keygen.exe

First submission 2024-10-15 19:40:03

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
Mime type: application/x-dosexec
File size: 54.0 KB (55296 bytes)
Compile time: 2005-09-13 11:01:06
MD5: 3bd08acd4079d75290eb1fb0c34ff700
SHA1: 84d4d570c228271f14e42bbb96702330cc8c8c2d
SHA256: 4d3d060d8ec7089acfb4ba233d6f2a00a910503be648709a97714c84a80cccd8
Import Hash : 5ef21414f390ccd1ad383d2c569cd765
Sections 3 UPX0 UPX1 .rsrc
Directories 2 import resource

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 33/77 VT report date: 2024-09-01 22:34:22
Malware Type 3 trojan pua hacktool
Threat Type 2 keygen hack

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://desquer.ens.uabc.mx/dam/software/keygen.exe VirusTotal Report desquer.ens.uabc.mx VirusTotal Report 2024-10-15 19:40:03

PE Sections 2 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
UPX0 0x1000 0x1c000 0 da39a3ee5e6b4b0d3255bfef95601890afd80709 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x1d000 0xb000 44544 e6533e6562189782b259e6ba6c1c4180d105637e ff872cb8347b0eddd65d55dec989cd5d
.rsrc 0x28000 0x3000 9728 047299a9b863567a683bbb90f0adaf611640fe21 e872a7b25088f7d23bbf5b882b7bfe91

PE Resources 6

Name Language Sublanguage Offset Size Data
RT_BITMAP LANG_ENGLISH SUBLANG_ENGLISH_US 0x164b0 54062
RT_ICON LANG_ENGLISH SUBLANG_ENGLISH_US 0x28224 7336
RT_DIALOG LANG_ENGLISH SUBLANG_ENGLISH_US 0x14220 650
RT_STRING LANG_ENGLISH SUBLANG_ENGLISH_US 0x257e8 42
RT_GROUP_ICON LANG_ENGLISH SUBLANG_ENGLISH_US 0x29ed0 20
RT_VERSION LANG_ENGLISH SUBLANG_ENGLISH_US 0x29ee8 840

Meta infos 13

LegalCopyright: Copyright 2005
InternalName: keygen.exe
FileVersion: 2, 0, 0, 5
FileDescription: Keymaker
SpecialBuild:
CompanyName:
LegalTrademarks:
Comments: You have been traced.
ProductName: Keymaker
ProductVersion: 2, 0, 0, 5
PrivateBuild:
Translation: 0x0409 0x04b0
OriginalFilename: keygen.exe

Packers detected 3

UPX v0.80 - v0.84
UPX 2.90 (LZMA)
UPX -> www.upx.sourceforge.net

Strings analysis - File found

Library
DVAPI32.dll
KERNEL32.dll
COMCTL32.dll
WINMM.dll
msvcp60.dll
GDI32.dll
MSVCRT.dll
USER32.dll
MSIMG32.dll
SHELL32.dll
MFC42.DLL

Import functions