ffd9273d8de6b9ba66adc5a2acff0761061cdb89e1d0f4ca972b86ed004b23af

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1970-Jan-01 00:00:00
Debug artifacts Embedded COFF debugging symbols

Plugin Output

Suspicious PEiD Signature: XWD graphics format
HQR data file
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • rundll32.exe
Tries to detect virtualized environments:
  • HARDWARE\DESCRIPTION\System
May have dropper capabilities:
  • CurrentControlSet\Services
Contains domain names:
  • .eq.github.com
  • .eq.golang.org
  • .hash.net
  • anydesk.com
  • api.ipify.org
  • download.anydesk.com
  • eq.github.com
  • eq.golang.org
  • github.com
  • golang.org
  • http://127.0.0.1
  • http://download.anydesk.com
  • http://download.anydesk.com/AnyDesk.execipher
  • https://api.ipify.org
  • https://api.ipify.org?format
  • https://go.dev
  • https://icanhazip.comset
  • https://ifconfig.me
  • https://www.windows.com
  • https://www.windows.com/stopcode
  • ipify.org
  • itab.github.com
  • itab.golang.org
  • textproto.nl
  • windows.com
  • www.windows.com
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Suspicious The PE is possibly packed. Unusual section name found: .xdata
Unusual section name found: /4
Unusual section name found: /19
Unusual section name found: /32
Unusual section name found: /46
Unusual section name found: /65
Unusual section name found: /78
Unusual section name found: /95
Unusual section name found: /112
Unusual section name found: .symtab
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 5204f3455a56d902dbb29faf6560a987
SHA1 0143e68a8a66c06a8de9c67c302cb8c46864ae60
SHA256 ffd9273d8de6b9ba66adc5a2acff0761061cdb89e1d0f4ca972b86ed004b23af
SHA3 989f8f9a6be6c7f0eeb19cb95c13f5338a04e556ff5adf9f08b7510dfe1aff20
SSDeep 98304:MOsz5A57/fvv2wo/lwhjY35numvBh8hufUE98Wx4m8cBA/BtPzT3rzXVzez5x:MTy5ywouO9SE48abX0z
Imports Hash ed8b780a3ce7ca4aba78a21f6bc3d4e0

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0x8b
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 16
TimeDateStamp 1970-Jan-01 00:00:00
PointerToSymbolTable 0xae3800
NumberOfSymbols 12199
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 3.0
SizeOfCode 0x39e000
SizeOfInitializedData 0x69800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000088A60 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 1.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0x2be3000
SizeOfHeaders 0x600
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 007c43cb37d3a20e8db1c7e0670328f4
SHA1 1b52b534f8860480dc585b518af9d52c683a577e
SHA256 742150fc0e6c6f5edd3c847de8c6cd8a89277268651fc9a5b4478ff27626e662
SHA3 f1cbaed774f71d7e03e1e31bb01f53d07a44c58aa79eec2bcb44892511c308d4
VirtualSize 0x39df51
VirtualAddress 0x1000
SizeOfRawData 0x39e000
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.20982

.rdata

MD5 9915b627b1ba9224bb0d9ab2432b885f
SHA1 401d0e06dc403cdf9f9a8dbb02e81a52f6e2cb02
SHA256 75546078a33ffe394b3f50ceb4c9e3f89eced3ac0222e8450c51b142879111fc
SHA3 e324a4ff3b505108e14d27fd5221e494339b7349934b6c81d29e950610c0622c
VirtualSize 0x3cea60
VirtualAddress 0x39f000
SizeOfRawData 0x3cec00
PointerToRawData 0x39e600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.67825

.data

MD5 9e84948ba480e86b2aa9c1e58d8e9a7f
SHA1 00ab3ec7cae40a9e098d6210b141b44d00f24ab6
SHA256 6c37de292e4ad01678265ba8af9688f600ac335e30256c63fe5ffb72de9ffc1a
SHA3 1b164a92db01f0d34c1b64684ed9bfda85c90f4fd7331b8b389ab582d972b26f
VirtualSize 0x20c16c0
VirtualAddress 0x76e000
SizeOfRawData 0x69800
PointerToRawData 0x76d200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.59786

