ea27d7be5a3a35ae05146715de28eb39061580ea0192c6fbd2352897b846d4be

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2086-Jun-12 22:44:10
Comments
CompanyName
FileDescription UID BYPASS INSTALLER V1
FileVersion 1.0.0.0
InternalName UID BYPASS V1.0.exe
LegalCopyright Copyright © 2026
LegalTrademarks
OriginalFilename UID BYPASS V1.0.exe
ProductName UID BYPASS INSTALLER V1
ProductVersion 1.0.0.0
Assembly Version 1.0.0.0

Plugin Output

Suspicious The PE is possibly packed. Unusual section name found: zF\x0d2\x072\x0b\x12
Section zF\x0d2\x072\x0b\x12 is both writable and executable.
Unusual section name found: ]<3\x0bQY\x1c0
Section ]<3\x0bQY\x1c0 is both writable and executable.
Unusual section name found: Xhj\x10&.\x0e\x0c
Section Xhj\x10&.\x0e\x0c is both writable and executable.
Unusual section name found: .xerin
Unusual section name found: .xerin
The PE only has 0 import(s).
Malicious VirusTotal score: 30/70 (Scanned on 2026-06-25 12:51:39) ALYac: Gen:Variant.Barys.511532
AVG: Win64:MalwareX-gen [Expl]
Arcabit: Trojan.Barys.D7CE2C
Avast: Win64:MalwareX-gen [Expl]
Avira: TR/Crypt.ZPACK.Gen7
BitDefender: Gen:Variant.Barys.511532
Bkav: W32.Malware.6BAD0CD
CTX: exe.unknown.barys
CrowdStrike: win/malicious_confidence_90% (D)
Cylance: Unsafe
Cynet: Malicious (score: 100)
DeepInstinct: MALICIOUS
ESET-NOD32: MSIL/Kryptik.AQEY trojan
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Barys.511532 (B)
F-Secure: Trojan.TR/Crypt.ZPACK.Gen7
GData: Gen:Variant.Barys.511532
Gridinsoft: Trojan.Heur!.0311B683
Malwarebytes: Trojan.Crypt.MSIL
McAfeeD: ti!EA27D7BE5A3A
MicroWorld-eScan: Gen:Variant.Barys.511532
Microsoft: Trojan:Win32/Wacatac.B!ml
Rising: Malware.Obfus/MSIL@AI.97 (RDM.MSIL2:GGu5g9eZMjGmEys2nwKzfw)
Sangfor: Suspicious.Win32.Save.a
SentinelOne: Static AI - Malicious PE
Symantec: ML.Attribute.HighConfidence
Trapmine: malicious.moderate.ml.score
VBA32: CIL.HeapOverride.Heur
VIPRE: Gen:Variant.Barys.511532
Webroot: Win.Trojan.Gen

Hashes

MD5 ed39f317d5e0049b527c24beb95b3e6f
SHA1 91caf71c9b166809c400140b47ca811bdb8a9470
SHA256 ea27d7be5a3a35ae05146715de28eb39061580ea0192c6fbd2352897b846d4be
SHA3 a9c630b4526b8c570a04246361756624629f24096539477a65dbd2bc3cb6aae8
SSDeep 49152:HI5VcCB3ViVa1d6Bu+dyKegmDv+gkdAFtH9AE8lgKi/6nmlsT5GfHKgjsDG2y:6B3VT+pwKevIdAFnxKgKIqT5GCxGT
Imports Hash d41d8cd98f00b204e9800998ecf8427e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2086-Jun-12 22:44:10
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 48.0
SizeOfCode 0x278e00
SizeOfInitializedData 0xa9e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000000000 (Section: ?)
BaseOfCode 0x7c000
ImageBase 0x400000
SectionAlignment 0x2000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x330000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x400000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x2000
LoaderFlags 0
NumberOfRvaAndSizes 16

zF\x0d2\x072\x0b\x12

MD5 1435686bb0e5a627290a563163a6ee34
SHA1 025ef68b6ab73366e69ae09d81cf0ae1f8b02af5
SHA256 41d07f5fb9dc8591b3d23607daa50369c3b0d500302e09e5576602ed7c1a7900
SHA3 06c41b66d8bd34f88d766410b43aecbf8990e5e8080bcd2ef15b15a2b857a31a
VirtualSize 0x3a664
VirtualAddress 0x2000
SizeOfRawData 0x3a800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.99927

