datdll.rar
First submission 2024-10-15 19:35:03
File details
File type: | PE32 executable (GUI) Intel 80386, for MS Windows |
Mime type: | application/x-dosexec |
File size: | 40.0 KB (40960 bytes) |
Compile time: | 2022-03-05 16:11:54 |
MD5: | 21082f24acc2835ca29295729bff4d1c |
SHA1: | 7c3b45fce8effe3029f2a76adc14ad0389dea8b6 |
SHA256: | 6aae60a32e444fdd0eaad750865fde8b604cb995776b07dddb3865d1e3ac3a2d |
Import Hash : | 399c4e86af8c1db069a69fbe120be19f |
Sections 3 | .text .data .rsrc |
Directories 2 | import resource |
File features detected
URLs, FQDN and IP indicators 1
PE Sections 0 suspicious
Name | VAddress | VSize | Size | SHA1 | MD5 | Suspicious |
---|---|---|---|---|---|---|
.text | 0x1000 | 0x67a0 | 28672 | 39dabd25ef9ab5c74c9362e647a58f23c161a72d | d355f3c381b013e2fc382314495b5489 | |
.data | 0x8000 | 0xaa0 | 4096 | 1ceaf73df40e531df3bfb26b4fb7cd95fb7bff1d | 620f0b67a91f7f74151bc5be745b7110 | |
.rsrc | 0x9000 | 0xb8c | 4096 | 713d2a063224fa753ae7a1ddd21a3a4759c0625c | 171cba7c22f29757d8aeb1de7b483283 |
PE Resources 3
Name | Language | Sublanguage | Offset | Size | Data |
---|---|---|---|---|---|
RT_ICON | LANG_NEUTRAL | SUBLANG_NEUTRAL | 0x92e4 | 2216 | |
RT_GROUP_ICON | LANG_NEUTRAL | SUBLANG_NEUTRAL | 0x92d0 | 20 | |
RT_VERSION | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 0x90f0 | 480 |
Meta infos 6
InternalName: | dat |
ProductVersion: | 2022.03.0005 |
Translation: | 0x0804 0x04b0 |
ProductName: | dat |
OriginalFilename: | dat.exe |
FileVersion: | 2022.03.0005 |
Packers detected 2
Microsoft Visual Basic v5.0 - v6.0 |
Microsoft Visual Basic v5.0 |
Strings analysis - File found
Autogen |
C:\Program Files (x86)\VB6Mini\bin\VB6.OLB |
Data |
taskkill /f /im NewTcp.Dat |
Text |
C\MirOfGame.txt |
Library |
taskkill /f /im MirYk360.dll |
VBA6.DLL |
VB5!6&vb6chs.dll |
MSVBVM60.DLL |
PSAPI.DLL |