System.exe

First submission 2024-10-18 04:40:04

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 794.0 KB (813056 bytes)
Compile time: 1992-06-20 00:22:17
MD5: 3d2c42e4aca7233ac1becb634ad3fa0a
SHA1: d2d3b2c02e80106b9f7c48675b0beae39cf112b7
SHA256: eeea8f11bf728299c2033bc96d9a5bd07ea4f34e5a2fbaf55dc5741b9f098065
Import Hash : 332f7ce65ead0adfb3d35147033aabe9
Sections 8 CODE DATA BSS .idata .tls .rdata .reloc .rsrc
Directories 4 import resource tls relocation

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 68/77 VT report date: 2024-10-17 18:10:41
Malware Type 3 trojan virus downloader
Threat Type 3 darkkomet comet synaptics

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://154.197.69.165/System.exe VirusTotal Report 154.197.69.165 VirusTotal Report 2024-10-18 04:40:04

PE Sections 3 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
CODE 0x1000 0x99bec 629760 55c4a89a3f388e5fbedf2bd1a233d36b4e71a565 33fbe30e8a64654287edd1bf05ae7c8c
DATA 0x9b000 0x2e54 12288 16555dc80f87a8e2c78d0d8485184637e66dfac4 1f5e19e7d20c1d128443d738ac7bc610
BSS 0x9e000 0x11e5 0 da39a3ee5e6b4b0d3255bfef95601890afd80709 d41d8cd98f00b204e9800998ecf8427e
.idata 0xa0000 0x2a42 11264 dcee39fc7cafbadf9c633832630a29b1707ece27 21ff53180b390dc06e3a1adf0e57a073
.tls 0xa3000 0x10 0 da39a3ee5e6b4b0d3255bfef95601890afd80709 d41d8cd98f00b204e9800998ecf8427e
.rdata 0xa4000 0x39 512 f47979e8a85bb490619bc05b0bfff2ad9c6cb39a a92cf494c617731a527994013429ad97
.reloc 0xa5000 0xa980 43520 80abf169f0339cdc8c7d22f62101ab59476e953c dcd1b1c3f3d28d444920211170d1e8e6
.rsrc 0xb0000 0x1bf30 114688 4f6d8a21ce7b97ba5d25c43a911aac8dd10de4bb e17b4fca1aaf4346cd1593efe86ed693

PE Resources 9

Name Language Sublanguage Offset Size Data
RT_CURSOR LANG_NEUTRAL SUBLANG_NEUTRAL 0xb1500 308
RT_BITMAP LANG_NEUTRAL SUBLANG_NEUTRAL 0xb2868 232
RT_ICON LANG_TURKISH SUBLANG_DEFAULT 0xb39f8 4264
RT_DIALOG LANG_NEUTRAL SUBLANG_NEUTRAL 0xb4aa0 82
RT_STRING LANG_NEUTRAL SUBLANG_NEUTRAL 0xb8a6c 852
RT_RCDATA LANG_TURKISH SUBLANG_DEFAULT 0xc73b8 18387
RT_GROUP_CURSOR LANG_NEUTRAL SUBLANG_NEUTRAL 0xcbc04 20
RT_GROUP_ICON LANG_TURKISH SUBLANG_DEFAULT 0xcbc18 20
RT_VERSION LANG_TURKISH SUBLANG_DEFAULT 0xcbc2c 772

Meta infos 11

LegalCopyright:
InternalName:
FileVersion: 1.0.0.4
CompanyName: Synaptics
LegalTrademarks:
Comments:
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
FileDescription: Synaptics Pointing Device Driver
Translation: 0x041f 0x04e6
OriginalFilename:

Packers detected 5

Borland Delphi 3.0 (???)
Borland Delphi 4.0
Borland Delphi v3.0
Borland Delphi v6.0 - v7.0
BobSoft Mini Delphi -> BoB / BobSoft

Anti debug functions 6

FindWindowA
GetLastError
GetWindowThreadProcessId
RaiseException
TerminateProcess
UnhandledExceptionFilter

Strings analysis - File found

Binary
xl/vbaProject.bin
Temporary
\Log.tmp
$000000.tmp
XML
xl/workbook.xml
xl/styles.xml
xl/theme/theme1.xml
xl/worksheets/sheet1.xml
Library
SbieDll.dll
ssleay32.dll
\libeay32.dll
MAPI32.dll
WININET.dll
SHELL32.dll
WS2_32.dll
http://xred.site50.net/syn/SSLLibrary.dll
AVICAP32.dll
USER32.dll
\ssleay32.dll
UxTheme.dll
KBHks.dll
Synaptics.dll
mscoree.dll
Shcore.dll
NETAPI32.dll
ole32.dll
ntdll.dll
IMM32.dll
ADVAPI32.dll
COMCTL32.dll
GDI32.dll
WSOCK32.dll
OLEAUT32.dll
KERNEL32.dll
vcltest3.dll
libeay32.dll
VERSION.dll

Strings analysis - Possible IPs found 3

0.0.0.1
1.0.0.4
127.0.0.1

Strings analysis - Possible URLs found 11

http://freedns.afraid.org/api/?action=getdyndns&sha=a30fa98efc092684e8d1c5cff797bcc613562978
https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1
https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download
https://docs.google.com/uc?id=0BxsMXGfPIZfSVlVsOGlEVGxuZVk&export=download
https://www.dropbox.com/s/n1w4p8gc6jzo0sg/SUpdate.ini?dl=1
http://xred.site50.net/syn/SUpdate.ini
http://xred.site50.net/syn/SSLLibrary.dll
https://docs.google.com/uc?id=0BxsMXGfPIZfSTmlVYkxhSDg5TzQ&export=download
http://ip-api.com/line/?fields=hosting
https://www.dropbox.com/s/fzj752whr3ontsm/SSLLibrary.dll?dl=1
http://xred.site50.net/syn/Synaptics.rar

Import functions

Name Latest seen MD5
BfRUleZGyl.exe 2023-01-06 17:20:02 cc69c7d6e3e3c93b31ef9c7937a3fb52
systrem.exe 2023-02-08 20:25:10 a4713efd7588cce07c4d82dda4efbfd3
2mfem8FxgENS.exe 2023-04-09 09:43:07 e19771cfa736a833e9cc4b72120e3112
a5d6cca28de4d6e521137acca4bc8d71.exe 2024-06-15 19:07:22 a09aea19c42bed05b1c624f8b4cd799c
ey.exe 2024-06-16 02:08:20 ceb1b42233ced601bf691ffa63a305a9
2.exe 2024-09-25 21:03:33 d65f5982c1f1f2967fdd91b7f21a5696
3333.exe 2024-09-25 19:59:13 0336bc6e2759bd7b5c400a447a55756e
163.exe 2024-09-25 20:00:52 c5d0790f653d7922b4723bdd6737f3a7
3-1.exe 2024-09-27 05:36:51 3482f7d0b7c1a3eeca3874bc9a1397ce
1.exe 2024-09-25 21:11:44 814eede0c07f64e2ce4efbeede8928f4