f371afcc19fcdbb16d5e55db7d43f526

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Mar-05 02:57:48
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.

Plugin Output

Suspicious The PE is possibly packed. Unusual section name found: .buildid
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryW
Safe VirusTotal score: 0/72 (Scanned on 2025-01-06 12:16:06) All the AVs think this file is safe.

Hashes

MD5 f371afcc19fcdbb16d5e55db7d43f526
SHA1 be62aa14795c2a334eef3fdd33194adc0b485a00
SHA256 38a58237613673d989e7f8e2cdc3efaa1484693e8cd1182899a117a98c966b5e
SHA3 c9b40c16ea0ea5348bd17cc46f1766e413d006f195f9a822ccf11f50e56ccb41
SSDeep 1536:r1yHDJRL07BK6Up8DUSeoMmiiHu2GaHkOrA:cPp1J3riH/5A
Imports Hash a9563ca2ee659a9314820bead4ec962b

DOS Header

e_magic MZ
e_cblp 0x78
e_cp 0x1
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x78

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2024-Mar-05 02:57:48
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x1e00
SizeOfInitializedData 0x17600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001140 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x15000
SizeOfHeaders 0x400
Checksum 0x1635a
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 612f13b1a20949bba1c805c638495c00
SHA1 8e74a79958acf6488fe615dee4173a4b96e39fae
SHA256 4ab9a6254f73f4956601a46361357f0ad92d238a43ae6f8eab200fa5047c1415
SHA3 1e7a84cf73f8503dee0f05389252d65ec5d8e1cb349fe970a29a24a6db3def5a
VirtualSize 0x1c86
VirtualAddress 0x1000
SizeOfRawData 0x1e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.77527

.rdata

MD5 dcb7faae7abc7c1dfadac4c2855067fa
SHA1 cae7ca686a9024d78f8289ce8674185151ec9550
SHA256 38d9791ed6ef45149712782f4a0ccfb42f23c02b3a4492ca7f03e53b9cbdecdc
SHA3 7f6f0f51025e8dd9feeb07420ea2050bd7396785845219b11465ff5de10d62bc
VirtualSize 0x114c
VirtualAddress 0x3000
SizeOfRawData 0x1200
PointerToRawData 0x2200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.35065

.buildid

MD5 af91219ca9a402e642ad67d0bd2f58ba
SHA1 28facc77e880fbc54136f6e833aaa95ce34bcf12
SHA256 80ad9b0d8c35908487e26d54f03d4f817466683af86f062285e7e88393a5231a
SHA3 26e1c2593b5a9502bf15c5bdb9cd49c1caf0bc9d6186b430059b60e66e97ccbf
VirtualSize 0x35
VirtualAddress 0x5000
SizeOfRawData 0x200
PointerToRawData 0x3400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.600755

.data

MD5 d36e8e0be902e9d81289ba090cc311e5
SHA1 6d2c8cf042080bc1196e5565f5b2aa7854c74458
SHA256 a028f657d3a4672e79bfecb170e886116cbd0b06e428d842c91c20f05784ec66
SHA3 eb6eebff34b04427a10388b0c0285cbd5904f812b78d60a49dbd74bd6afa4325
VirtualSize 0x1bc
VirtualAddress 0x6000
SizeOfRawData 0x200
PointerToRawData 0x3600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.42505

.pdata

MD5 96b91119ce3f4f34345e33b607b00a4d
SHA1 47f375ecbcc5dee11fcadc69f4f66feaa2812e65
SHA256 6b6d61042d983cc28576e611fed69c351522e7188a7fe4ad6b870276bff8351d
SHA3 f839da7b9cf99a56b06fe69b6fc83d09a617654109243f8a352898a60c299d0c
VirtualSize 0x18c
VirtualAddress 0x7000
SizeOfRawData 0x200
PointerToRawData 0x3800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.12203

.tls

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0x8000
SizeOfRawData 0x200
PointerToRawData 0x3a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 7fdba64c5ad1cf07ffc9a56b5466d5ed
SHA1 3bde550adb7a64d937456097ce32a2356b9cde98
SHA256 6b03c15a34ceedeeaab8642a251423dbba83edbd184478f58b10752631e38c34
SHA3 dd2014869b5c0ebae9171c4eb734ad35d2316c8098a95823f0066370b74aefe2
VirtualSize 0xb910
VirtualAddress 0x9000
SizeOfRawData 0xba00
PointerToRawData 0x3c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.84315

