| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Sep-19 11:54:31 |
| Debug artifacts |
aircard.pdb
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to RC5 or RC6 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/70 (Scanned on 2026-09-29 11:58:34) | APEX: Malicious |
| MD5 | 8a0b8b96c0863277dfb9a1f2fcc2ca29 🔍 |
|---|---|
| SHA1 | 4cdb0e49ceeffe1e0b56a2a1eaf3b7beda733b75 🔍 |
| SHA256 | e8887b85b810e64b293fcff6919b1b6cc2eb61203799a17b89fc744aed62e32f 🔍 |
| SHA3 | 1a637f0074565a57ac7608cb1b9c414b82e166bb77bf5adbd9fa998363a9f4ec 🔍 |
| SSDeep | 49152:kcokurHr2QC9nwQxtYVzcxcBDeRpRonMAos9w+zF655O336U3JDwcCnohVfcQN5:kHlC/VUoseUT3HSAN5+BbF6C 🔍 |
| Imports Hash | 7ccec30f46d05b6d74a84f572526872a 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 5 |
| TimeDateStamp | 2026-Sep-19 11:54:31 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x486e00 |
| SizeOfInitializedData | 0x2dfa00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000044CE80 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x769000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 6eebb0c047ba35e9e069a22687352e45 🔍 |
|---|---|
| SHA1 | c5a9e72869064703caa7618812afdc79d5b88404 🔍 |
| SHA256 | c8f3c37abcb1291dc08683e29c29c40c50adfe0d75d6e730e4619f031f1de86d 🔍 |
| SHA3 | 0ddc7adc99d7a158257fe0ccae8357e9777b525b46b405a714f1dc82b028c842 🔍 |
| VirtualSize | 0x486d08 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x486e00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.38203 |
| MD5 | a50406df600da86cffad75f453b24b0d 🔍 |
|---|---|
| SHA1 | 9a42ed93ea98dbfbe6faed863ded7e53628c3878 🔍 |
| SHA256 | 16c2065efe6af12ad22dfd4828a744d368a9bee47d53d7bbd5bc014893fc233e 🔍 |
| SHA3 | 5ad604f63ffa73f1b617c53cfcb62e74e605e1e210516cb5211fcb0bc4a136c1 🔍 |
| VirtualSize | 0x2b8b5e |
| VirtualAddress | 0x488000 |
| SizeOfRawData | 0x2b8c00 |
| PointerToRawData | 0x487200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.28241 |
| MD5 | a234b7aca29f89cc88937076c5c97f81 🔍 |
|---|---|
| SHA1 | 997c94908a475034d5888246670e18c0230a3240 🔍 |
| SHA256 | d46ed81ad418298fc667a0bcf0d9d32e1a6246b9ee9c573d0d0ee090fa422622 🔍 |
| SHA3 | 1d205a0fe3a11f2ff19eca85e8707d9857051961817c9c098e7a9c0314848e1f 🔍 |
| VirtualSize | 0xe40 |
| VirtualAddress | 0x741000 |
| SizeOfRawData | 0xc00 |
| PointerToRawData | 0x73fe00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 1.05912 |
| MD5 | 6c2d2e6b7a82582090c772ebfa713bd6 🔍 |
|---|---|
| SHA1 | c9161f5e9cd86857de7b09b5598ecd89bd79af38 🔍 |
| SHA256 | 6037c42f83378d0121e9abf0987d060e53a3a6f3603832b9753647fd00616cf9 🔍 |
| SHA3 | b17c9d1dd412e64bf8a84aba9ef0d5d11a9a0e14cd08f8ccffc66cfea94c2548 🔍 |
| VirtualSize | 0x20268 |
| VirtualAddress | 0x742000 |
| SizeOfRawData | 0x20400 |
| PointerToRawData | 0x740a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.41673 |
| MD5 | 048b5d86af0a974bae4461d3ac86547c 🔍 |
|---|---|
| SHA1 | b372f03394fb31f71c0800429fad3b7fe707d21a 🔍 |
| SHA256 | d5ea3e4477639b4e33ce5fc7c03298eb1f13fad73e9e4b41a8d3a3152de1875f 🔍 |
| SHA3 | 9ac4bea2189ff776ccc54c36d0f6e2679295482171b1000328b3cd3352c2b39d 🔍 |
| VirtualSize | 0x5968 |
| VirtualAddress | 0x763000 |
| SizeOfRawData | 0x5a00 |
| PointerToRawData | 0x760e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.46214 |
