xbyxsv3.94.exe

First submission 2024-10-15 18:34:32

File details

File type: PE32+ executable (GUI) x86-64, for MS Windows
Mime type: application/x-dosexec
File size: 3628.48 KB (3715566 bytes)
Compile time: 2024-02-26 10:01:47
MD5: 2fe7543228c4b5807227ae21f3fdce4d
SHA1: 73f969ac6e3a98fc984c7df20d10da623e8dbe54
SHA256: bc6eceab2cbc5a832b6800b0773b0b684ca113bf581a69bd1c1760ca3a4ee167
Import Hash : b1c5b1beabd90d9fdabd1df0779ea832
Sections 8 .text .rdata .data .pdata .didat _RDATA .rsrc .reloc
Directories 6 import export resource debug tls relocation

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://www.beiletoys.com/xbyxsv3.94.exe VirusTotal Report www.beiletoys.com VirusTotal Report 2024-10-15 18:34:32

PE Sections 0 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x466ee 288768 52f547fc3f0d2aa9a5a2d94433f3448b56e1c0bd 27edb25a1bc32573014bf3adb5cecc24
.rdata 0x48000 0x128c4 76288 fefc45f02c6ff06e09932f38813f1eab18bd51b8 cde5f7a0fae18bcdb38da9f29d7f3313
.data 0x5b000 0xe75c 6656 a3eef31648e0ecfb2e97e7d8ad1fcb5d8b34fa2a 0a420650d3abfc14c296cd4945b33a1d
.pdata 0x6a000 0x306c 12800 c1e46ef3aae699aed50d6199dfbd9785b902c916 95c27b680fbce994429e951f39e7a9ad
.didat 0x6e000 0x360 1024 abc0703e582be8fd7ba539f6cd6e5c2cbcd313ba 53c09865fd6da5cc74254921d9575e3d
_RDATA 0x6f000 0x15c 512 6daf1314805ef690b307d9c21114a47e20ee68ad 58d3584c9c50f7594166c2ade479252f
.rsrc 0x70000 0xe000 54784 bb8be5daa09738f66f22f5074832cfc99766cc0b 2cc1cef49fec5d9984adf2f94700ff20
.reloc 0x7e000 0x970 2560 b8c49df878d332ebd45f8be315a23f5d1c7402bf 77a9ddfc47a5650d6eebbcc823e39532

PE Resources 6

Name Language Sublanguage Offset Size Data
PNG LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x711bc 5545
RT_ICON LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x77ed8 15729
RT_DIALOG LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x7c354 486
RT_STRING LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x7cca0 206
RT_GROUP_ICON LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x7cd70 104
RT_MANIFEST LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x7cdd8 1875

Packers detected 1

Microsoft Visual C++ 8.0 (DLL)

Anti debug functions 6

GetLastError
IsDebuggerPresent
IsProcessorFeaturePresent
RaiseException
TerminateProcess
UnhandledExceptionFilter

Strings analysis - File found

Temporary
winrarsfxmappingfile.tmp
XML
f.xml
Database
Y:.dB
Library
Crypt32.dll
peerdist.dll
msasn1.dll
profapi.dll
api-ms-win-core-synch-l1-2-0.dll
RpcRtRemote.dll
sfc_os.dll
XmlLite.dll
USERENV.dll
ntmarta.dll
rasadhlp.dll
mscoree.dll
mlang.dll
cryptsp.dll
linkinfo.dll
UxTheme.dll
imageres.dll
VERSION.dll
cscapi.dll
usp10.dll
wkscli.dll
devrtl.dll
secur32.dll
wintrust.dll
atl.dll
WINNSI.DLL
rsaenh.dll
riched20.dll
cryptui.dll
ntshrui.dll
slc.dll
oleaccrc.dll
PSAPI.DLL
propsys.dll
KERNEL32.dll
NETAPI32.dll
aclui.dll
dhcpcsvc6.dll
cryptbase.dll
ws2help.dll
SHELL32.dll
samlib.dll
shdocvw.dll
dwmapi.dll
cabinet.dll
MPR.dll
WS2_32.dll
WindowsCodecs.dll
dnsapi.dll
SSPICLI.DLL
samcli.dll
apphelp.dll
dfscli.dll
dsrole.dll
ieframe.dll
lpk.dll
comres.dll
netutils.dll
clbcatq.dll
dhcpcsvc.dll
IPHLPAPI.DLL
srvcli.dll
DXGIDebug.dll
browcli.dll
SETUPAPI.dll
ADVAPI32.dll
USER32.dll
COMCTL32.dll
Fole32.dll
SHLWAPI.dll
GDI32.dll
gdiplus.dll
COMDLG32.dll
OLEAUT32.dll
node.dll

Strings analysis - Possible URLs found 1

http://schemas.microsoft.com/SMI/2005/WindowsSettings

Import functions

Name Latest seen MD5
a.exe 2024-05-26 01:26:02 5c95d5493dda877b228a6485a6d40d9c
csrss.exe 2024-05-30 10:24:06 1eaae465bda927c1893a5744301cde9b
lrthijawd.exe 2024-06-14 16:06:02 1b1ecd323162c054864b63ada693cd71
kfiwarhg.exe 2024-06-14 16:30:14 7d44a8a6757c2b7287c4a7b761f4e326
4x.exe 2024-06-07 14:16:02 c8432b773d48e5e0a9f2d1ecb7c557f8
motruhjgmawes.exe 2024-06-14 16:49:08 57a6a83482ce2897e8cdec17accbd662
potkmdaw.exe 2024-07-12 12:39:02 cefc3739d099bae51eb2a9d3887ac12c
live3.exe 2024-07-20 05:58:04 9fe68af3f2db3c8428035cabfccafd04
live.exe 2024-07-20 07:37:04 deb7f0871db1a1ad70b0ec844efc51d1
gawdth.exe 2024-09-02 00:31:29 c02798b26bdaf8e27c1c48ef5de4b2c3
jsawdtyjde.exe 2024-08-25 14:04:02 4c3049f8e220c2264692cb192b741a30
66b2871b47a8b_uhigdbf.exe 2024-10-09 18:58:05 eeecdefa939b534bc8f774a15e05ab0f
66e30a27e0efe_tmpD.exe 2024-09-28 05:39:01 af91873c641aab500eba3a3ad6f17b74
66e1a49ce28da_wtyhjkosefktyh.exe 2024-09-28 04:07:03 68821531a37ba7822fd5d67019733b6b
Meeting-https.exe 2024-10-07 21:45:02 4b61a3d79a892267bf6e76a54e188cc0
setup2.exe 2024-10-13 13:56:08 2ffafb44b3efdc58f229ffbce7b12796
rbx.exe?ex=670cc4cc&is=670b734c&hm=3c647bebfcf01e0dd93e67e212054aa02bc3b2b54a7738168d98490d5192ee3c& 2024-10-13 17:14:02 abfe9c702641bda679c3947a9bbde15f
Windows.Defender.Update.exe 2024-10-17 17:40:02 bde1d37ad1cf05320955681bf6455efa