d1e4ae0b27eb3afd660fc6d05d816c16

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 1970-Jan-01 00:00:00
Debug artifacts Embedded COFF debugging symbols

Plugin Output

Suspicious PEiD Signature: HQR data file
Info Interesting strings found in the binary: Contains domain names:
  • .eq.runtime.net
  • eq.runtime.net
  • runtime.net
  • type..eq.runtime.net
Suspicious The PE is possibly packed. Unusual section name found: /4
Unusual section name found: /19
Unusual section name found: /32
Unusual section name found: /46
Unusual section name found: /65
Unusual section name found: /78
Unusual section name found: /90
Unusual section name found: .symtab
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryW
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 d1e4ae0b27eb3afd660fc6d05d816c16
SHA1 7b3bbec66a9afbf74e32559cc971b25ae0797bd4
SHA256 d55e0e4685f3abf4860f17dda0f9780fbc2593781eacce1e8549e9122ecd4685
SHA3 20b9dd986c6416fb2daf0902b81d004503f45a54eb37d18dfa7a22e8f6e1f085
SSDeep 24576:Wy5jYnRxJlK8NWhcplo8+bU1+lWXz4KtDpF11Vgyj7HV:WyGRNKsx48+bU1+l/Kt1Fayn1
Imports Hash 4035d2883e01d64f3e7a9dccb1d63af5

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0x4
e_cparhdr 0
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0x8b
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 13
TimeDateStamp 1970-Jan-01 00:00:00
PointerToSymbolTable 0x1eca00
NumberOfSymbols 2389
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 3.0
SizeOfCode 0xa8600
SizeOfInitializedData 0x15600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000067480 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 1.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0x255000
SizeOfHeaders 0x600
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 6b2e14c86599d752692881d5095e7be9
SHA1 99d68895e51f0085a0a13e18490fe290cdb91222
SHA256 af91b830d7f982350fb2bc635ec2eb904fdede74bd79855ffbad693c7e7e5a51
SHA3 56609cb4008fe2fea67a0d9562e1182fbe883d77c6b489ea0a150d5099f571b5
VirtualSize 0xa8558
VirtualAddress 0x1000
SizeOfRawData 0xa8600
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.92696

.rdata

MD5 7df5ce6eb04d9fd1fb8172ded44a387f
SHA1 56a4492679dd7e9051bc443594cba6c5a49bf076
SHA256 d9366e625c942cb9750f1ddbc98f3a66fb57235bdb26a1e3bc60600466f2d7c8
SHA3 d2c0a16e8f2e61093993507e9f3b215ee4a141957d359a53ff0e230db3a74da1
VirtualSize 0xab750
VirtualAddress 0xaa000
SizeOfRawData 0xab800
PointerToRawData 0xa8c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.24155

.data

MD5 5be70ef46dcbdaf470435b79ee6c27dc
SHA1 687da0290da39315ddc6fcca74ad8532022727b1
SHA256 fac7c7370ffc0be16e3038a0cd9623dcd182c9ca418faf9cc3504636fa776c42
SHA3 4dc14daa98f6fc8b0bf04940e35686b4a2823d4f002a7607ad4ecda4d4481ed2
VirtualSize 0x5e4b0
VirtualAddress 0x156000
SizeOfRawData 0x15600
PointerToRawData 0x154400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.02756

/4

MD5 28a3e9c96b9bb43e6541a26c8f68899b
SHA1 d5055422d0b8c4494eb8e58fccfc0c1ceafbeed3
SHA256 975598b01533b812dcfde96cc17be963bfef2aff01d84eeec67fa3f71e2f0658
SHA3 af7ac55943731d23db6ba4a312b7176306d760c6f0209d7f9ff38da1a33fdcce
VirtualSize 0x119
VirtualAddress 0x1b5000
SizeOfRawData 0x200
PointerToRawData 0x169a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.82922

/19

MD5 9dde9da64037b4e3ca1f580aa342444a
SHA1 c9ee12840ce3a2aecc3bb1b2a137dc034f55aacf
SHA256 8269250d4af77c9df9a4964c7a4f5d055769ebfb961df207c7160c2ad1f99736
SHA3 3a9113a5f0d9998132086ee0f72a6105215316fec2229df170cdc7951f5dae3d
VirtualSize 0x1e06d
VirtualAddress 0x1b6000
SizeOfRawData 0x1e200
PointerToRawData 0x169c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.99398

/32

MD5 06713bfb798ac6f923b8a94ac83be5d6
SHA1 9a0dd20a7a99b4dd78f4f2ec5035197fd1bd3763
SHA256 5d19c2f271696bac21a35504a29dfabfa56f2b79b424eefffc606ac1c69109ee
SHA3 17df0453fc289936008cdf0356d44684a2cd9b9a99fbce1a532baa13667293e8
VirtualSize 0x5d90
VirtualAddress 0x1d5000
SizeOfRawData 0x5e00
PointerToRawData 0x187e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.92677

