e79ee512c4abfea139453c542ba9e5df8f61386e73a70d74b6ac3601998bc175

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Nov-03 17:59:06
Detected languages English - United States

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • github.com
  • https://github.com
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Possibly launches other programs:
  • ShellExecuteW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 13/72 (Scanned on 2025-11-04 16:14:16) APEX: Malicious
CrowdStrike: win/grayware_confidence_70% (D)
Cylance: Unsafe
Cynet: Malicious (score: 100)
DeepInstinct: MALICIOUS
ESET-NOD32: a variant of Win32/GameHack_AGen.AHN potentially unsafe
MaxSecure: Trojan.Malware.300983.susgen
McAfeeD: Real Protect-LS!FB6A554FD7DE
Microsoft: Trojan:Win32/Sabsik.EN.A!ml
Paloalto: generic.ml
Sangfor: Suspicious.Win32.Save.a
Skyhigh: BehavesLike.Win32.Generic.jh
Sophos: Mal/Generic-S

Hashes

MD5 fb6a554fd7def7e9b95af83eeeda4c38
SHA1 da130f1039f0193d8996ca04b2456c6b1d010143
SHA256 e79ee512c4abfea139453c542ba9e5df8f61386e73a70d74b6ac3601998bc175
SHA3 ce3322ed1d32265dc0a64cd3c8d6dd15363df7b674a181d4598387c64a859ed9
SSDeep 12288:7P4aTOlyRrkiab1GgXVkzp+sNue4Nxph0lhSMXlCIlic3Q2:t6lyRrkiaogXizp+sNOh0lhSMXl/lic
Imports Hash 67601163bbab1fb84125ee20896ed923

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2025-Nov-03 17:59:06
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x65a00
SizeOfInitializedData 0x30a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00064E6E (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x67000
ImageBase 0x10000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x99000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 c40996a144e05930dcef8f1105c224b8
SHA1 1a836d127407378fb4dcc342b1ed10ca3ef4f943
SHA256 22d48cc676d2ef8c03e1f579035ac58c40f7fe13d4470e476d9a4487a8867521
SHA3 2f303ef592f7d88f15ec4a6c0dab230f28dd2adbbf191ce1ff676b21815497c1
VirtualSize 0x65994
VirtualAddress 0x1000
SizeOfRawData 0x65a00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.60875

.rdata

MD5 a7a8de5c02fe343737db9b71d04752ae
SHA1 a434ffb73b46cbe9d8b283e8eb99120aaadb4695
SHA256 31a0b903420af558bb5e60d53f02c6264d03cba9cb1ce24b4518d0b35e8b9574
SHA3 54aacec32229de36deb5f86ce888f86e56bd9630f35db82e762390071935670f
VirtualSize 0x2ca10
VirtualAddress 0x67000
SizeOfRawData 0x2cc00
PointerToRawData 0x65e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.86994

.data

MD5 b4ce7318a11fb9cae77598d8b3c7a5c5
SHA1 4586bc8ba85a5ec98edf5ecf7de57857a9d8bd48
SHA256 56bbf8eaad3536ec4f3ca13c23e2a610298696f06db806bc792ff69bb317ae95
SHA3 aff78c781b7910bceb6e8f674a44a228909e3431132ce75e20bc37904942d006
VirtualSize 0xb10
VirtualAddress 0x94000
SizeOfRawData 0x800
PointerToRawData 0x92a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.46456

.rsrc

MD5 55fabca052df5ffb207348fdff1260b0
SHA1 ea20dfee6ca5d8de1ee094c398b2e51ed4660411
SHA256 759609be8b678e2a2d739038a18487e5b3bffec058e6eb7833be133f12d2377d
SHA3 360b061c48b2bce2cd99e2b1b054ebd4b73a9bf2c862dc600032ad177f494e4d
VirtualSize 0xf8
VirtualAddress 0x95000
SizeOfRawData 0x200
PointerToRawData 0x93200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.52739

.reloc

MD5 092ca9e5b49244ed3a0ad8f2da0e04ee
SHA1 4500f26b3aead732729b9deae05c9755048ade64
SHA256 aaec4d384496e581ac7fc90b9e68341c57228b1e9c7f50d37f69d8c5020b0ddc
SHA3 6c86ab3da94fe7232086391cebd18d304b0b27afc62be582dbbf09237f7cae6b
VirtualSize 0x2e84
VirtualAddress 0x96000
SizeOfRawData 0x3000
PointerToRawData 0x93400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.63029