Imports

api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
calloc
free
malloc
api-ms-win-crt-private-l1-1-0.dll __C_specific_handler
memcpy
api-ms-win-crt-runtime-l1-1-0.dll __p___argc
__p___argv
__p___wargv
__p__wcmdln
_cexit
_configure_narrow_argv
_configure_wide_argv
_crt_at_quick_exit
_crt_atexit
_initialize_narrow_environment
_initialize_wide_environment
_initterm
_set_app_type
_set_invalid_parameter_handler
abort
exit
signal
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
__p__commode
__p__fmode
__stdio_common_vfprintf
__stdio_common_vfwprintf
__stdio_common_vswprintf
fwrite
api-ms-win-crt-string-l1-1-0.dll _wcsdup
memset
strlen
strncmp
wcslen
USER32.dll MessageBoxW
KERNEL32.dll DeleteCriticalSection
EnterCriticalSection
GetLastError
GetProcAddress
GetStartupInfoW
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryW
SetDllDirectoryW
SetUnhandledExceptionFilter
Sleep
TlsGetValue
VerSetConditionMask
VerifyVersionInfoW
VirtualProtect
VirtualQuery
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
api-ms-win-crt-environment-l1-1-0.dll __p__environ
__p__wenviron
api-ms-win-crt-time-l1-1-0.dll __daylight
__timezone
__tzname
_tzset

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.57231
MD5 501e8af424332e3558cc240782ffd610
SHA1 b4c2f687ccedc9d256e7eb46cd582f60e7586c96
SHA256 c2d382e6f8793db8b2b875ca457ca4775b71fd6bc0983361f779419a25097f53
SHA3 40791185f8639cbf8135624a59eb24ea6742cac586bb440cbcf2c5c24c2b36e9

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.60793
MD5 1aee0c561610365c71378c0db43ad8fc
SHA1 926c4552265089a8ca873da11e6a77dc23a48bed
SHA256 96a6a400cbc2334f65d4313c0a81fbb5490f27665287384562f5a1d91c12779f
SHA3 895b64a0b95d6bcd8e04f478c2f289c1c620fd47c799b1831e62cb56e428f560

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.63694
MD5 00a8dedc7f9a3c7e53e591404a18e22b
SHA1 b4099feb1e6193052d8b93c7e6e66afa241e0794
SHA256 9c22f9ed11692c4bd7a7a245467eec84fcd4ffcb5a8dfac6cc10f2ce15f7e1a8
SHA3 e57294781ea68c8029174409c48d04baea51f2369c98aa7df0ebba1043903017

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.55421
MD5 9e5a7f724962804350bd629d4f1ceba9
SHA1 b7b5c9c24d132883d9698402ec102d585d36c213
SHA256 8fa92336d3ed3ba21083a6f46bdd1328742ca8b36ac83cf81e8dde4e3228ece5
SHA3 397a18cfc58b7be04d1e2c4160ae3835a9d60c6bbbd02d2d323d8018df147507

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x7323
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92486
Detected Filetype PNG graphic file
MD5 d0fb7f340bab844605a52a4bf2e2836c
SHA1 762a1b9b3258e3cafda598039f8393d067a40c26
SHA256 e6ffe64a20bfe5a665a95dc0027107b84b382b217422a164a82df11a123eff52
SHA3 dd9738fb89a344b7020140ea91807a9da6e6c1dc7a5802a5fcbe5235b5bd8d4c

1 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.64638
Detected Filetype Icon file
MD5 9e8f9e7e98ec8ab0a30e49400c5fd78d
SHA1 c82458e9b53b8800a3996cbfc7c934c81a8b2b26
SHA256 358de0a8c0d6bd75c2710b85411953cd6538be1a6a1ad5c7531ed7ccb7181a32
SHA3 192b4d65557dd08ce4e3a47886b481e887658ee038cc8aef97f3ccb05dc5701a

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2024-Mar-05 02:57:48
Version 0.0
SizeofData 25
AddressOfRawData 0x501c
PointerToRawData 0x341c

TLS Callbacks

StartAddressOfRawData 0x140008000
EndAddressOfRawData 0x140008008
AddressOfIndex 0x140006128
AddressOfCallbacks 0x140003530
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x0000000140001780
0x0000000140001800

Load Configuration

RICH Header

Errors

[!] Error: Could not reach the requested directory (offset=0x0).
<-- -->