cd55f7976ff35228c4fc53c06f4c42f5489d896702e1edb73f45f90888d62de3

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Sep-26 10:32:09
Detected languages Chinese - PRC
FileVersion 6.1.7601.17514
FileDescription Microsoft@ Windows@ Operating System
ProductName Microsoft@ Windows@ Operating System
ProductVersion 6.1.7601.17514
CompanyName Windows
LegalCopyright @ Microsoft Corportion ALL rights reserved
Comments Windows

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++
Microsoft Visual C++ v6.0
Suspicious PEiD Signature: UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX v2.0 -> Markus, Laszlo & Reiser (h)
UPX -> www.upx.sourceforge.net
UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Info Libraries used to perform cryptographic operations: Microsoft's Cryptography API
Suspicious The PE is packed with UPX Unusual section name found: UPX0
Section UPX0 is both writable and executable.
Unusual section name found: UPX1
Section UPX1 is both writable and executable.
Unusual section name found: .SCY
Section .SCY is both writable and executable.
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • FindWindowA
Code injection capabilities (PowerLoader):
  • FindWindowA
  • GetWindowLongA
Can access the registry:
  • RegCreateKeyExA
  • RegOpenKeyExA
  • RegOpenKeyA
  • RegQueryValueExA
  • RegCloseKey
  • RegSetValueExA
Possibly launches other programs:
  • CreateProcessA
Uses Microsoft's cryptographic API:
  • CryptHashData
  • CryptGetHashParam
  • CryptDestroyHash
  • CryptReleaseContext
  • CryptCreateHash
  • CryptAcquireContextA
Can create temporary files:
  • CreateFileW
  • CreateFileA
  • GetTempPathA
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • CallNextHookEx
Manipulates other processes:
  • OpenProcess
  • Process32Next
  • Process32First
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 2d4e939c1d57a72b5503970cbd459216 🔍
SHA1 d727b9525a1e0622c376701ac6a27552c9e37b6e 🔍
SHA256 cd55f7976ff35228c4fc53c06f4c42f5489d896702e1edb73f45f90888d62de3 🔍
SHA3 4c80e2db97fcdf916ae415ca9d6772c453918d49090d8b686bea28a69304f996 🔍
SSDeep 24576:NvdhRF5kX7TwzT+Xp9RPhnk3X6XJf9SZqDvPGW3IRCJzwcyahGYvzn4pGWv3vUv:NPU2RRCBwPanvL9e398SmsD5 🔍
Imports Hash 19a2f91f3993246ffe8b89b84a6d0d38 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2026-Sep-26 10:32:09
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0x14f000
SizeOfInitializedData 0x1000
SizeOfUninitializedData 0x50000
AddressOfEntryPoint 0x00024C39 (Section: UPX0)
BaseOfCode 0x51000
BaseOfData 0x1a0000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x1a3000
SizeOfHeaders 0x400
Checksum 0x1546ab
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

UPX0

MD5 bc3d8de179847ac3dc443bc2c54d1fda 🔍
SHA1 7def2ce9a10bf7030644f499a118dbeb920507c2 🔍
SHA256 668bb162b7943b549f9a679bbc1e06e998d6686028a45cd1e3dba966d97a6bbd 🔍
SHA3 aeb75f91507eb64927e1d6c06e07817fc321748988ab108dd90c9cf8871e8841 🔍
VirtualSize 0x50000
VirtualAddress 0x1000
SizeOfRawData 0x50000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.82346

UPX1

MD5 dc55ae4993f50e1f90477134f1972e17 🔍
SHA1 87685f270058e1ed0fe4e86b07b823aba0b48809 🔍
SHA256 6c885605c5907c04f2e2b2f5a8feee1dab876535c6c6895b315e8b4e79335dcd 🔍
SHA3 3ee51f022b8effb0649272ec2da295862d8ab85561e3e0800e40df6deeb34947 🔍
VirtualSize 0x14f000
VirtualAddress 0x51000
SizeOfRawData 0x14f000
PointerToRawData 0x50400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.80504

.rsrc

MD5 4b177a29399053e17078264097eb28cf 🔍
SHA1 605cae5c6ee440210fa9597a3e5a7bf8c044cc62 🔍
SHA256 6900181e1d49da3a03bed5759cf54b4b8c477512923a29a7a8d55743d7d7bd22 🔍
SHA3 43f5489c8f2a2b196bf1059bd2a438c795a1d877601d8a6cbfc123785e879805 🔍
VirtualSize 0x1000
VirtualAddress 0x1a0000
SizeOfRawData 0x800
PointerToRawData 0x19f400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.24704

