| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2024-Dec-04 10:30:18 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 51/72 (Scanned on 2025-08-28 10:41:48) |
ALYac:
Gen:Trojan.Heur3.LPT.gqW@aeSsdnoab
APEX: Malicious AVG: Win32:MalwareX-gen [Misc] AhnLab-V3: Trojan/Win.Generic.C5703790 Alibaba: Trojan:Win32/Nekark.c8f3ddb0 Arcabit: Trojan.Heur3.LPT.EF683D Avast: Win32:MalwareX-gen [Misc] Avira: TR/AD.Nekark.gilic BitDefender: Gen:Trojan.Heur3.LPT.gqW@aeSsdnoab Bkav: W32.AIDetectMalware CAT-QuickHeal: Trojan.Ghanarava.17340691668d9670 CTX: exe.trojan.nekark CrowdStrike: win/malicious_confidence_100% (W) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS DrWeb: Trojan.DownLoader48.61001 Elastic: malicious (high confidence) Emsisoft: Gen:Trojan.Heur3.LPT.gqW@aeSsdnoab (B) F-Secure: Trojan.TR/AD.Nekark.gilic Fortinet: W32/PossibleThreat GData: Gen:Trojan.Heur3.LPT.gqW@aeSsdnoab Google: Detected Ikarus: Trojan.Nekark Jiangmin: HackTool.Inject.dvy K7AntiVirus: Riskware ( 00584baa1 ) K7GW: Riskware ( 00584baa1 ) Kaspersky: HEUR:Trojan.Win32.Scar.gen Kingsoft: malware.kb.a.969 Lionic: Trojan.Win32.Nekark.4!c Malwarebytes: Trojan.Downloader MaxSecure: Trojan.Malware.1466431.susgen McAfeeD: ti!E6AE0415BEAF MicroWorld-eScan: Gen:Trojan.Heur3.LPT.gqW@aeSsdnoab Microsoft: Trojan:Win32/Wacatac.B!ml NANO-Antivirus: Trojan.Win32.Scar.lawarj Paloalto: generic.ml Rising: Trojan.Kryptik@AI.86 (RDML:GEvNVCYsTc2mfJrhKmyysA) Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Malicious PE Skyhigh: BehavesLike.Win32.NetLoader.nh Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence Tencent: Malware.Win32.Gencirc.1424789e TrellixENS: Artemis!1D824F4F9B17 TrendMicro-HouseCall: TROJ_GEN.R002H09HD25 VBA32: suspected of Trojan.Downloader.gen VIPRE: Gen:Trojan.Heur3.LPT.gqW@aeSsdnoab Varist: W32/ABTrojan.NDFS-6169 Zillya: Trojan.Scar.Win32.191819 alibabacloud: Trojan:Win/Wacatac.B9nj |
| MD5 | 1d824f4f9b1759fdfa46003b898d9670 🔍 |
|---|---|
| SHA1 | 5ab01224e7117969d1f9cfdb8682bcda38663d3f 🔍 |
| SHA256 | e6ae0415beaf6654c797dd828db881db8a5136b72da66517a2662a6a6636ccc9 🔍 |
| SHA3 | 7048fc2b5e3f5a1b7e791aee8ada91409debf1c7b9a3700817c8899a9fe01312 🔍 |
| SSDeep | 3072:VAlX7+D02WFZudKd84aXVZjyEymSH45thLUWgbhKXX+Z4aao0X:i71B846jZhEguCD 🔍 |
| Imports Hash | 90bb9f120b73e6b566f4bdaf455949e0 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2024-Dec-04 10:30:18 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xfc00 |
| SizeOfInitializedData | 0x8c00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00001732 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x11000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1c000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 29fc38552b5e657d0ef42f2ee316290f 🔍 |
|---|---|
| SHA1 | e586b6975ceae70eb82365abc11def7cdf149759 🔍 |
| SHA256 | 6e09442290e4da5ebc2f281225ea6cec6ba3c06a561169e33fc1289145b0c679 🔍 |
| SHA3 | 125c0d0382b70eca18e30ab55ceb16ecea1e3a99a6c1925debbbf5aedd27a19c 🔍 |
| VirtualSize | 0xfb73 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0xfc00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.58342 |
