba9a7097bace3f84af15c84a5e387c3e
SHA256 db9bf8826101522c1e2861b5233fe394b69b99b7711ae7daaa977a644647cdc0
SHA3 e239f39cda3855f370b485acf8f85587de95587d44b79eeeed8b27d2e0aa6efa

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.21095
MD5 669e380ccf9a373e8c2f29a3140356e1
SHA1 70a69703db4d08e48c29001c35982101ecb063a1
SHA256 8896efe252635b941f1e9b1a9c2decf1159653ec6110c60264ebe91bb04f5581
SHA3 39e1401e3ad1c7571e76106b43d9deb275126bb489565439cfcaae2de77ce4c1

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 28f8d082df931688124f25f23c688904
SHA1 2f057655ecdd3ab25cfe985714e270786ce16cae
SHA256 4e7a8c59942ff527ff680aa88cc66bb8c8e7b6c02a018bc85ba36794e278670f
SHA3 99f004163a598b6df87372bd9b7d5e7704dbfdf7cfb3ec96da9e31c0275f7465

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 a42b23f1c58701e073db2e9de0b27333
SHA1 f22232cbadff165ceb212527a6d77124312d0688
SHA256 e253c6a87bdd62e771c0ef1b9850dbc9523c51408ca282f994d3530dbbad9b11
SHA3 bc93a26ac3218cac12b89fa3242b509e44b087d2c22a54d9a47c63692dc8dc57

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 7e1b34650fb04bc15a494a1d712cffee
SHA1 43e1808e4308baf093556946552f4fabc05278d8
SHA256 3731b0a75ab19d96b774da62d37eccacd517c6593af20aa66525dc0b951cdba9
SHA3 79a9c096a1a56ae4f98f1e8ad4c44fa5c08e5d98e745898df9031e3b3a13c46c

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 809457c05fe696f5d34ac5ac8768cdd4
SHA1 a2c3e4966415100c7d24f7f3dc7e27d2a60d20c9
SHA256 1b66520d471367f736d50c070a2e2bba8ad88ac58743394a764b888e9cb6f6be
SHA3 002d1b10f28d74c7572fc7c5b403eb32f2a0540c4958d7878ef67edfd17c8109

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 982079681d7ad12766abc44f06946f3e
SHA1 50f73ed0787bf5911bb907e487efbc84a9714e48
SHA256 250f52cb2d6f1966a29f6ac771fa1cd185b8f8531396c8a4026c0fe635617e0c
SHA3 b8805d45012d79cfa8bb45e23c9b4a4421cd91538d569e58437efa0f545cf4d4

103

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x144
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62375
MD5 1d958df872e65e9a04f929c89155e3f3
SHA1 5fff638c5caa7a6f598bfbafd8d8e7fe4f5764cd
SHA256 e6065cad9c0f4a4c7ec1de33c05b192b04cb96ad6cfb0e2ae0188fcaea6ea7c3
SHA3 b29b01b665ef63d2e0f362ce3bf145b41d860ddb989398de87df16d48ac8483b

105

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x23e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.72007
MD5 4e06b9c226906d7d31f90453697d36c0
SHA1 5d9a8b5dd5fe583227a0ab81fba83d98c4eb5452
SHA256 4b8679b0520596391355fd3b18c8b5979337aaa321c322f951fde6c053a6d845
SHA3 c3546d405a8722220c4e5652e54350941e3f2cadc30fdfc258fe377d9fef6354

106

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x104
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.84976
MD5 b756cf50afdc5a248bf9f3ff865177a6
SHA1 267b0f95a9f852b7af09e5d909a3febc24ca3ccb
SHA256 c47426270cabd4199bbff8e4fc363265990a8a935c023a8c7d6597a0378e5f5f
SHA3 1fb62d573cc8b6fdf137fd2c44249ba4f1c6d687bd878a786a395448d6069438

111

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.85529
MD5 f90fecb69f0cde5d64f508884dcb0404
SHA1 4baf5e55965823176fa6910a5ec9fdca077995f9
SHA256 45ac0526fc85b64bcbb69ca682b0ca4d866a5e42709deaed11ce79395fec63d7
SHA3 8e5819e3997885152c58d0ec124c1b14288188081f3719777d414d72f5b13e5a

103 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.08365
Detected Filetype Icon file
MD5 aa356c6c4e779ee9cd23c9f09cc48e70
SHA1 749ecd994cb139284ba638fecee71f4db63e2667
SHA256 65392e6df5bc488e4dd6ea9518052f136a762d6d730059acb51d909159bde258
SHA3 f10d15b3ba4d474c0173067b7ef6a4be9ad01ff509ea6d3c87816161b9086ac8

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x430
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.28979
MD5 f6a268513f51ae213ae8e5c833aa607d
SHA1 f07a9bbb38b22c5b37d06ab0cace35f99d0de3fd
SHA256 7eeaa40711ad2ee848189dde8331562fa61c1f14d23832bca6969a5f15dc6320
SHA3 1367e956e4a4df1882433278467f30903b84b765cc9bef77d8ac3d23c0169eaf

Version Info

TLS Callbacks

Load Configuration

RICH Header

Errors

[!] Error: Could not read an IMAGE_BASE_RELOCATION! [*] Warning: Section .bss has a size of 0!
Leave a comment

No comments yet.