igccu.exe

First submission 2023-09-12 09:52:04

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 298.5 KB (305664 bytes)
Compile time: 2023-03-15 21:13:30
MD5: 131ccad3c84639a1cb61bb56fb5b9e24
SHA1: 849f9be725d5216840f88607592ef44b07e2518c
SHA256: 12bbde25bb3a140f9699c4627d5235bc921097ba0bfbbd64d5834fb760ea6ba2
Import Hash : fd6dfb11bfd672e911229df79ae69bc7
Sections 3 .text .data .rsrc
Directories 2 import resource
Virus Total: 34/71 VT report date: 2023-09-12 01:50:48

File features detected

Is DLL

Packers

Anti Debug

Anti VM

Signed

XOR

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://103.250.79.174/520/igccu.exe VirusTotal Report 103.250.79.174 VirusTotal Report 2023-09-12 09:52:04

PE Sections 1 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x200f0 131584 37ab13b5c16d007dfa9415681c80cb9ddca1a801 b0e6f235ccb4c0d1916e82f9c0545675
.data 0x22000 0x1ebbe8c 92160 cadc91c0fbb460732d5378e1fc920068187de5c5 a41d97dfdd8a6283a7e943cb21777094
.rsrc 0x1ede000 0x13a68 80896 562f4d8320cd1c3f124b5c616a478b84ed90a2de 5e5745b0007578d7ffc2023b3b995045

PE Resources 6

Name Language Sublanguage Offset Size Data
RT_CURSOR LANG_NEUTRAL SUBLANG_NEUTRAL 0x1ef0468 2216
RT_ICON LANG_SINDHI SUBLANG_SYS_DEFAULT 0x1eeff98 1128
RT_STRING LANG_SINDHI SUBLANG_SYS_DEFAULT 0x1ef1808 608
RT_GROUP_CURSOR LANG_NEUTRAL SUBLANG_NEUTRAL 0x1ef0d10 20
RT_GROUP_ICON LANG_SINDHI SUBLANG_SYS_DEFAULT 0x1ef0400 104
RT_VERSION LANG_NEUTRAL SUBLANG_NEUTRAL 0x1ef0d28 572

Meta infos 7

FileVersions: 42.51.49
InternalName: Superior.exe
ProductVersion: 27.5.34.0
LegalCopyrights: Challangers bojala
Translation: 0x124e 0x043a
FileDescriptions: Anybodies
ProductName: Bonni

Packers detected 2

Microsoft Visual C++ 8
VC8 -> Microsoft Corporation

Anti debug functions 6

GetLastError
IsDebuggerPresent
IsProcessorFeaturePresent
RaiseException
TerminateProcess
UnhandledExceptionFilter

Strings analysis - File found

Library
WUSER32.DLL
KERNEL32.dll
mscoree.dll
ADVAPI32.dll
SHELL32.dll
USER32.dll
GDI32.dll

Import functions