]<3\x0bQY\x1c0

MD5 fa198c543bb2d04eab6e9aac58ca969d
SHA1 6ea62b7107302da9a6c62380da8d6b2d937fd4b7
SHA256 67e1fba8a6d3c090072fc689a632f278c5d0ef3ba278ee6c2257ac6d74d6be25
SHA3 b75f9c443f03776d4e3f87827343223055cf8ee1b1c7cd8eca58da00c5fda867
VirtualSize 0x3aa70
VirtualAddress 0x3e000
SizeOfRawData 0x3ac00
PointerToRawData 0x3ac00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.99922

Xhj\x10&.\x0e\x0c

MD5 04d91d4e806e8ea33762502b2481e713
SHA1 7fb50493aa1f9badeae2384b6ade790efd0a1fe9
SHA256 79f6b790fbf8e76e53bf178188e744b8da35f74071d1c03194033ea51c9dafa1
SHA3 4525dd7c4ae3d1d1b49b335c8d0f044d0de94f77487c27ad04399714eb3d5fee
VirtualSize 0x8
VirtualAddress 0x7a000
SizeOfRawData 0x200
PointerToRawData 0x75800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.16299

.text

MD5 50fe5bf1ce8c79b4102f151530d22074
SHA1 7e9c231ee202d17cb8273e050103067611e1d075
SHA256 291dff6c69105949ebbbdfd99f86cfd87daf34b08e767695b219cb4190cdee6e
SHA3 88b4f47fbd97151eecd1a68ec230b62fb74a8e6abc15a1fd0c948482fdb565d6
VirtualSize 0x278c4c
VirtualAddress 0x7c000
SizeOfRawData 0x278e00
PointerToRawData 0x75a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 7.93421

.rsrc

MD5 29cf2444b60037c2733270723b226a28
SHA1 59f1a5d01b7741de49a7b542870fa4eda9e6f9d6
SHA256 17612fb23653e1e7b7d10fc9cd5982371b3dc864d314d229a5fa360a06798755
SHA3 347748110798a9813956fb4b531911647185dcabd0411a8d8cdeedefc4e39f8f
VirtualSize 0x34537
VirtualAddress 0x2f6000
SizeOfRawData 0x34600
PointerToRawData 0x2ee800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.88212

.xerin

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x40
VirtualAddress 0x32c000
SizeOfRawData 0x200
PointerToRawData 0x322e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_EXECUTE
Entropy 0

.xerin (#2)

MD5 de641f655f360d42583c63b4087ab73e
SHA1 517ecd4109d228005b05d836818d151c27bb5928
SHA256 3c56347b2af2522e6fab7b12aa32a5fedd316aa07ca383ee5250472ac2f0a76b
SHA3 a03be06c0f67eb2d232265c658b0f771c255825bcc351308ad7a307a4be57343
VirtualSize 0x9d
VirtualAddress 0x32e000
SizeOfRawData 0x200
PointerToRawData 0x323000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.24693

Imports

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.84448
MD5 b1edad4d13e8f5c7d65d2c24e82e0846
SHA1 c1caa4ed1bf935a0070bd500ba108b2b7cbad246
SHA256 4435c34c0e9061ebfafc066a13097a81d98e67852827153cdeda03711eed5e15
SHA3 fd02aa092fbfadd2620791a41df95573c0ff2695b370477b3ae52f443db75d43

2

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.57794
MD5 4dea8cb4fb8e82cd42b2b77bd20e9737
SHA1 15f66837d17b652bd487517a90bc8a834e98dff7
SHA256 8244e0e8aaf713fc513cc90bb0dc4441b8e92e14198c61e88e97326b2dd037fc
SHA3 a7a19956b933800070bbab65102ffeb72ddbc00f8d0776eee3d3ba0d9deb8e48

3

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.33644
MD5 d5440806a30f033a851be685bbfdb9cd
SHA1 0ba99357bfb6ed4df39eeba4a0ff202af060909b
SHA256 151d35052ecae1cbe9feeb9587fad5c3edaaa848e9d17c09e3fd8b7de1819b37
SHA3 c686aadf7c02a03c7155aee3626e4dc2d42cd8fec3671ed35a76b6ecb401c4d4