| bcrypt.dll |
BCryptGenRandom
|
|---|---|
| kernel32.dll |
SetHandleInformation
GetModuleHandleW GetProcessHeap HeapFree HeapAlloc GlobalFree FormatMessageW SetDllDirectoryW LoadLibraryExA LoadLibraryExW LoadLibraryA GetModuleFileNameW DuplicateHandle GetModuleHandleA GetModuleHandleExW SetThreadErrorMode FreeLibrary GetProcAddress GetLastError Sleep LoadLibraryW CloseHandle SetLastError |
| ntdll.dll |
NtReadFile
NtCreateNamedPipeFile NtOpenFile NtWriteFile RtlNtStatusToDosError |
| oleaut32.dll |
GetErrorInfo
VariantClear SysAllocStringLen SysStringLen SetErrorInfo SysFreeString SafeArrayCreateVector SafeArrayPutElement |
| user32.dll |
MapVirtualKeyW
SendInput SetForegroundWindow LoadCursorW SetCursor GetClassNameW GetClassInfoExW RegisterWindowMessageA ShowWindow GetPropW SetPropW SetWindowLongPtrW CallWindowProcW ClientToScreen DefWindowProcW GetSystemMenu EnableMenuItem RemovePropW RegisterClassExW CreateWindowExW SetWindowLongW RegisterRawInputDevices DestroyCursor GetWindowLongPtrW PeekMessageW GetCursorPos TranslateMessage DispatchMessageW DestroyWindow RedrawWindow PostMessageW ReleaseDC EnumDisplayMonitors GetMonitorInfoW MonitorFromPoint GetDC IsWindowVisible SystemParametersInfoA GetClientRect GetActiveWindow GetSystemMetrics SendMessageW CreateIconFromResourceEx IsIconic SetWindowPos InvalidateRgn CreateIcon DestroyIcon GetForegroundWindow MonitorFromWindow GetWindowTextLengthW GetWindowTextW SetCursorPos SetWindowTextW SetWindowDisplayAffinity FlashWindowEx ChangeDisplaySettingsExW GetWindowPlacement SetWindowPlacement GetWindowRect ReleaseCapture ValidateRect GetRawInputData MsgWaitForMultipleObjectsEx ToUnicodeEx AdjustWindowRectEx GetWindowLongW ShowCursor ClipCursor GetClipCursor TrackMouseEvent SetCapture MonitorFromRect ScreenToClient GetMenu GetKeyboardLayout MapVirtualKeyExW IsProcessDPIAware GetKeyState GetAsyncKeyState GetKeyboardState |
| uiautomationcore.dll |
UiaRaiseAutomationPropertyChangedEvent
UiaRaiseAutomationEvent UiaLookupId UiaGetReservedNotSupportedValue UiaReturnRawElementProvider UiaHostProviderFromHwnd |
| gdi32.dll |
DeleteObject
GetDeviceCaps CreateRectRgn |
| ole32.dll |
CoCreateInstance
CoInitializeEx OleInitialize RegisterDragDrop RevokeDragDrop CoCreateFreeThreadedMarshaler CoTaskMemFree CoUninitialize |
| shlwapi.dll |
AssocQueryStringW
|
| shell32.dll |
DragQueryFileW
SHCreateItemFromParsingName DragFinish |
| bcryptprimitives.dll |
ProcessPrng
|
| api-ms-win-core-synch-l1-2-0.dll |
WakeByAddressAll
WaitOnAddress WakeByAddressSingle |
| OPENGL32.dll |
wglGetProcAddress
wglCreateContext wglDeleteContext wglShareLists wglGetCurrentContext wglGetCurrentDC wglMakeCurrent |
| KERNEL32.dll |
InitializeSListHead
SetUnhandledExceptionFilter GlobalLock GetSystemTimeAsFileTime SetWaitableTimer CreateWaitableTimerExW GetFileAttributesW CreateProcessW GetWindowsDirectoryW GetSystemDirectoryW FreeEnvironmentStringsW GetEnvironmentStringsW CompareStringOrdinal ExitProcess CreateDirectoryW GetFileInformationByHandleEx GetFileInformationByHandle FindClose FindFirstFileExW SetFileInformationByHandle SetFileTime CreateFileW GetFullPathNameW QueryPerformanceCounter QueryPerformanceFrequency WriteFileEx ReadFileEx SleepEx