setup2.exe

First submission 2024-10-13 13:56:08

File details

File type: PE32+ executable (GUI) x86-64, for MS Windows
Mime type: application/x-dosexec
File size: 64217.98 KB (65759210 bytes)
Compile time: 2024-05-12 12:17:07
MD5: 2ffafb44b3efdc58f229ffbce7b12796
SHA1: 3ce9d89c6af5059f455de63a7cf13e6bad4733a0
SHA256: e8c90ed9b9acf1f82a0823c676420ac365d06b8399a91cb23a5ef535a49c2f7f
Import Hash : b1c5b1beabd90d9fdabd1df0779ea832
Sections 8 .text .rdata .data .pdata .didat _RDATA .rsrc .reloc
Directories 6 import export resource debug tls relocation

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://103.130.147.211/Files/setup2.exe VirusTotal Report 103.130.147.211 VirusTotal Report 2024-10-13 13:56:08

PE Sections 1 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x4676e 288768 278d421b8fcce5071cdb55190b5a29b42bdf8201 f06bb06e02377ae8b223122e53be35c2
.rdata 0x48000 0x128c4 76288 3114d29305d4b88fffea6ad50b3704072be27858 2de06d4a6920a6911e64ff20000ea72f
.data 0x5b000 0xe75c 6656 a1ae38ef93496365ab03cd8e1b3098ca6ac430e0 0dbdb901a7d477980097e42e511a94fb
.pdata 0x6a000 0x306c 12800 e0cde833721b87c288e4dbf07c14d46d8670d708 b0ce0f057741ad2a4ef4717079fa34e9
.didat 0x6e000 0x360 1024 190f8d2fea268d844623189351a02d25e6bedfff 1fcc7b1d7a02443319f8fcc2be4ca936
_RDATA 0x6f000 0x15c 512 8d13993151b09d8343303215408e337388130e61 3f331ec50f09ba861beaf955b33712d5
.rsrc 0x70000 0x6ed4 28672 03c1dc6648717671df2d379cfcc647ba6b5eda1f 616ca1adc79dcf28d7f8aa0128704b18
.reloc 0x77000 0x970 2560 b8c49df878d332ebd45f8be315a23f5d1c7402bf 77a9ddfc47a5650d6eebbcc823e39532

PE Resources 6

Name Language Sublanguage Offset Size Data
PNG LANG_RUSSIAN SUBLANG_NEUTRAL 0x7109c 5545
RT_ICON LANG_NEUTRAL SUBLANG_DEFAULT 0x72648 8558
RT_DIALOG LANG_RUSSIAN SUBLANG_NEUTRAL 0x75104 586
RT_STRING LANG_RUSSIAN SUBLANG_NEUTRAL 0x76504 616
RT_GROUP_ICON LANG_NEUTRAL SUBLANG_DEFAULT 0x7676c 20
RT_MANIFEST LANG_RUSSIAN SUBLANG_NEUTRAL 0x76780 1875

Packers detected 1

Microsoft Visual C++ 8.0 (DLL)

Anti debug functions 6

GetLastError
IsDebuggerPresent
IsProcessorFeaturePresent
RaiseException
TerminateProcess
UnhandledExceptionFilter

Anti debug functions 1

VMCheck.dll

Strings analysis - File found

Executable
kC.SO
k4g0.SO
gr].sO
Vk.SO
)*.So
&&.sO
Temporary
winrarsfxmappingfile.tmp
Database
i~.db
L46_2R.Db
Library
Crypt32.dll
peerdist.dll
msasn1.dll
profapi.dll
api-ms-win-core-synch-l1-2-0.dll
RpcRtRemote.dll
sfc_os.dll
XmlLite.dll
USERENV.dll
ntmarta.dll
rasadhlp.dll
mscoree.dll
mlang.dll
cryptsp.dll
linkinfo.dll
UxTheme.dll
imageres.dll
VERSION.dll
cscapi.dll
usp10.dll
wkscli.dll
devrtl.dll
secur32.dll
wintrust.dll
atl.dll
WINNSI.DLL
rsaenh.dll
riched20.dll
cryptui.dll
ntshrui.dll
slc.dll
oleaccrc.dll
PSAPI.DLL
propsys.dll
KERNEL32.dll
NETAPI32.dll
aclui.dll
dhcpcsvc6.dll
cryptbase.dll
ws2help.dll
SHELL32.dll
samlib.dll
shdocvw.dll
dwmapi.dll
cabinet.dll
MPR.dll
WS2_32.dll
WindowsCodecs.dll
dnsapi.dll
SSPICLI.DLL
samcli.dll
apphelp.dll
dfscli.dll
dsrole.dll
ieframe.dll
lpk.dll
comres.dll
netutils.dll
clbcatq.dll
dhcpcsvc.dll
IPHLPAPI.DLL
srvcli.dll
DXGIDebug.dll
browcli.dll
SETUPAPI.dll
SHLWAPI.dll
COMDLG32.dll
ADVAPI32.dll
COMCTL32.dll
USER32.dll
Fole32.dll
gdiplus.dll
OLEAUT32.dll
GDI32.dll

Strings analysis - Possible URLs found 1

http://schemas.microsoft.com/SMI/2005/WindowsSettings

Import functions

Name Latest seen MD5
a.exe 2024-05-26 01:26:02 5c95d5493dda877b228a6485a6d40d9c
csrss.exe 2024-05-30 10:24:06 1eaae465bda927c1893a5744301cde9b
lrthijawd.exe 2024-06-14 16:06:02 1b1ecd323162c054864b63ada693cd71
kfiwarhg.exe 2024-06-14 16:30:14 7d44a8a6757c2b7287c4a7b761f4e326
4x.exe 2024-06-07 14:16:02 c8432b773d48e5e0a9f2d1ecb7c557f8
motruhjgmawes.exe 2024-06-14 16:49:08 57a6a83482ce2897e8cdec17accbd662
potkmdaw.exe 2024-07-12 12:39:02 cefc3739d099bae51eb2a9d3887ac12c
live3.exe 2024-07-20 05:58:04 9fe68af3f2db3c8428035cabfccafd04
live.exe 2024-07-20 07:37:04 deb7f0871db1a1ad70b0ec844efc51d1
gawdth.exe 2024-09-02 00:31:29 c02798b26bdaf8e27c1c48ef5de4b2c3
jsawdtyjde.exe 2024-08-25 14:04:02 4c3049f8e220c2264692cb192b741a30
66b2871b47a8b_uhigdbf.exe 2024-10-09 18:58:05 eeecdefa939b534bc8f774a15e05ab0f
66e30a27e0efe_tmpD.exe 2024-09-28 05:39:01 af91873c641aab500eba3a3ad6f17b74
66e1a49ce28da_wtyhjkosefktyh.exe 2024-09-28 04:07:03 68821531a37ba7822fd5d67019733b6b
Meeting-https.exe 2024-10-07 21:45:02 4b61a3d79a892267bf6e76a54e188cc0
rbx.exe?ex=670cc4cc&is=670b734c&hm=3c647bebfcf01e0dd93e67e212054aa02bc3b2b54a7738168d98490d5192ee3c& 2024-10-13 17:14:02 abfe9c702641bda679c3947a9bbde15f
xbyxsv3.94.exe 2024-10-15 18:34:32 2fe7543228c4b5807227ae21f3fdce4d
Windows.Defender.Update.exe 2024-10-17 17:40:02 bde1d37ad1cf05320955681bf6455efa