/46

MD5 14cea2cfeea2e401f94846319c93e309
SHA1 d64ff3036d2acf5e6324a5671ad4f1a1cdb42c5c
SHA256 46e6a74fb0dd7780004d5d55ff89cdea196ff3861f781696bcd89e59e0319dbe
SHA3 149751d60965cc38dc25f6b263997ab6d2d28bc8cc968a674c940d5584fca030
VirtualSize 0x46
VirtualAddress 0x1db000
SizeOfRawData 0x200
PointerToRawData 0x18dc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.16233

/65

MD5 a2781619136cd834003bb9c5f4061a0f
SHA1 a7da9d9bf25d598e35ddb1d185448c31e312d3f3
SHA256 3e3c4c309f40634641376b3e4e35dfe1e6018cfdb3235ea5a5e20d3d69518cb9
SHA3 ccae5d6a490c5aebb4a824cffee3842aa3bf40525a2a6be04a11861d9ffb6e6c
VirtualSize 0x33e86
VirtualAddress 0x1dc000
SizeOfRawData 0x34000
PointerToRawData 0x18de00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.9956

/78

MD5 f3cf0a89e47fd9a0e8f43166d150fd4c
SHA1 2f1eb81b9ca20c9ea428fe628e091d6f341560a1
SHA256 cdda113b55d991792f0be5388c56f536855d3d338a55e4d7dc2fcddeed0da958
SHA3 3d66d7c31f607007de2b166fa8feb9274589c03ba525abe3aadfc08ede283c99
VirtualSize 0x1926f
VirtualAddress 0x210000
SizeOfRawData 0x19400
PointerToRawData 0x1c1e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.99076

/90

MD5 0dc6ca70315facb34796bbfcd0298e24
SHA1 b78115431fb3835c1e48426b44466a0c129f7d6f
SHA256 e3948c6624b4345ea0282c3eb52b5cf9e7411602394f3d61564475e7084a2fa5
SHA3 4fd1227ba737c3c9657fdf2c9353d3ff576a4b8967ff699f9d898a68dc0ebc92
VirtualSize 0x9fd6
VirtualAddress 0x22a000
SizeOfRawData 0xa000
PointerToRawData 0x1db200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.81165

.idata

MD5 11b3b2f2ea2e338f4479070d696a7c10
SHA1 1d2c0963db204c6f1084b52876a916362466985b
SHA256 f67728185aa69f4133bdda08a488ecbecae64a4b77bfee43a04f6cf24037687e
SHA3 b290a7cf6f863f75491da0b43ea11b41d33bbfd53a916b7e20eb35286ac5436d
VirtualSize 0x476
VirtualAddress 0x234000
SizeOfRawData 0x600
PointerToRawData 0x1e5200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.54626

.reloc

MD5 a6d907d17b351a659fa44150d8a6e407
SHA1 367af6fab2bf04284b023f6807418237d2e6c78c
SHA256 6276ae958dad70716651a74dc1f4b36d002834ed362fef7d8a91bdf79b055b42
SHA3 72f9112c13a8515cf99378da8c09325a41e2fad439454e7e1296bcc356e66905
VirtualSize 0x704e
VirtualAddress 0x235000
SizeOfRawData 0x7200
PointerToRawData 0x1e5800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.43259

.symtab

MD5 2b8e75138d835ec3875541f5aa401c58
SHA1 2dda515f591f45ccc9bbd4a3af793f7f6d45c69a
SHA256 8ad887c295bc8e090c604dafb83be9ac70316f99d34407d427568455eb6c8bd7
SHA3 e205a6aa6c4436bcf13cd9feca84768dfb6e57c48a424c9eff89a3af26b7763c
VirtualSize 0x17d4e
VirtualAddress 0x23d000
SizeOfRawData 0x17e00
PointerToRawData 0x1eca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.11764

Imports

kernel32.dll WriteFile
WriteConsoleW
WaitForMultipleObjects
WaitForSingleObject
VirtualQuery
VirtualFree
VirtualAlloc
SwitchToThread
SuspendThread
Sleep
SetWaitableTimer
SetUnhandledExceptionFilter
SetProcessPriorityBoost
SetEvent
SetErrorMode
SetConsoleCtrlHandler
ResumeThread
PostQueuedCompletionStatus
LoadLibraryA
LoadLibraryW
SetThreadContext
GetThreadContext
GetSystemInfo
GetSystemDirectoryA
GetStdHandle
GetQueuedCompletionStatusEx
GetProcessAffinityMask
GetProcAddress
GetEnvironmentStringsW
GetConsoleMode
FreeEnvironmentStringsW
ExitProcess
DuplicateHandle
CreateWaitableTimerExW
CreateThread
CreateIoCompletionPort
CreateEventA
CloseHandle
AddVectoredExceptionHandler

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

RICH Header

Errors

[*] Warning: Tried to read outside the COFF string table to get the name of section /4! [*] Warning: Tried to read outside the COFF string table to get the name of section /19! [*] Warning: Tried to read outside the COFF string table to get the name of section /32! [*] Warning: Tried to read outside the COFF string table to get the name of section /46! [*] Warning: Tried to read outside the COFF string table to get the name of section /65! [*] Warning: Tried to read outside the COFF string table to get the name of section /78! [*] Warning: Tried to read outside the COFF string table to get the name of section /90!
<-- -->