| MD5 | bdb1cd08ef3d03f337de8c06f7d5925a 🔍 |
|---|---|
| SHA1 | 15cd5982a524a636ce8804260f90ae12093e0357 🔍 |
| SHA256 | f86715ae6af74fd7c5071c2a1253dae22b47d53de3c7859d56c843bf3193e58f 🔍 |
| SHA3 | 81bc6deb270308379b11689482ce003537319cc3b4ede8b32c80e244eb665b81 🔍 |
| VirtualSize | 0x6558 |
| VirtualAddress | 0x11000 |
| SizeOfRawData | 0x6600 |
| PointerToRawData | 0x10000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.88514 |
| MD5 | 99dc0e65713eff35913089b1d0e59468 🔍 |
|---|---|
| SHA1 | 81ab24b055a71c317fdaf3c59a8c94716a62037c 🔍 |
| SHA256 | e84f41188a5612bce6327d6f2855ba657c2b3812664acf8e89b5eef444a61d5d 🔍 |
| SHA3 | b918435c4c5364107a3f159083d41efa79465cfd415385545ce856abc9993426 🔍 |
| VirtualSize | 0x13d4 |
| VirtualAddress | 0x18000 |
| SizeOfRawData | 0xa00 |
| PointerToRawData | 0x16600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 2.19842 |
| MD5 | bcc24d190231a70e53d687aa8f3d4ca2 🔍 |
|---|---|
| SHA1 | 274defc989eeee9316cba9d6a4c7a9e992c57bd2 🔍 |
| SHA256 | e1bf88f1fb4f4c2dfaf3fb47221051e4f6c5c480286c6962eb31cee8eac7b5c6 🔍 |
| SHA3 | e7e588051e8423c78942cd81fa8bfcecd42639473acebd15f9eda7d2e54602c6 🔍 |
| VirtualSize | 0x1078 |
| VirtualAddress | 0x1a000 |
| SizeOfRawData | 0x1200 |
| PointerToRawData | 0x17000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.33042 |
| ADVAPI32.dll |
RegOpenKeyExA
RegSetValueExA RegCloseKey |
|---|---|
| SHELL32.dll |
ShellExecuteA
SHGetFolderPathA |
| CRYPT32.dll |
CryptStringToBinaryA
|
| USER32.dll |
SystemParametersInfoA
|
| WININET.dll |
InternetOpenA
InternetCloseHandle InternetOpenUrlA InternetReadFile |
| KERNEL32.dll |
SetEndOfFile
WriteConsoleW HeapReAlloc HeapSize ReadConsoleW ReadFile FlushFileBuffers CreateFileW GetProcessHeap UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW GetModuleHandleW LCMapStringW RtlUnwind GetLastError SetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary GetProcAddress LoadLibraryExW EncodePointer RaiseException GetStdHandle WriteFile GetModuleFileNameW ExitProcess GetModuleHandleExW GetCommandLineA GetCommandLineW HeapFree CloseHandle GetConsoleOutputCP GetConsoleMode GetFileSizeEx SetFilePointerEx HeapAlloc FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCPInfo MultiByteToWideChar WideCharToMultiByte GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW SetStdHandle GetFileType GetStringTypeW CompareStringW DecodePointer |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Dec-04 10:30:18 |
| Version | 0.0 |
| SizeofData | 712 |
| AddressOfRawData | 0x16414 |
| PointerToRawData | 0x15414 |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x418040 |
| SEHandlerTable | 0x41631c |
| SEHandlerCount | 10 |
| XOR Key | 0x732c5a5d |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 11 |
| C++ objects (30795) | 148 |
| C objects (30795) | 20 |
| ASM objects (33808) | 20 |
| C objects (33808) | 18 |
| C++ objects (33808) | 38 |
| Imports (30795) | 13 |
| Total imports | 93 |
| C++ objects (34123) | 1 |
| Linker (34123) | 1 |
No comments yet.