Order-63729r.exe

First submission 2024-10-15 20:47:02

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 112.0 KB (114688 bytes)
Compile time: 1992-06-20 00:22:17
MD5: 27864dd446f03f806b26031d97e3377b
SHA1: 18688de552635bfbe9b3afae166b1d86d41eccc4
SHA256: 94d346e862d5850b5d19aefd5053191c47975b2d233958f5145f0390d42c1fbd
Import Hash : 6d1f2b41411eacafcf447fc002d8cb00
Sections 5 CODE DATA BSS .idata .reloc
Directories 2 import relocation

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 65/75 VT report date: 2024-10-15 07:16:58
Malware Type 1 trojan
Threat Type 3 stealer azorult coins

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://217.160.121.141:8030/5643254657/Order-63729r.exe VirusTotal Report 217.160.121.141 VirusTotal Report 2024-10-15 20:47:02

PE Sections 1 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
CODE 0x1000 0x196b0 104448 12f6291fa8c64b3f478907b767329d835786daf9 feaf2e72a4f659a585c0d0b9535269d6
DATA 0x1b000 0x66c 2048 f10488ba381658b00bf5f052264affcec2b91505 c1ef01f2c6a2c3da4b3b7d3b6128db9b
BSS 0x1c000 0x8c5 0 da39a3ee5e6b4b0d3255bfef95601890afd80709 d41d8cd98f00b204e9800998ecf8427e
.idata 0x1d000 0x79e 2048 0f3134155613a4fd8e541f21250cfab0484639ff 556c360ee726e003c5e1f6a038e97572
.reloc 0x1e000 0x135c 5120 bba372c593ca6cc1b2ff90f8f852450a93d763ad cac55c427defaffc85c1a164a6baac6b

Packers detected 5

Borland Delphi 3.0 (???)
Borland Delphi 4.0
Borland Delphi v3.0
Borland Delphi v6.0 - v7.0
BobSoft Mini Delphi -> BoB / BobSoft

Anti debug functions 2

RaiseException
UnhandledExceptionFilter

Anti debug functions 1

VMCheck.dll

Strings analysis - File found

Data
%TEMP%\curbuf.dat
XML
%APPDATA%\.purple\accounts.xml
\accounts.xml
Database
\main.db
main.db
Text
.address.txt
\*.txt
PasswordsList.txt
System.txt
ip.txt
Library
Crypt32.dll
ntdll.dll
WTSAPI32.dll
USER32.dll
WSOCK32.dll
USERENV.dll
ole32.dll
GDI32.dll
WININET.dll
ADVAPI32.dll
KERNEL32.dll
OLEAUT32.dll
gdiplus.dll
dnsapi.dll
crtdll.dll
SHELL32.dll

Strings analysis - Possible URLs found 2

https://dotbit.me/a/
http://ip-api.com/json

Import functions