Imports

KERNEL32.dll GlobalLock
WideCharToMultiByte
GlobalUnlock
GetLocaleInfoA
LoadLibraryA
QueryPerformanceFrequency
GetProcAddress
QueryPerformanceCounter
VirtualFree
VirtualAlloc
VirtualQuery
HeapCreate
VirtualProtect
HeapFree
Thread32Next
Thread32First
GetCurrentThreadId
SuspendThread
ResumeThread
CreateToolhelp32Snapshot
GlobalAlloc
HeapReAlloc
CloseHandle
HeapAlloc
GetThreadContext
GetCurrentProcessId
FlushInstructionCache
SetThreadContext
OpenThread
Sleep
InitializeSListHead
GetSystemTimeAsFileTime
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
SleepConditionVariableSRW
WakeAllConditionVariable
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
GlobalFree
MultiByteToWideChar
AllocConsole
CreateThread
GetModuleHandleA
GetLastError
GetCurrentProcess
USER32.dll GetKeyState
GetMessageExtraInfo
LoadCursorA
SetClipboardData
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
SetCapture
SetCursor
GetClientRect
IsWindowUnicode
ReleaseCapture
SetCursorPos
SetWindowLongA
GetClipboardData
EmptyClipboard
CloseClipboard
OpenClipboard
GetCursorPos
CallWindowProcA
SHELL32.dll ShellExecuteW
MSVCP140.dll ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@I@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@P6AAAVios_base@1@AAV21@@Z@Z
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UAE@XZ
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QAE@PAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?good@ios_base@std@@QBE_NXZ
?always_noconv@codecvt_base@std@@QBE_NXZ
??1_Lockit@std@@QAE@XZ
??0_Lockit@std@@QAE@H@Z
?_Getgloballocale@locale@std@@CAPAV_Locimp@12@XZ
?_Id_cnt@id@locale@std@@0HA
?_Xout_of_range@std@@YAXPBD@Z
?_Xlength_error@std@@YAXPBD@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QAEXH_N@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAE@XZ
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IAE@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAE@XZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPBD_J@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UAE@XZ
?_Init@locale@std@@CAPAV_Locimp@12@_N@Z
?_Xbad_alloc@std@@YAXXZ
?id@?$numpunct@D@std@@2V0locale@2@A
??1facet@locale@std@@MAE@XZ
??0facet@locale@std@@IAE@I@Z
?_Decref@facet@locale@std@@UAEPAV_Facet_base@3@XZ
?_Incref@facet@locale@std@@UAEXXZ
?_Gettrue@_Locinfo@std@@QBEPBDXZ
?_Getfalse@_Locinfo@std@@QBEPBDXZ
?_Getlconv@_Locinfo@std@@QBEPBUlconv@@XZ
?_Getcvt@_Locinfo@std@@QBE?AU_Cvtvec@@XZ
??1_Locinfo@std@@QAE@XZ
??0_Locinfo@std@@QAE@PBD@Z
?uncaught_exceptions@std@@YAHXZ
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPAU_iobuf@@PBDHH@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SAIPAPBVfacet@locale@2@PBV42@@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAE_JPBD_J@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHD@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QBEHAAU_Mbstatet@@PAD1AAPAD@Z
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QBE?AVlocale@2@XZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAPAD0PAH001@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEXXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@XZ
?in@?$codecvt@DDU_Mbstatet@@@std@@QBEHAAU_Mbstatet@@PBD1AAPBDPAD3AAPAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QBEHAAU_Mbstatet@@PBD1AAPBDPAD3AAPAD@Z
IMM32.dll ImmSetCandidateWindow
ImmReleaseContext
ImmGetContext
ImmSetCompositionWindow
VCRUNTIME140.dll memcpy
memset
_CxxThrowException
_except_handler4_common
__std_type_info_destroy_list
strchr
strstr
__std_terminate
__std_exception_copy
__std_exception_destroy
memchr
__CxxFrameHandler3
memmove
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
_get_stream_buffer_pointers
_fseeki64
freopen_s
fsetpos
ungetc
setvbuf
fgetpos
fgetc
fputc
ftell
__stdio_common_vsscanf
fread
__stdio_common_vsprintf
_wfopen
fwrite
fflush
fclose
__stdio_common_vfprintf
fseek
api-ms-win-crt-runtime-l1-1-0.dll _seh_filter_dll
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
_execute_onexit_table
_crt_atexit
_invalid_parameter_noinfo_noreturn
_initterm
_initterm_e
_cexit
api-ms-win-crt-convert-l1-1-0.dll strtoul
atof
api-ms-win-crt-heap-l1-1-0.dll malloc
calloc
free
_callnewh
api-ms-win-crt-math-l1-1-0.dll _ldclass
_dsign
_fdsign
_libm_sse2_cos_precise
_ldsign
_CIatan2
_libm_sse2_pow_precise
_CIfmod
_dclass
_libm_sse2_sin_precise
_libm_sse2_sqrt_precise
ceil
_fdclass
_libm_sse2_acos_precise
_hypotf
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-string-l1-1-0.dll strncpy
strncmp
isdigit
api-ms-win-crt-filesystem-l1-1-0.dll _unlock_file
_lock_file

Delayed Imports

2

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x91
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.8858
MD5 f7ad1eab748bc07570a57ec87787cf90
SHA1 0b1608da9fef218386e825db575c65616826d9f4
SHA256 d2952e57023848a37fb0f21f0dfb38c9000f610ac2b00c2f128511dfd68bde04
SHA3 6c9541b36948c19ae507d74223621875b3af4064f7cd8200bdb97e15a047e96a

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Nov-03 17:59:06
Version 0.0
SizeofData 824
AddressOfRawData 0x90fac
PointerToRawData 0x8fdac

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2025-Nov-03 17:59:06
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x100912f4
EndAddressOfRawData 0x100912fc
AddressOfIndex 0x100949e8
AddressOfCallbacks 0x10067364
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0xc0
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x10094040
SEHandlerTable 0x10090e44
SEHandlerCount 55

RICH Header

XOR Key 0x3a9095a8
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 16
ASM objects (34321) 7
C objects (34321) 10
C++ objects (34321) 25
Imports (34321) 4
Imports (33140) 13
Total imports 262
C++ objects (LTCG) (34810) 19
Resource objects (34810) 1
Linker (34810) 1

Errors

Leave a comment

No comments yet.