| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2025-May-04 14:03:12 |
| Detected languages |
English - United States
|
| Debug artifacts |
D:\vs_tudio\letsdefend\x64\Release\letsdefend.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
| Info | The PE contains common functions which appear in legitimate applications. |
Uses Microsoft's cryptographic API:
|
| Malicious | VirusTotal score: 8/72 (Scanned on 2025-10-02 15:42:14) |
APEX:
Malicious
Bkav: W64.AIDetectMalware CrowdStrike: win/malicious_confidence_60% (D) DeepInstinct: MALICIOUS MaxSecure: Trojan.Malware.300983.susgen McAfeeD: ti!E5BE10EF9DF3 TrellixENS: Artemis!710EA7B57F35 TrendMicro-HouseCall: Trojan.Win32.VSX.PE04C9n |
| MD5 | 710ea7b57f35ec12d03c3d324afcf6c0 🔍 |
|---|---|
| SHA1 | eac57586e092578a2382fcb4c7cd86591b1828d7 🔍 |
| SHA256 | e5be10ef9df37f79e02236cb13391d64c50648532f91cb09345619a90bdcb1da 🔍 |
| SHA3 | 836cfe7397ea66d7d0a9d249119148147483137000a80d762fb1a256d7ead623 🔍 |
| SSDeep | 384:pitLknG4rZPS0oCj0SlsnOGJPONTJjB5scXsAx51MF:ps4G+PToCvsn6NL6QsM5 🔍 |
| Imports Hash | 9c5b04d38386dbd652093e9687541061 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2025-May-04 14:03:12 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x3600 |
| SizeOfInitializedData | 0x3600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000003740 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xc000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 16a5ca015f057f3be424eedc8bf6863c 🔍 |
|---|---|
| SHA1 | 63a8d2e2716bfa255249066559ca4a9f0dadcb35 🔍 |
| SHA256 | abb630b26883e7f94f31da00dcf81951f74d820556237d9f0334c964457c8842 🔍 |
| SHA3 | e688dab8962ee68efa0919820515cf4a9fc741b0e8e7a9d8f3093495181c3a5c 🔍 |
| VirtualSize | 0x355e |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x3600 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.59429 |
| MD5 | 70bd5fd5e03e8a8750a244033283761b 🔍 |
|---|---|
| SHA1 | 3030a7ce8f26a839d404e2d640ee4d36f9a97c77 🔍 |
| SHA256 | 0edd7dbee1f3c2bc2af7c43600166eb318138a33caf105270c5ed50056d1fcb7 🔍 |
| SHA3 | 54d2766f8559421c69c99df6a19a04eac722be680d31ff06dd999b351738a238 🔍 |
| VirtualSize | 0x2330 |
| VirtualAddress | 0x5000 |
| SizeOfRawData | 0x2400 |
| PointerToRawData | 0x3a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.54535 |
| MD5 | b4422d3f77ef1ff9839a8f0dea0e4b9c 🔍 |
|---|---|
| SHA1 | 4b5946bc71948a2d7fbef0cfe88e871017b8d2ad 🔍 |
| SHA256 | 04af4b9b22d34a9821b785bce1eec0c40fd84f3fdecc4de141e02a748cce2e5e 🔍 |
| SHA3 | 4eb67d326d629a7fda7c6c01519b1a0597937267982b16f457e2d42f7838d2f9 🔍 |
| VirtualSize | 0x720 |
| VirtualAddress | 0x8000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x5e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 2.06652 |
| MD5 | 364d6a86336a0cb8810fe7d6c6e42218 🔍 |
|---|---|
| SHA1 | 6776c6af376390ebc0c9eb95ab0ad39389636675 🔍 |
| SHA256 | b15b7975ce50fdee42c973c313f0aa98a307d952da6d4e0dbb3982dc2eed3646 🔍 |
| SHA3 | a27acf83041c801a82ba8612a2aef4429a05e27d471fbed434523433588446a0 🔍 |
| VirtualSize | 0x558 |
| VirtualAddress | 0x9000 |
| SizeOfRawData | 0x600 |
| PointerToRawData | 0x6000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 3.76336 |
| MD5 | 101f04294dcfeea9dfe10d3c920461d9 🔍 |
|---|---|
