ed38c3387157776faa5848e63bde2b6af60858b73381216791bf0ebd5f5fa998

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_NATIVE
Compilation Date 2026-Apr-24 15:13:31

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentControlSet\Services
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA1
Uses constants related to SHA256
Suspicious The PE is possibly packed. Unusual section name found: PAGE
Unusual section name found: .cod0
Suspicious The PE contains functions most legitimate programs don't use. Functions which can be used for anti-debugging purposes:
  • ZwQuerySystemInformation
Uses Windows's Native API:
  • ZwCreateFile
  • ZwQueryInformationFile
  • ZwReadFile
  • ZwClose
  • ZwAllocateVirtualMemory
  • ZwFreeVirtualMemory
  • ZwOpenFile
  • ZwQueryDirectoryFile
  • ZwFsControlFile
  • ZwOpenProcess
  • ZwDeviceIoControlFile
  • ZwCreateEvent
  • ZwWaitForSingleObject
  • ZwOpenKey
  • ZwQueryValueKey
  • ZwSetValueKey
  • NtBuildNumber
  • ZwSetInformationThread
  • ZwOpenDirectoryObject
  • ZwQueryInformationProcess
  • ZwQueryInformationThread
  • ZwQueryDirectoryObject
  • ZwSetSecurityObject
  • ZwCreateKey
  • ZwQuerySystemInformation
Info The PE is digitally signed. Signer: Microsoft Windows Hardware Compatibility Publisher
Issuer: Microsoft Windows Third Party Component CA 2014
Suspicious VirusTotal score: 2/64 (Scanned on 2026-09-15 18:18:16) APEX: Malicious
McAfeeD: ti!ED38C3387157

Hashes

MD5 9fedb8e2d3edf2e67dfea9815cb7f8c6 🔍
SHA1 40dc6681cfd5dfe64dfadac1bada797002e2d455 🔍
SHA256 ed38c3387157776faa5848e63bde2b6af60858b73381216791bf0ebd5f5fa998 🔍
SHA3 9ec44459a4371e5fa04dff9d218d3643d163267bd54b6c6f139d3ddb05cf7577 🔍
SSDeep 196608:fzTEGgSXdLSxAPV7Kj3fE4htNvUbyl6aTpPYKijSUHGVVu0VpDUiZPKp:fzTEGgcdL8APVmM4tBvPriBHOoaPKp 🔍
Imports Hash c79eb0f05cfa627d03b7bb11dc9e1315 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 8
TimeDateStamp 2026-Apr-24 15:13:31
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x35a00
SizeOfInitializedData 0x11cb400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000001201000 (Section: INIT)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion A.0
ImageVersion A.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0x1c12000
SizeOfHeaders 0x400
Checksum 0xa75ee9
Subsystem IMAGE_SUBSYSTEM_NATIVE
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_FORCE_INTEGRITY
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 f931b4f11eeb18ae1fde660b22d72d96 🔍
SHA1 311f55e5ada50a61e04a314334924d4573f4ba76 🔍
SHA256 b4afa825bf02a6ec8e033b88ab6e306f5622b384c214d5d57bb8f5d5b9199013 🔍
SHA3 8e3db783a80917f290332622ff3db361cfc5c60409a619604683c01e144345cd 🔍
VirtualSize 0x32895
VirtualAddress 0x1000
SizeOfRawData 0x32a00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
Entropy 7.33891

.rdata

MD5 6ebce7234191bcfd7f7c13c8f0a774eb 🔍
SHA1 d79fe2eb47755d1619115965cead88da1f771ec8 🔍
SHA256 b22e15c69b44d1e8e550f37909d7dfccf0d43f5398044b0f7cab1d24d1e1d7c5 🔍
SHA3 2a07cfcbcc23d79ed34c216c39d2da4ca1a5264aa91e78f85d50122c14dbb260 🔍
VirtualSize 0x9594
VirtualAddress 0x34000
SizeOfRawData 0x9600
PointerToRawData 0x32e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
Entropy 5.21442

.data

MD5 c64577e4f41113c60b59e69723e1afaf 🔍
SHA1 4231365af2b6d09f229fc36f80933878aaa9527a 🔍
SHA256 86dd2cbc10ed2c46625dc0f21a11cca73de1db547cce65e321ffe2c9e28b734b 🔍
SHA3 866806640fe6cd8dc3df67d305bffd85390ca901d2fd08237f38d5d1bcd75819 🔍
VirtualSize 0x11bdfbc
VirtualAddress 0x3e000
SizeOfRawData 0x14400
PointerToRawData 0x3c400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.61012

.pdata

MD5 656441ea9098473a49fc6f86c09a0251 🔍
SHA1 dc802d95900683199569870ae6a37e4733efadb8 🔍
SHA256 81559b8a7eda895cd588b6f2afc4cea2e9acb7d821972e3a9ffd6e5e763f98c1 🔍
SHA3 80e68a0340109219a3c79726ac9abf9b31b8c637e1b1ce9f676aa09dd6a6e804 🔍
VirtualSize 0x2280
VirtualAddress 0x11fc000
SizeOfRawData 0x2400
PointerToRawData 0x50800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
Entropy 7.77914

PAGE

MD5 18a06b708c93947290da45080d0d8e71 🔍
SHA1 5de4962403e4c93a0aedc6538ebdca687b717228 🔍
SHA256 a192bf451ee13b2030831a57e7793ce6438ab2cf0868ca5b8fc490a1ce533bd3 🔍
SHA3 5f3bb8df2b2d9ae1a8328a4212b206d28c7d6b84314a483d8698ac687303a4b6 🔍
VirtualSize 0x1f67
VirtualAddress 0x11ff000
SizeOfRawData 0x2000
PointerToRawData 0x52c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.25982

