Nudes-Package.exe

First submission 2023-09-15 08:36:31

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
Mime type: application/x-dosexec
File size: 55694.0 KB (57030653 bytes)
Compile time: 2018-12-15 23:26:14
MD5: 005b1f4d6729d95ddf2dba7a5e3784f9
SHA1: 485f5b3997eb05dfb1c93b87df82427071453490
SHA256: f5cc6323609dd029809f3a08012e9a00cdf4ff68308ab0092d4d5f3cef0844af
Import Hash : b34f154ec913d2d2c435cbd644e91687
Sections 5 .text .rdata .data .ndata .rsrc
Directories 3 import resource security
Virus Total:

File features detected

Is DLL

Packers

Anti Debug

Anti VM

Signed

XOR

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXps://cdn.discordapp.com/attachments/1142516762299093186/1151977915991466005/Nudes-Package.exe VirusTotal Report cdn.discordapp.com VirusTotal Report 2023-09-15 08:36:31

PE Sections 1 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x6627 26624 0e5e99bb884a9fe9f4dee59b6bf9acf9746f3115 7618d4c0cd8bb67ea9595b4266b3a91f
.rdata 0x8000 0x14a2 5632 0a0c2be86d54840b2eaa4abf2412bb3588e032c4 eecac1fed9cc6b447d50940d178404d8
.data 0xa000 0x70ff8 1536 bdd9e7400edf5b4fddcffb66fcb1d3d83c8901da db8f31a08a2242d80c29e1f9500c6527
.ndata 0x7b000 0x90000 0 da39a3ee5e6b4b0d3255bfef95601890afd80709 d41d8cd98f00b204e9800998ecf8427e
.rsrc 0x10b000 0x42ac0 273408 3cae919b06cac7497906ae985c31e207c3294bcd 4044ec1105bb339a1dd0167eda6e9d24

PE Resources 5

Name Language Sublanguage Offset Size Data
RT_ICON LANG_ENGLISH SUBLANG_ENGLISH_US 0x10b1d8 270376
RT_DIALOG LANG_ENGLISH SUBLANG_ENGLISH_US 0x14d3f8 96
RT_GROUP_ICON LANG_ENGLISH SUBLANG_ENGLISH_US 0x14d458 20
RT_VERSION LANG_ENGLISH SUBLANG_ENGLISH_US 0x14d470 784
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x14d780 830

Meta infos 7

LegalCopyright: Copyright \xa9 2023 Copyright Microsoft Corporation. All rights reserved.
ProductVersion: 1.0.0
CompanyName: Copyright Microsoft Corporation. All rights reserved.
FileVersion: 1.0.0
FileDescription: VideoGames is a video game
Translation: 0x0409 0x04e4
ProductName: VideoGames

Anti debug functions 2

FindWindowExW
GetLastError

File signature

MD5 SHA1 Block size Virtual Address
d41d8cd98f00b204e9800998ecf8427e da39a3ee5e6b4b0d3255bfef95601890afd80709 10192 64563644

Strings analysis - File found

Executable
%y.SO
Database
1`!F e.DB
Library
%s%s.dll
ADVAPI32.dll
GDI32.dll
SHELL32.dll
USER32.dll
COMCTL32.dll
ole32.dll
KERNEL32.dll
Web Page
U .pHP

Strings analysis - Possible URLs found 1

http://nsis.sf.net/NSIS_Error

Import functions

Name Latest seen MD5
HBZ.exe 2023-06-15 06:59:01 cc0a1c96c14263e48f82965ff47e0521
LUK.exe 2023-06-15 07:41:02 8f488bf3643183b3e0eddfb0ee888083
EYG.exe 2023-06-19 15:43:02 3d4b36f562038a18fc835188470973c7
DamnedInstaller.exe 2023-07-07 09:06:15 c4dd1dbdaf1a8f596f94670846511d31
cosmicdirftsbeta.exe 2023-07-31 13:35:14 296552ede6571789ff56aad76634598f