d850574d113af717a8d9230896bf887c

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2006-May-05 15:04:05

Plugin Output

Suspicious PEiD Signature: HQR data file
Info Interesting strings found in the binary: Contains domain names:
  • .eq.golang.org
  • eq.golang.org
  • golang.org
  • type..eq.golang.org
Suspicious The PE is possibly packed. Unusual section name found: .symtab
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryW
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 d850574d113af717a8d9230896bf887c
SHA1 131960d5be18e993afdfb23b125db36296135a42
SHA256 c4bff61be2c562d0463b6fb307ccc87cc7ff36a7196055e02cecac2383e78781
SHA3 246890712c47199b7eb5afc0446093e151c95b51531a6d5e4ef67528ddaa6346
SSDeep 49152:w1BoO33Trb/TivO90dL3BmAFd4A64nsfJ8wCDM9erguD58VduQq1:o3c5
Imports Hash 9cbefe68f395e67356e2a5d8d1b285c0

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0x4
e_cparhdr 0
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0x8b
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2006-May-05 15:04:05
PointerToSymbolTable 0x1a2600
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 3.0
SizeOfCode 0xbea00
SizeOfInitializedData 0x19000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000005E640 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 1.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0x202000
SizeOfHeaders 0x600
Checksum 0x1a9410
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 b44c2b65a9ded268f9af2bc57d6a4f33
SHA1 701d44b872fad6de728b9c90e54f6ba6b6390401
SHA256 7a5616ecda02e71fb5b7ce434cd7245a1801575565ef334d21e5a5602afa310f
SHA3 fba6127fd400360d522bb7010e7f0c04b367abf16fd3e5f6442518b4f5bc377d
VirtualSize 0xbe990
VirtualAddress 0x1000
SizeOfRawData 0xbea00
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.18445

.rdata

MD5 84f092cbaad9a202309fb5360ee61fb5
SHA1 8aba0bb974a244db2ee8e2a05635b790dd30cd99
SHA256 98b92c552f92b450359abbd71da7bc40a5b0d5e600937960c421859ffcbcb6c0
SHA3 d65233e37f1b23fb3d1a0b9dfd3f1301cfe1eb4aaffe7bf7ee33c665b95b0e27
VirtualSize 0xc67e0
VirtualAddress 0xc0000
SizeOfRawData 0xc6800
PointerToRawData 0xbf000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.31817

.data

MD5 f9636855a1900f83f52c00ec59931591
SHA1 20816e835843d0244bf0ec4d89ca1e492375eabd
SHA256 2ef62e814715b252fbe9bcd8d52402bb46a8a1a052d33ac1703ce59249909593
SHA3 77cadda5a0b14a7d104a815b6cfacca0700e92632867e4b33130356597890d2e
VirtualSize 0x74e60
VirtualAddress 0x187000
SizeOfRawData 0x19000
PointerToRawData 0x185800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.53445

.idata

MD5 d583f2c28582e03021b9364819808079
SHA1 d88ccdff6c40bd5c02b8af68fb422619c3606ec1
SHA256 b133f27685123ea9915df7e9073266cf2391fe95c38a6708daf83bba5455d771
SHA3 1ba36d0b5fef7e57c02862fab78a6a0e67092f42d04d0c53db9fc6194f4c4cfc
VirtualSize 0x47c
VirtualAddress 0x1fc000
SizeOfRawData 0x600
PointerToRawData 0x19e800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.57352

.reloc

MD5 a47758576fcf8405ab467dec12d5cca2
SHA1 d1cf4ded1c65a609c3e495867f7b89cc7a20492b
SHA256 d57d9c5b724eff516db13e91dc6b39c607585e32d0a9849a8f08a8e8cbfc992b
SHA3 d1ca3b6441340368c076438c89601e301ec114fd5426c20d2c6584a2fa7c9fa0
VirtualSize 0x36e6
VirtualAddress 0x1fd000
SizeOfRawData 0x3800
PointerToRawData 0x19ee00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.40727

.symtab

MD5 07b5472d347d42780469fb2654b7fc54
SHA1 943ae54f4818e52409fbbaf60ffd71318d966b0d
SHA256 3e67f4a7d14b832ff2a2433e9cf0f6f5720821f67148a87c0ee2595a20c96c68
SHA3 a70a3e18515c06557b62676f2a8eb6d7d41962d8c9c7c49f4641c429cc65b977
VirtualSize 0x4
VirtualAddress 0x201000
SizeOfRawData 0x200
PointerToRawData 0x1a2600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.0203931

Imports

kernel32.dll WriteFile
WriteConsoleW
WaitForMultipleObjects
WaitForSingleObject
VirtualQuery
VirtualFree
VirtualAlloc
SwitchToThread
SuspendThread
SetWaitableTimer
SetUnhandledExceptionFilter
SetProcessPriorityBoost
SetEvent
SetErrorMode
SetConsoleCtrlHandler
ResumeThread
PostQueuedCompletionStatus
LoadLibraryA
LoadLibraryW
SetThreadContext
GetThreadContext
GetSystemInfo
GetSystemDirectoryA
GetStdHandle
GetQueuedCompletionStatusEx
GetProcessAffinityMask
GetProcAddress
GetEnvironmentStringsW
GetConsoleMode
FreeEnvironmentStringsW
ExitProcess
DuplicateHandle
CreateWaitableTimerExW
CreateThread
CreateIoCompletionPort
CreateFileA
CreateEventA
CloseHandle
AddVectoredExceptionHandler

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

RICH Header

Errors

<-- -->