INIT

MD5 52ea08995119d94b6535cfbd517b2a93 🔍
SHA1 0d9d81cb13a0c6fddad038d1d867906c8da1efec 🔍
SHA256 e02213ed839ab4834b84f5572c0c3a0e65693f1befdc83e944f5786d8639ed5c 🔍
SHA3 0f13ea89ccd63db8a2de3e4ac4d67e45ab826feb4c95d6854530709a26c180e5 🔍
VirtualSize 0xfdc
VirtualAddress 0x1201000
SizeOfRawData 0x1000
PointerToRawData 0x54c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.45807

.cod0

MD5 001f7b5d36ec55b84c614b532531626c 🔍
SHA1 f04f9cbbff7ad52b2aa61c2f595bfb329df0911b 🔍
SHA256 f5063b5da7cb869a9bff03b7a0aaa0f1017a7d9d351ddfda30930fda5c725893 🔍
SHA3 35406e4aed90c2a5d03ccf09969e216110d5de8c070d1c7c35d6c4d216406d1d 🔍
VirtualSize 0xa0db48
VirtualAddress 0x1202000
SizeOfRawData 0xa0dc00
PointerToRawData 0x55c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
Entropy 7.61827

.reloc

MD5 b59fdce7869d401fb1094c88573c850a 🔍
SHA1 3f242893dc5855986eb10b6b8a97238d64fbacf6 🔍
SHA256 cff3390f0239636d82a9887845eb8ab992903c8a65bc86fd6044c787d4e7174d 🔍
SHA3 22ad1eb1761f9f68fd92e528db79d78ca445e50ff7fae53e1bdf5ba0f18fa767 🔍
VirtualSize 0x1990
VirtualAddress 0x1c10000
SizeOfRawData 0x1a00
PointerToRawData 0xa63800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.49286

Imports

ntoskrnl.exe ExAllocatePoolWithTag
ExFreePoolWithTag
ZwCreateFile
ZwQueryInformationFile
ZwReadFile
ZwClose
RtlInitUnicodeString
KeGetCurrentIrql
KeDelayExecutionThread
KeWaitForSingleObject
PsCreateSystemThread
ObReferenceObjectByHandle
ObfReferenceObject
ObReferenceObjectByPointer
ObfDereferenceObject
MmIsAddressValid
PsGetCurrentProcessId
IoGetRequestorSessionId
__chkstk
PsThreadType
IoDriverObjectType
ExAcquireFastMutex
ExReleaseFastMutex
IoGetCurrentProcess
KeStackAttachProcess
KeUnstackDetachProcess
RtlEqualUnicodeString
PsLookupProcessByProcessId
MmGetSystemRoutineAddress
PsLookupThreadByThreadId
ZwAllocateVirtualMemory
ZwFreeVirtualMemory
RtlRandomEx
__C_specific_handler
wcsnlen
KeInitializeEvent
IoBuildDeviceIoControlRequest
IofCallDriver
ZwOpenFile
ZwQueryDirectoryFile
ZwFsControlFile
RtlInitAnsiString
RtlAnsiStringToUnicodeString
RtlFreeUnicodeString
ZwOpenProcess
ObQueryNameString
strcmp
IoFileObjectType
ZwDeviceIoControlFile
ZwCreateEvent
ZwWaitForSingleObject
_stricmp
ExGetPreviousMode
IoThreadToProcess
PsProcessType
IofCompleteRequest
ProbeForRead
ProbeForWrite
MmMapIoSpace
MmUnmapIoSpace
MmGetPhysicalAddress
sprintf
ExAllocatePool
ExFreePool
strlen
KeSetEvent
PsGetProcessId
ObOpenObjectByPointer
RtlIsNtDdiVersionAvailable
KeClearEvent
KeResetEvent
KeQueryTimeIncrement
PsTerminateSystemThread
IoCreateNotificationEvent
IoCreateSymbolicLink
IoDeleteDevice
IoDeleteSymbolicLink
ZwOpenKey
ZwQueryValueKey
ZwSetValueKey
ExUuidCreate
PsSetCreateProcessNotifyRoutine
PsSetCreateThreadNotifyRoutine
PsRemoveCreateThreadNotifyRoutine
PsSetLoadImageNotifyRoutine
PsRemoveLoadImageNotifyRoutine
IoGetRequestorProcessId
IoGetRequestorProcess
MmHighestUserAddress
MmSystemRangeStart
NtBuildNumber
toupper
towupper
_wcsnicmp
RtlAppendUnicodeStringToString
RtlAppendUnicodeToString
ZwSetInformationThread
ZwOpenDirectoryObject
PsGetProcessSectionBaseAddress
ZwQueryInformationProcess
ZwQueryInformationThread
ZwQueryDirectoryObject
_vsnwprintf
wcslen
_vsnprintf
RtlImageDirectoryEntryToData
ZwSetSecurityObject
IoDeviceObjectType
IoCreateDevice
RtlGetDaclSecurityDescriptor
RtlGetGroupSecurityDescriptor
RtlGetOwnerSecurityDescriptor
RtlGetSaclSecurityDescriptor
SeCaptureSecurityDescriptor
_snwprintf
RtlLengthSecurityDescriptor
SeExports
RtlCreateSecurityDescriptor
wcschr
RtlAbsoluteToSelfRelativeSD
RtlAddAccessAllowedAce
RtlLengthSid
IoIsWdmVersionAvailable
RtlSetDaclSecurityDescriptor
ZwCreateKey
PsGetVersion
ExAllocatePoolWithQuotaTag
ZwQuerySystemInformation
KeBugCheckEx

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140052380

RICH Header

Errors

Leave a comment

No comments yet.