GetEnvironmentVariableW IsThreadAFiber FlsSetValue FlsFree FlsAlloc WriteConsoleW GetConsoleOutputCP GetConsoleMode GetStdHandle ReleaseMutex CreateMutexA GetCurrentProcessId lstrlenW GetCurrentProcess WaitForSingleObjectEx GetCurrentDirectoryW RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext GetSystemInfo WideCharToMultiByte GlobalSize GetCurrentThreadId MultiByteToWideChar GlobalUnlock GlobalAlloc GetCurrentThread SetThreadStackGuarantee AddVectoredExceptionHandler WaitForSingleObject HeapReAlloc CreateThread SwitchToThread SetFilePointerEx GetLocalTime |
| USER32.dll |
CloseTouchInputHandle
IsClipboardFormatAvailable RegisterClipboardFormatW CloseClipboard SetClipboardData EmptyClipboard GetClipboardData GetTouchInputInfo RegisterTouchWindow OpenClipboard |
| GDI32.dll |
SwapBuffers
SetPixelFormat DescribePixelFormat ChoosePixelFormat |
| ADVAPI32.dll |
RevertToSelf
ImpersonateAnonymousToken |
| ws2_32.dll |
setsockopt
WSACleanup WSAStartup send recv getsockopt select closesocket connect ioctlsocket WSASocketW WSAGetLastError |
| imm32.dll |
ImmAssociateContextEx
ImmSetCompositionWindow ImmGetContext ImmGetCompositionStringW ImmReleaseContext ImmSetCandidateWindow |
| dwmapi.dll |
DwmEnableBlurBehindWindow
DwmSetWindowAttribute |
| uxtheme.dll |
SetWindowTheme
|
| VCRUNTIME140.dll |
memcmp
memset _CxxThrowException memmove __current_exception_context memcpy __current_exception __C_specific_handler __CxxFrameHandler3 |
| api-ms-win-crt-math-l1-1-0.dll |
exp2f
cbrtf acosf floor atan2f truncf cosf fmod cos sin powf _hypotf sinf expf __setusermatherr floorf roundf round ceilf trunc |
| api-ms-win-crt-string-l1-1-0.dll |
wcslen
strlen |
| api-ms-win-crt-runtime-l1-1-0.dll |
_seh_filter_exe
_set_app_type strerror _configure_narrow_argv _initialize_narrow_environment _get_initial_narrow_environment _initterm _initterm_e exit _exit _register_thread_local_exe_atexit_callback __p___argv _cexit _c_exit __p___argc terminate _initialize_onexit_table _register_onexit_function _crt_atexit |
| api-ms-win-crt-stdio-l1-1-0.dll |
_set_fmode
__p__commode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-heap-l1-1-0.dll |
free
_set_new_mode |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Sep-19 11:54:31 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0x6c1e70 |
| PointerToRawData | 0x6c1070 |
| Referenced File | aircard.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Sep-19 11:54:31 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x6c1e94 |
| PointerToRawData | 0x6c1094 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Sep-19 11:54:31 |
| Version | 0.0 |
| SizeofData | 816 |
| AddressOfRawData | 0x6c1ea8 |
| PointerToRawData | 0x6c10a8 |
| StartAddressOfRawData | 0x1406c21f8 |
|---|---|
| EndAddressOfRawData | 0x1406c2390 |
| AddressOfIndex | 0x140741db0 |
| AddressOfCallbacks | 0x140488ae8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140741b40 |
| XOR Key | 0xcbbe1efd |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 12 |
| Imports (35721) | 2 |
| ASM objects (35721) | 3 |
| C objects (35721) | 9 |
| C++ objects (35721) | 23 |
| Imports (33145) | 13 |
| Total imports | 310 |
| Unmarked objects (#2) | 44 |
| Linker (36256) | 1 |
No comments yet.