.SCY

MD5 ca26a4b189fb8a41e48ee9404c818e0d 🔍
SHA1 48bcd48bbe9d75500a0633c68360a5fe9d49b7b1 🔍
SHA256 b1f8cdb7b5ea3079551c03177ebe93eaa898ad67818c3db1aa80c0ac80c40fe7 🔍
SHA3 958c06c7e383cee42c247a654bc70f5bf2885f44e12c5ea0642e351f629e81fe 🔍
VirtualSize 0x2000
VirtualAddress 0x1a1000
SizeOfRawData 0x1e00
PointerToRawData 0x19fc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.44983

Imports

advapi32.dll CryptHashData
RegCreateKeyExA
RegOpenKeyExA
RegOpenKeyA
RegQueryValueExA
RegCloseKey
CryptGetHashParam
CryptDestroyHash
CryptReleaseContext
CryptCreateHash
CryptAcquireContextA
RegSetValueExA
comctl32.dll InitCommonControls
gdi32.dll GetObjectA
Escape
ExtTextOutA
TextOutA
RectVisible
PtVisible
gdi32.dll (#2) GetObjectA
Escape
ExtTextOutA
TextOutA
RectVisible
PtVisible
kernel32.dll SetStdHandle
IsBadCodePtr
GetStringTypeW
GetStringTypeA
LCMapStringW
SetUnhandledExceptionFilter
IsBadWritePtr
VirtualAlloc
VirtualFree
HeapCreate
HeapDestroy
GetVersionExA
GetFileType
GetStdHandle
SetHandleCount
MultiByteToWideChar
GetEnvironmentStrings
FreeEnvironmentStringsW
FreeEnvironmentStringsA
UnhandledExceptionFilter
GetACP
HeapSize
RaiseException
RtlUnwind
GetCommandLineA
GetOEMCP
GetCPInfo
FlushFileBuffers
OpenEventA
CreateEventA
lstrcpynA
RtlMoveMemory
CreateThread
CreateProcessA
WaitForSingleObject
CloseHandle
GetShortPathNameA
GetWindowsDirectoryA
GetSystemDirectoryA
CreateFileW
GetFileTime
GetFileAttributesW
FileTimeToLocalFileTime
FileTimeToSystemTime
GetLocaleInfoA
GetDateFormatA
GetTimeFormatA
LeaveCriticalSection
InitializeCriticalSection
EnterCriticalSection
LCMapStringA
LoadLibraryA
GetProcAddress
FreeLibrary
GetTickCount
SetFilePointer
GetStartupInfoA
FindFirstFileA
RemoveDirectoryA
FindNextFileA
FindClose
GetLocalTime
GetEnvironmentVariableA
GetPrivateProfileStringA
GetFileAttributesA
WriteFile
Sleep
GlobalAlloc
GlobalLock
GlobalUnlock
GlobalFree
GetUserDefaultLCID
WideCharToMultiByte
CreateFileA
GetFileSize
ReadFile
GetModuleFileNameA
CreateDirectoryA
DeleteFileA
IsBadReadPtr
HeapFree
HeapReAlloc
HeapAlloc
ExitProcess
GetModuleHandleA
GetProcessHeap
TerminateProcess
OpenProcess
GetCurrentProcess
Process32Next
Process32First
CreateToolhelp32Snapshot
SetWaitableTimer
CreateWaitableTimerA
SetErrorMode
GetProcessVersion
FindResourceA
LoadResource
LockResource
GetVersion
GlobalGetAtomNameA
GlobalAddAtomA
GetEnvironmentStringsW
GetTempPathA
GlobalFindAtomA
GetLastError
GetCurrentThreadId
GetCurrentThread
lstrcmpiA
lstrcmpA
GlobalDeleteAtom
lstrlenA
LocalAlloc
LocalFree
TlsAlloc
DeleteCriticalSection
GlobalHandle
TlsFree
GlobalReAlloc
TlsSetValue
LocalReAlloc
TlsGetValue
lstrcpynA
MulDiv
GlobalFlags
InterlockedDecrement
WritePrivateProfileStringA
lstrcatA
lstrcpyA
InterlockedIncrement
SetLastError
oleaut32.dll VariantInit
SafeArrayAllocDescriptor
SafeArrayAllocData
SafeArrayGetDim
SafeArrayGetLBound
SafeArrayGetUBound
SafeArrayAccessData
SafeArrayUnaccessData
SafeArrayGetElemsize
SysFreeString
VarR8FromCy
VarDateFromBool
VariantChangeType
LoadTypeLib
LHashValOfNameSys
RegisterTypeLib
VariantCopy
SafeArrayCreate
SysAllocString
VariantClear
SafeArrayDestroy
VariantTimeToSystemTime
SystemTimeToVariantTime
shell32.dll SHGetSpecialFolderLocation
SHGetPathFromIDListA
shlwapi.dll PathIsDirectoryW
PathFileExistsA
PathFindExtensionA
user32.dll FindWindowA
MsgWaitForMultipleObjects
DispatchMessageA
TranslateMessage
PeekMessageA
WaitForInputIdle
ClientToScreen
PostMessageW
FindWindowExA
user32.dll (#2) FindWindowA
MsgWaitForMultipleObjects
DispatchMessageA
TranslateMessage
PeekMessageA
WaitForInputIdle
ClientToScreen
PostMessageW
FindWindowExA
user32.dll (#3) FindWindowA
MsgWaitForMultipleObjects
DispatchMessageA
TranslateMessage
PeekMessageA
WaitForInputIdle
ClientToScreen
PostMessageW
FindWindowExA
user32.dll (#4) FindWindowA
MsgWaitForMultipleObjects
DispatchMessageA
TranslateMessage
PeekMessageA
WaitForInputIdle
ClientToScreen
PostMessageW
FindWindowExA
user32.dll (#5) FindWindowA
MsgWaitForMultipleObjects
DispatchMessageA
TranslateMessage
PeekMessageA
WaitForInputIdle
ClientToScreen
PostMessageW
FindWindowExA
user32.dll (#6) FindWindowA
MsgWaitForMultipleObjects
DispatchMessageA
TranslateMessage
PeekMessageA
WaitForInputIdle
ClientToScreen
PostMessageW
FindWindowExA
user32.dll (#7) FindWindowA
MsgWaitForMultipleObjects
DispatchMessageA
TranslateMessage
PeekMessageA
WaitForInputIdle
ClientToScreen
PostMessageW
FindWindowExA
user32.dll (#8) FindWindowA
MsgWaitForMultipleObjects
DispatchMessageA
TranslateMessage
PeekMessageA
WaitForInputIdle
ClientToScreen
PostMessageW
FindWindowExA
winspool.drv DocumentPropertiesA
ClosePrinter
OpenPrinterA
ole32.dll OleIsCurrentClipboard
OleFlushClipboard
CoRevokeClassObject
CoRegisterMessageFilter
CoFreeUnusedLibraries
OleUninitialize
OleInitialize
CoInitialize
CoUninitialize
OleRun
CoCreateInstance
CLSIDFromString
CLSIDFromProgID
oledlg.dll OleUIBusyA

