e521320d30fb248590745459c23ba955e0fc6a6560f8f327f1c6adc27471a072

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-18 20:32:54
Detected languages English - United States

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • github.com
  • https://github.com
Suspicious The PE is possibly packed. Unusual section name found: .fptable
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Possibly launches other programs:
  • ShellExecuteW
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 282f5875382f8f04b55ef88f377f2c3c
SHA1 34efbd2a9340285de3b8b0714d2e83f89c67cdcb
SHA256 e521320d30fb248590745459c23ba955e0fc6a6560f8f327f1c6adc27471a072
SHA3 df4d32b91b65562a55d1b0df7a1bdbf88db05bcd5fcd17e4bd507a9c8de66a75
SSDeep 12288:bNbEvVqoEy7omt4cgc9Ma6Rj2uVxNUEKjlybQ1e22E6IjYi0n3olGXQr:bSfkqfuWys1evLi0n3tXQ
Imports Hash 4b7dab842cc29c4bd4b8d67af46a6c00

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Jul-18 20:32:54
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x91800
SizeOfInitializedData 0x3f400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000006B318 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xd6000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 383ab1b051518316590f9664d22a6c5e
SHA1 b15e03a6a4f9b8dce4450cd19c8ab7da9ab53fab
SHA256 b323032211a23b28be356528394ed90e6cf22749b38df67d41c93fcf25491a21
SHA3 ccd48bf1fb4cea43ae9d141815fdf9bd9467e521e0e3ed3e445f1b1f1a917a59
VirtualSize 0x91800
VirtualAddress 0x1000
SizeOfRawData 0x91800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.57481

.rdata

MD5 61838e6936766e9b58afc35da626b52e
SHA1 924bf8b9235bba7713ffaef49ae767913b90e834
SHA256 6b61cc2782fde04a200d330d8560c93dde88494b6d2d6676b65da3c0c8fe40c9
SHA3 3034a2d28ffc484c554a3eb99052ce413e27c894d3d98a09f4256e376c4d2e3a
VirtualSize 0x2525c
VirtualAddress 0x93000
SizeOfRawData 0x25400
PointerToRawData 0x91c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.23831

.data

MD5 74c8f4b818d4dbf4f6f09fba47f3eb37
SHA1 0844c506aacf20de597e16d8c67737da7e057ee1
SHA256 1be0504eaa99dfbf114e8104f9a6219a47cc19cca53fd1970c2b875c79db216f
SHA3 606887ca6b25868abe4074c2322d3d8b50b75cef275d0e3024a55478631c7a1d
VirtualSize 0x12a20
VirtualAddress 0xb9000
SizeOfRawData 0x1000
PointerToRawData 0xb7000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.87239

.pdata

MD5 2079a0c284583d486cb5a3e4db8bf9ab
SHA1 52f9041ebf470519dcd1dddf5b0627d80e97a3be
SHA256 1bcbfa0fa53da66cf4796b082bab5915bcdb91a354ee44df639c0a1316c04791
SHA3 3a867cb5d7b33dc6d4f45230a20561ebdb39c512eaee2344d7e9ec90b5922f3c
VirtualSize 0x65c4
VirtualAddress 0xcc000
SizeOfRawData 0x6600
PointerToRawData 0xb8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.98021

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x100
VirtualAddress 0xd3000
SizeOfRawData 0x200
PointerToRawData 0xbe600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 174d1a7de7abf218e385ee5154087807
SHA1 4a16954ed89418cc2bd2baa586038895d345e0f2
SHA256 9158635342cf1318002e2448e79b5b54c64bfa69c27e0cf48231ebbd1798c5ba
SHA3 0c28eb3c140dc3f383f32379122251728bcf9cf512c6799b608d9afa2095a907
VirtualSize 0xf8
VirtualAddress 0xd4000
SizeOfRawData 0x200
PointerToRawData 0xbe800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.52496