4

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.87702
MD5 b59fdd1711940af767fc9676dd2c66f0
SHA1 56b50cbf816a45528bab5d6fc9bb0da99166e59f
SHA256 2ada938c5b339406921f013de3a877d1925e8f19db09cfbcc21cd13f56c6552b
SHA3 f33eaf84e526c06347590f1b46f79af4c68fe9cf031b81f64f4e8285ed39c245

5

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.70263
MD5 66f06bbe29048ad71b39bc898dd56e64
SHA1 4ec22150fd9651cb7b943d2bb5c60838408a35c1
SHA256 2df2b2b525089a270fcc83d10d22151b884c8d7082bbbc8b6cafe9de7c164875
SHA3 4793596ba0f656ac94935cb8766da0d88bb3a3f067c37adb56ff21128c2c7803

6

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x5488
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.54325
MD5 35a572a0fd0dfe4970497ba0f06d3b0a
SHA1 d63cc92819364a2c2bee9f17e19ef51a748f52b3
SHA256 d04fd6a5669717bc3602438196b2f89086f424cfb621af5e7ad2b5c0dbd13a05
SHA3 b44bce84daea8750dda47b14859bbef52795ced32772f05979f67d2d33233452

7

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35885
MD5 a652b97dd9efddcca222ad1172e5b273
SHA1 d704d42dca8cffb098b5181e087cb96403685aa4
SHA256 2daf4c9a35f727a3d8ec18f588835865766f84856c90bfc0de576fec919207eb
SHA3 61a7e1b01c72116f911b5d0cceed948597dc386e5bc133320e47587ed63af561

8

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15562
MD5 a5f59bd26cb694b60ac8b88c725de748
SHA1 543a299fd583b58545776f53fe5bdcb3a387a6e2
SHA256 165efc16eab3b25232ee9afd19ca3449155bdc98a666637f8c9e933c716998fb
SHA3 817e73dfe228c68ab20d4b73b68a3bbc22da9ab909607b5d0ff58339442007be

9

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0xb981
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.96706
Detected Filetype PNG graphic file
MD5 ffa6c1243c052eda48ca3ace2c5c441f
SHA1 eb2904a3260abe2ae6a1c948c2ffce0823bb01d4
SHA256 345f14c07964def3d084fe9627264c0ff967e83b942010b4291207bd0df4a668
SHA3 5409a2f6e9e4012c5e4d1f0bcf831a4d7afa3c1a7dd9dae4cff990305f417698

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.03466
Detected Filetype Icon file
MD5 ac6ea610406bcce37d57f2d5c2af4dc8
SHA1 6dcc61e7fd867acb63f4871e4174d240dbb1c554
SHA256 f8ac4eb960b4f4a7278504063f5c5bd56ca4c7892125924d79f4ac9efd9df8ea
SHA3 d8eb572876c0c1cf0db5be243577de2cf21ca691e12ba6c5d1128dc7e3ce6778

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x36c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3892
MD5 95e27286efd60b15ff2b1e69c5965e99
SHA1 c7b3031ab5278b5649b1c759864204f515145758
SHA256 a3fb2e86de2caaca7e10605f826e18ab20e7fc1f5058793297f9a4c6a03dbfd2
SHA3 595b0f3af14fb0abd2e41ab6d636403f859f07fede9c4a0341cb4b3ede5d0258

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0xd53
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.01752
MD5 a99c09dbd4a65da324e2d732f5351786
SHA1 164d3ec47c9487bd42d9ec580fb730a61dc156d7
SHA256 59c778ad5af1032a264960d8cf35e7b4226e9ab5d1d9cbe91d4f93b347768b88
SHA3 5e12a029662dd5cc2e838e5e40d2e0715685e718c429233ccb2e35881abdd4e6

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments
CompanyName
FileDescription UID BYPASS INSTALLER V1
FileVersion (#2) 1.0.0.0
InternalName UID BYPASS V1.0.exe
LegalCopyright Copyright © 2026
LegalTrademarks
OriginalFilename UID BYPASS V1.0.exe
ProductName UID BYPASS INSTALLER V1
ProductVersion (#2) 1.0.0.0
Assembly Version 1.0.0.0
Resource LangID UNKNOWN

TLS Callbacks

Load Configuration

RICH Header

Errors

Leave a comment

No comments yet.