Delayed Imports

1

Type RT_VERSION
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x314
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44231
MD5 792882fa87c7a75b66440a4762b52f10 🔍
SHA1 998a7481367a39d3486dfce7e20eda4307655d46 🔍
SHA256 38587b1d9025cc0c31bb5e325f492f80de5233d55a0e04becb6c5dc3c12dc09d 🔍
SHA3 f5aa126000166bf2385b52c319e93f93f41a79d38e6d7f7147fd52c5dae64fb1 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0
FileVersion 6.1.7601.17514
ProductVersion 6.1.7601.17514
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language Chinese - PRC
FileVersion (#2) 6.1.7601.17514
FileDescription Microsoft@ Windows@ Operating System
ProductName Microsoft@ Windows@ Operating System
ProductVersion (#2) 6.1.7601.17514
CompanyName Windows
LegalCopyright @ Microsoft Corportion ALL rights reserved
Comments Windows
Resource LangID Chinese - PRC

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x3b5e7537
Unmarked objects 0
12 (7291) 1
C objects (VS2003 (.NET) build 4035) 6
14 (7299) 31
C objects (VS98 SP6 build 8804) 137
Imports (VS2003 (.NET) build 4035) 25
Total imports 495
C++ objects (VS98 SP6 build 8804) 164
Unmarked objects (#2) 1
C++ objects (VS98 build 8168) 2

Errors

Leave a comment

No comments yet.