.reloc

MD5 6ee2fe26f5e822af3590f77dcee27bc3
SHA1 3eba07329b1d28e990d33317cd1ba335c9b09192
SHA256 9a425fb6268e7582d18ba5c0bd887e97663c6ed9aa7396b5cf0c98880a81041d
SHA3 0f7c6eca0523d4d10c82345edf828ba5d8a16196cd918192d83840ce6f6ae37b
VirtualSize 0x88c
VirtualAddress 0xd5000
SizeOfRawData 0xa00
PointerToRawData 0xbea00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.06582

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
d3d12.dll #101
dxgi.dll CreateDXGIFactory1
USER32.dll SendInput
RegisterClassExA
GetAsyncKeyState
SetCursorPos
UnregisterClassA
DefWindowProcW
GetKeyState
GetMessageExtraInfo
LoadCursorA
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
SetCapture
SetCursor
IsWindowUnicode
ReleaseCapture
GetClientRect
GetCursorPos
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
DestroyWindow
CallWindowProcA
DefWindowProcA
CreateWindowExA
SetWindowLongPtrA
KERNEL32.dll FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
GetCommandLineA
GetCPInfo
GetOEMCP
GetACP
IsValidCodePage
FindNextFileW
FindFirstFileExW
FindClose
GetFileSizeEx
GetConsoleOutputCP
WriteFile
FlushFileBuffers
LCMapStringW
InitializeCriticalSectionEx
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
ReadConsoleW
GetProcessHeap
GetStringTypeW
Sleep
DisableThreadLibraryCalls
CreateThread
GetModuleHandleW
GetTickCount
SetStdHandle
GetModuleHandleA
OutputDebugStringA
MultiByteToWideChar
GlobalAlloc
GlobalFree
GlobalLock
WideCharToMultiByte
GlobalUnlock
GetLocaleInfoA
LoadLibraryA
QueryPerformanceFrequency
IsDBCSLeadByte
GetProcAddress
FreeLibrary
QueryPerformanceCounter
CloseHandle
VirtualFree
VirtualAlloc
GetSystemInfo
VirtualQuery
HeapCreate
VirtualProtect
HeapFree
GetCurrentProcess
Thread32Next
Thread32First
GetCurrentThreadId
SuspendThread
ResumeThread
CreateToolhelp32Snapshot
GetLastError
HeapReAlloc
HeapAlloc
HeapDestroy
GetThreadContext
GetCurrentProcessId
FlushInstructionCache
SetThreadContext
OpenThread
GetModuleHandleExW
ExitProcess
GetConsoleMode
CreateFileW
HeapSize
WriteConsoleW
WaitForSingleObject
SetEndOfFile
SetFilePointerEx
GetFileType
GetStdHandle
CreateEventA
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
RtlUnwindEx
InterlockedFlushSList
RtlPcToFileHeader
RaiseException
SetLastError
EncodePointer
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
LoadLibraryExW
ReadFile
GetModuleFileNameW
SHELL32.dll ShellExecuteW
IMM32.dll ImmGetContext
ImmSetCandidateWindow
ImmSetCompositionWindow
ImmReleaseContext
D3DCOMPILER_47.dll D3DCompile

Delayed Imports

2

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x91
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.8858
MD5 f7ad1eab748bc07570a57ec87787cf90
SHA1 0b1608da9fef218386e825db575c65616826d9f4
SHA256 d2952e57023848a37fb0f21f0dfb38c9000f610ac2b00c2f128511dfd68bde04
SHA3 6c9541b36948c19ae507d74223621875b3af4064f7cd8200bdb97e15a047e96a

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-18 20:32:54
Version 0.0
SizeofData 892
AddressOfRawData 0xadaa8
PointerToRawData 0xac6a8

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jul-18 20:32:54
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1800ade70
EndAddressOfRawData 0x1800ade78
AddressOfIndex 0x1800ba464
AddressOfCallbacks 0x180093588
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1800b9040

RICH Header

XOR Key 0xd8b7e09c
Unmarked objects 0
C++ objects (33145) 160
C objects (33145) 28
ASM objects (33145) 28
ASM objects (35207) 10
C objects (35207) 15
C++ objects (35207) 39
Imports (33145) 21
Total imports 179
C++ objects (LTCG) (35228) 18
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.