| SHA1 | bb2f3029cd26628c904eca1d14683f2af6ba57e9 🔍 |
| SHA256 | 35e337ded3af0e1d8140f055f2ec4d9bfb3f23d1408c22c82b29becd027b8afb 🔍 |
| SHA3 | a2e9ad9e1911f2e478d453f9eae35c8b8c4dcf7200fe01d0b666a2584f1ca49c 🔍 |
| VirtualSize | 0x1e0 |
| VirtualAddress | 0xa000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x6600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.7015 |
| MD5 | 7da64d2ecd10cf11e3cb94260b869c3b 🔍 |
|---|---|
| SHA1 | e3bc749153ecc782cda9300d5c3fe2905f7562f7 🔍 |
| SHA256 | 103ed38c2932f6e18cab9611df419357006df2870c62db8a5528a37187c7d16f 🔍 |
| SHA3 | 7b6d5215ca9d1044c7405d155d74ecd9fdafd7169684d7931ffe5264332b1a68 🔍 |
| VirtualSize | 0x58 |
| VirtualAddress | 0xb000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x6800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 1.19002 |
| KERNEL32.dll |
IsDebuggerPresent
GetLastError RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead GetModuleHandleW RtlCaptureContext |
|---|---|
| ADVAPI32.dll |
CryptDestroyKey
CryptAcquireContextA CryptReleaseContext CryptImportKey CryptEncrypt CryptSetKeyParam |
| MSVCP140.dll |
?width@ios_base@std@@QEBA_JXZ
?flags@ios_base@std@@QEBAHXZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ?width@ios_base@std@@QEAA_J_J@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?uncaught_exception@std@@YA_NXZ ?_Xlength_error@std@@YAXPEBD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?good@ios_base@std@@QEBA_NXZ |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__current_exception
_CxxThrowException memcpy __current_exception_context __std_exception_copy __std_exception_destroy memmove __C_specific_handler memset |
| api-ms-win-crt-runtime-l1-1-0.dll |
_initialize_onexit_table
_register_onexit_function _crt_atexit _cexit terminate _c_exit exit _exit _register_thread_local_exe_atexit_callback _initterm_e _initterm _get_initial_narrow_environment _initialize_narrow_environment _configure_narrow_argv __p___argv _set_app_type __p___argc _invalid_parameter_noinfo_noreturn _seh_filter_exe |
| api-ms-win-crt-stdio-l1-1-0.dll |
__acrt_iob_func
__p__commode _set_fmode __stdio_common_vfprintf |
| api-ms-win-crt-heap-l1-1-0.dll |
_set_new_mode
free malloc _callnewh |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-May-04 14:03:12 |
| Version | 0.0 |
| SizeofData | 74 |
| AddressOfRawData | 0x5dd8 |
| PointerToRawData | 0x47d8 |
| Referenced File | D:\vs_tudio\letsdefend\x64\Release\letsdefend.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-May-04 14:03:12 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x5e24 |
| PointerToRawData | 0x4824 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-May-04 14:03:12 |
| Version | 0.0 |
| SizeofData | 720 |
| AddressOfRawData | 0x5e38 |
| PointerToRawData | 0x4838 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-May-04 14:03:12 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140008000 |
| XOR Key | 0x790eba97 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 10 |
| ASM objects (34321) | 3 |
| C objects (34321) | 10 |
| C++ objects (34321) | 25 |
| Imports (34321) | 6 |
| Imports (33140) | 5 |
| Total imports | 86 |
| C++ objects (LTCG) (34810) | 1 |
| Resource objects (34810) | 1 |
| Linker (34810) | 1 |
No comments yet.