.pdata

MD5 a609841424ad2066a0a0d62e5e262f5e
SHA1 424be4800c34557ce13dc527d0822cbdf08e40f0
SHA256 c191cd824e50349069830f9fbe482e7a4559180ecba383a3ee113065435fbe83
SHA3 2b7aefc09a341a265cc909d22170a9d9e66766eb307d1883fc87d8c298f78f56
VirtualSize 0x155f4
VirtualAddress 0x2830000
SizeOfRawData 0x15600
PointerToRawData 0x7d6a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.67278

.xdata

MD5 b921dbd5ea0834f209b22591277c9cb7
SHA1 7d0b107088bab2861e3b18cf708d72ce4d0c0ba5
SHA256 1278be19261cbb7b44b440f1e7bda45b865e73b98f39d5090fb58876e38d02f0
SHA3 596f65bfe91bf8f455ccee038895b47fac2e7f54835f6fdbfee2c1d1d763bc84
VirtualSize 0xb4
VirtualAddress 0x2846000
SizeOfRawData 0x200
PointerToRawData 0x7ec000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.78711

/4

MD5 bcddef00414a946919302442928e542e
SHA1 b0fbeae40093e8241edcbdeae94ba06880dedf04
SHA256 fb7bf682d27ba8920146a9b134a183cd2109b202916488b9b3a4f7d623f0b484
SHA3 7d5b252590738bde977b6dfab9c3034c2ad82b952980a3585c1dc88e1f06f005
VirtualSize 0x154
VirtualAddress 0x2847000
SizeOfRawData 0x200
PointerToRawData 0x7ec200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.67257

/19

MD5 bf4054200b9cf8502cd607996349bb31
SHA1 9bf09087f6ad2c92c365c122e998513a2a4e597a
SHA256 d6e3373a86eec0cb92c36a03ddc09fb6f226ca7520f4054ee9b8a5373fd2b3da
SHA3 28ae5d0d05f2edd108b5b4028800199df0a4c917f774a00081bd0cb4da61494a
VirtualSize 0xa3ba5
VirtualAddress 0x2848000
SizeOfRawData 0xa3c00
PointerToRawData 0x7ec400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.99584

/32

MD5 17d3475f7574a574f3924e4d88281507
SHA1 a760e665e2e662a223fa7cf25276cc9bfc1ca7e3
SHA256 48606881972e3bc2324385bcd2851f51513d2be63255c6b984404c79fdfd154e
SHA3 040407a77f6a846b16c8822a0372c6fa0ab3b642b812af7fdb298a2047e5f551
VirtualSize 0x220d4
VirtualAddress 0x28ec000
SizeOfRawData 0x22200
PointerToRawData 0x890000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.94336

/46

MD5 40cca7c46fc713b4f088e5d440ca7931
SHA1 3aaa1650bfaf5325fa9cb3a1a284aebcc92aebf4
SHA256 3e3c5f5d419b70e588da0ef0e3d9ce1a5863a5624febc16cd0c007cd14e89015
SHA3 a0e18fe9f6ac46417d52cdc99cf9ae56edb5a53f788995a085b10f88f348a0e4
VirtualSize 0x30
VirtualAddress 0x290f000
SizeOfRawData 0x200
PointerToRawData 0x8b2200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.855685

/65

MD5 92368ec70192788b92803f92cb5e7499
SHA1 a21bc866cc7c074df45473aa257e0aa3159d149b
SHA256 b9d0632653b05bb1d9689148fb4df288e777c53ef0296d9dfaab4319f1b43ade
SHA3 fc32e3c190fd1c191f1cf8ce9771d2130f89dd29d628e6eca18612c04251c44f
VirtualSize 0x1398a4
VirtualAddress 0x2910000
SizeOfRawData 0x139a00
PointerToRawData 0x8b2400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.99871

/78

MD5 aef75e4dc08fa6f71145c5f6fdb1552f
SHA1 fc6512d90551f3e6b419ee88ba2bbd530d39da7a
SHA256 29048b8864fe8bd7bc363985837208f47c6fa7367d93434b77ee4215f6238085
SHA3 9d6791bbe5b906cba54dc3083a8794b88710636cc1dfd3edad698dc32d8d16f1
VirtualSize 0xa05bc
VirtualAddress 0x2a4a000
SizeOfRawData 0xa0600
PointerToRawData 0x9ebe00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.99782

