2_xnfile.exe

First submission 2024-10-15 06:43:02

File details

File type: PE32+ executable (GUI) x86-64, for MS Windows
Mime type: application/x-dosexec
File size: 1155.93 KB (1183672 bytes)
Compile time: 2024-10-14 09:59:31
MD5: 0b4ad3d05337dd790a3ff9d0e01b3bb8
SHA1: 1230a630f0cfa7689cf89100d87aef50fbd54468
SHA256: 7b2f904ede2ef17c8b9cda1433ffab97b5f7098ee33664a8362beaa1479e1baa
Import Hash : fadc5a257419d2541a6b13dfb5e311e2
Sections 6 .text .rdata .data .pdata .rsrc .reloc
Directories 6 import resource debug tls relocation security

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 9/76 VT report date: 2024-10-15 02:54:36
Malware Type 1 trojan
Threat Type 3 autoit filerepmalware ykdwl

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://cache.ussc.org/player/2_xnfile.exe VirusTotal Report cache.ussc.org VirusTotal Report 2024-10-15 06:43:02

PE Sections 1 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0xb3328 734208 4475f0b38c6921083c1f099fe0696cd7d82eb187 507a8505198e35cc9675301d53e3b1c4
.rdata 0xb5000 0x34204 214016 aa0018160834c39aa77d89dd98e9e9b4783c33dc 9eda36be0cf076085a2f9772c1ee5803
.data 0xea000 0x9120 20480 ae2d0564eab0244a333aa2fd168a9fe54b6c4377 ec6b77d6ef8898b0d3b7d48c042d66a0
.pdata 0xf4000 0x6f48 28672 6c22013d212c2d3b8d455f73b7fca00f301d2edf 4416e27f8be9f9271c439d2fd34d1b2d
.rsrc 0xfb000 0x2990c 170496 da847d8cee8a536605cdb09f5893ba8090710bd3 e02216b045d5fc2881bea67841111c6d
.reloc 0x125000 0xa74 3072 0bfd3a8a134847a73f17668d586186181a6a960c 5ddb0e422ace102fe530e589a0cbec6f

PE Resources 7

Name Language Sublanguage Offset Size Data
RT_ICON LANG_ENGLISH SUBLANG_ENGLISH_UK 0x112858 61489
RT_MENU LANG_ENGLISH SUBLANG_ENGLISH_UK 0x12188c 80
RT_STRING LANG_ENGLISH SUBLANG_ENGLISH_UK 0x123a4c 344
RT_RCDATA LANG_NEUTRAL SUBLANG_NEUTRAL 0x123ba4 2080
RT_GROUP_ICON LANG_ENGLISH SUBLANG_ENGLISH_UK 0x12442c 20
RT_VERSION LANG_ENGLISH SUBLANG_ENGLISH_UK 0x124440 220
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_UK 0x12451c 1007

Meta infos 1

Translation: 0x0809 0x04b0

Packers detected 1

Microsoft Visual C++ 8.0 (DLL)

Anti debug functions 12

FindWindowExW
FindWindowW
GetLastError
GetWindowThreadProcessId
IsDebuggerPresent
IsProcessorFeaturePresent
OutputDebugStringW
Process32FirstW
Process32NextW
RaiseException
TerminateProcess
UnhandledExceptionFilter

File signature

MD5 SHA1 Block size Virtual Address
1e658d6cce296161bfd065d485d60bce a70f0e6ac2da971ae7cc2b5ae6f363ef00bef5b2 11704 1171968

Strings analysis - File found

Library
KERNEL32.dll
api-ms-win-core-synch-l1-2-0.dll
mscoree.dll
ADVAPI32.dll
OLEAUT32.dll
VERSION.dll
UxTheme.dll
WSOCK32.dll
SHELL32.dll
PSAPI.DLL
COMCTL32.dll
ole32.dll
IPHLPAPI.DLL
WININET.dll
USER32.dll
USERENV.dll
WINMM.dll
GDI32.dll
COMDLG32.dll
MPR.dll

Strings analysis - Possible IPs found 1

255.255.255.255

Strings analysis - Possible URLs found 20

http://www.sftcomp.ru
http://ocsp.digicert.com0C
http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0A
https://www.globalsign.com/repository/0
http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
http://ocsp.globalsign.com/gsgccr45codesignca20200V
http://crl.globalsign.com/gsgccr45codesignca2020.crl0
http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
http://crl.globalsign.com/codesigningrootr45.crl0V
http://ocsp.globalsign.com/rootr30;
http://secure.globalsign.com/cacert/gsgccr45codesignca2020.crt0=
http://secure.globalsign.com/cacert/root-r3.crt06
http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
http://crl.globalsign.com/root-r3.crl0G
http://secure.globalsign.com/cacert/codesigningrootr45.crt0A
http://ocsp.globalsign.com/codesigningrootr450F
http://ocsp.digicert.com0X

Import functions

Name Latest seen MD5
DownVerySync.exe 2024-09-28 18:59:25 a54ca6fc8ecfab0cc46f506d29acfd19
66f95555bb57c_zKODjTqg.exe 2024-10-08 00:29:02 e9e4631f6d4869dd176e01d368e12ce1
66fffb908255c_nnxin.exe 2024-10-04 18:24:02 0c11d30a02ea3b4bde5fa33c18845928
6702875225645_mSetup.exe 2024-10-07 09:34:02 a4aed3956f4142020f7c42873e6af07d
67040a97a73fb_workApp.exe 2024-10-10 04:38:03 1d2cf62e7874bb460b7258279a55ddf3
akt.exe 2024-10-15 17:57:04 d386565f65fd215007e08b79fad52eca