lock2.exe

First submission 2024-10-14 08:39:12

File details

File type: PE32+ executable (GUI) x86-64, for MS Windows
Mime type: application/x-dosexec
File size: 22978.23 KB (23529710 bytes)
Compile time: 2024-10-10 16:33:54
MD5: 3812c2d4d4dfa94c499267326af9f1eb
SHA1: a1b5eec7f6cbd772620b36f2b845e24615694f67
SHA256: b9ec93accf74bf9ec303100202e486ce05ecc7d99d42c724c0744cd783a053ad
Import Hash : a9827d13e19b1fcf3bfb108f25cfeebe
Sections 21 .text .data .rdata /4 .pdata .xdata .bss .idata .CRT .tls .rsrc .reloc /14 /29 /41 /55 /67 /80 /91 /107 /123
Directories 4 import resource tls relocation

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 12/77 VT report date: 2024-10-14 08:10:48
Malware Type 1 trojan

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://107.175.73.38/lock2.exe VirusTotal Report 107.175.73.38 VirusTotal Report 2024-10-14 08:39:12

PE Sections 3 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x1b08 7168 a045cd43a549ffc33a6809d9dd01331b2a094b81 f193de6dfbb7e436762c356acc538ea3
.data 0x3000 0xa0 512 d445b3a3e5f35e88c1dd514efd345019225bc3be a9d75fb7707ab4d24ef580eab4df85e5
.rdata 0x4000 0x8e0 2560 5ee618cc7f32bb6b0d79308b3d3589283971ac34 149a112fc700dc2f67e43d7eff060937
/4 0x5000 0x4 512 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 bf619eac0cdf3f68d496ea9344137e8b
.pdata 0x6000 0x258 1024 8da273c26a77aee3e7f5a4c2054e89d7cd1a03f4 1ff5237deca968184abfb5082e44fa03
.xdata 0x7000 0x1d4 512 95ad4f4f2b3fe077e13c87fbddcc24316ad03d6f afc5037970656d1d7c7754164a22afc0
.bss 0x8000 0x1e0 0 da39a3ee5e6b4b0d3255bfef95601890afd80709 d41d8cd98f00b204e9800998ecf8427e
.idata 0x9000 0x84c 2560 ea9cff792e3edd6371cc268cf64aecdc32a7f994 b7cfe1ecc3a6bc07041505aafd04babe
.CRT 0xa000 0x60 512 1fdd43e136204d9eb0c0d028388407bb9dda323a a9ba6ac0ca682bcdda683aff23598360
.tls 0xb000 0x10 512 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 bf619eac0cdf3f68d496ea9344137e8b
.rsrc 0xc000 0x16501a8 23396864 2154a29f9200756b4594502d6e35d00d2bbc9420 ef513ff0fee5d1629d5cfb900ba91410
.reloc 0x165d000 0x78 512 d4ab291a672d1699272174c6ad564168bc52b4cb d4a21ef67e54fb12734d41a8d501a4c5
/14 0x165e000 0x460 1536 4dda297cc84f7198a11f4c704732a601e6529f17 7c00e61686fcbc4a42b8f80df6b17f60
/29 0x165f000 0xaae9 44032 ab6fea3a3df8689dcbf1e02df8d16a6a46548dfb f2c3d65ad7a061be1acdd7f01929f96a
/41 0x166a000 0x1cb8 7680 0bf7cf6312c5764c8b5b6ac52a0668ec760697ff 089bd22e9162cbfa4761dd2e0e909a38
/55 0x166c000 0x1b32 7168 bf6ab78d32fc24aa3c712e5ba088b9de31865fb5 c0adc8ea98f4ad8acc2ca412a8bced52
/67 0x166e000 0xad0 3072 50c3303cf36e4df9530f0de2913112b275ce28a9 05a368d59313437315b6755179a424e7
/80 0x166f000 0x354 1024 a40def3e59e56c244b7f1ee9e4d2758cc286e7db a5657ca8b7b4d6587b37b69dca0759a0
/91 0x1670000 0x205b 8704 6a74e6e58cbb49e6a89961f7071d5710271c5c31 9bbe9dd66e6ef5ad08d3fe0304d7e852
/107 0x1673000 0x120d 5120 6adbfb9c98fc58017e73c6ae09ebbbfef3e18b02 b766092a75cab20f3c0bd4b595f53148
/123 0x1675000 0x195 512 a2a125cb7390661b9af98659661b28127255ba37 0a478305b637270896b63c2f3a8d9a48

PE Resources 2

Name Language Sublanguage Offset Size Data
WAVE LANG_ENGLISH SUBLANG_ENGLISH_US 0xc0d8 15102030
RT_BITMAP LANG_ENGLISH SUBLANG_ENGLISH_US 0xe73128 8294524

Packers detected 1

Microsoft Visual C++ 8.0 (DLL)

Anti debug functions 1

GetLastError

Strings analysis - File found

Library
USER32.dll
KERNEL32.dll
libgcc_s_dw2-1.dll
MSVCRT.dll
WINMM.dll
GDI32.dll

Import functions

Name Latest seen MD5
real.exe 2024-10-14 08:06:09 7f598dc2ae60de57f8002472e608b5f9