/95

MD5 c556ed7dcfa4885528dcaf9cdf00f7ed
SHA1 2e03fff20f8e88c3762b48d55c83f445d76c61e3
SHA256 7de85c74a2650977c25eb752f4130233fe1c60f9dbf46c6b6a1e57e3e1eee318
SHA3 b578d54567a684962666176f6edf90e2509d53a95763ddfe319ae5c203b0611b
VirtualSize 0x3f98f
VirtualAddress 0x2aeb000
SizeOfRawData 0x3fa00
PointerToRawData 0xa8c400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.99614

/112

MD5 73094a71fc0a14045f193c963475cec0
SHA1 4ea94e5d170588430094ac89b0da3145ff1c2b41
SHA256 a9442c3c8db365aa87c29facf4adaf5a57832a6b22667d67779d43cb967f3950
SHA3 62fc60af682b79a0ad5286822bde70cc260e6cad6040cb3d0f52876ef0987924
VirtualSize 0x4411
VirtualAddress 0x2b2b000
SizeOfRawData 0x4600
PointerToRawData 0xacbe00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.73492

.idata

MD5 72d54942c7b1bd98066043f9346cb917
SHA1 0fcc8a31691e5981b4ec48d79eb2b055c5fcc07d
SHA256 017394c420c5cf4c37f3eaf812f523bcaf912257eed637e998c00374bb3dbc1a
SHA3 5b96f21d13aaf3d8387ea6fbf2ac971e527bbf87bd14fa0f148fe9aa15836aa0
VirtualSize 0x57c
VirtualAddress 0x2b30000
SizeOfRawData 0x600
PointerToRawData 0xad0400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.21783

.reloc

MD5 57c0a90a7e0f4826117051d9925f00c4
SHA1 bb170abca82dff6215521131ba9811c38e471d68
SHA256 35ffbadb9e9f457daccde6a0ab4a1302d7f7d1755ca5b9d55acead8dd6282b9f
SHA3 ccef5bff8cd64f52abc998ef7dc8ab34f3595f6f487919932a897bf722549f80
VirtualSize 0x12ca8
VirtualAddress 0x2b31000
SizeOfRawData 0x12e00
PointerToRawData 0xad0a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.42358

.symtab

MD5 f4ba1c6ee2963ae50ea9c90c3f12f8b1
SHA1 9aea442009a05fe21df6679beaf75dea20ef4d8b
SHA256 53e5a8525d740f6a2fc2e86df9dae0b80ca52effeb8b581dfa0aff128e2ddcab
SHA3 93c464eb158d6705ee90483fedc39f32f10fc9c3d146a88b60888a6581cf2b80
VirtualSize 0x9ed25
VirtualAddress 0x2b44000
SizeOfRawData 0x9ee00
PointerToRawData 0xae3800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.39358

Imports

kernel32.dll GetProcAddress
LoadLibraryExW
WriteFile
WriteConsoleW
WerSetFlags
WerGetFlags
WaitForMultipleObjects
WaitForSingleObject
VirtualQuery
VirtualFree
VirtualAlloc
TlsAlloc
SwitchToThread
SuspendThread
SetWaitableTimer
SetProcessPriorityBoost
SetEvent
SetErrorMode
SetConsoleCtrlHandler
RtlVirtualUnwind
RtlLookupFunctionEntry
ResumeThread
RaiseFailFastException
QueryPerformanceCounter
PostQueuedCompletionStatus
LoadLibraryExW
SetThreadContext
GetThreadContext
GetSystemInfo
GetSystemDirectoryA
GetStdHandle
GetQueuedCompletionStatusEx
GetProcessAffinityMask
GetProcAddress
GetErrorMode
GetEnvironmentStringsW
GetCurrentThreadId
GetConsoleMode
FreeEnvironmentStringsW
ExitProcess
DuplicateHandle
CreateWaitableTimerExW
CreateThread
CreateIoCompletionPort
CreateEventA
CloseHandle
AddVectoredExceptionHandler
AddVectoredContinueHandler

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

RICH Header

Errors

[*] Warning: Tried to read outside the COFF string table to get the name of section /4! [*] Warning: Tried to read outside the COFF string table to get the name of section /19! [*] Warning: Tried to read outside the COFF string table to get the name of section /32! [*] Warning: Tried to read outside the COFF string table to get the name of section /46! [*] Warning: Tried to read outside the COFF string table to get the name of section /65! [*] Warning: Tried to read outside the COFF string table to get the name of section /78! [*] Warning: Tried to read outside the COFF string table to get the name of section /95! [*] Warning: Tried to read outside the COFF string table to get the name of section /112!
Leave a comment

No comments yet.