QCast_Win.exe

First submission 2024-10-15 19:46:31

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
Mime type: application/x-dosexec
File size: 1965.02 KB (2012182 bytes)
Compile time: 1992-06-20 00:22:17
MD5: 3e303276d3194f4d2bd955adb347482d
SHA1: af2917a90abf4356266ac56d5c1859c16c2d1621
SHA256: 0f1c6514ccaa8d7f5a4f72f25c24deb4ce4e65a00810bbb0694d95c3762d3447
Import Hash : 47913b68f1b7d2f7585792df7a7249bc
Sections 3 UPX0 UPX1 .rsrc
Directories 4 import resource tls security

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://data.yhydl.com:20006/file/QCast_Win.exe VirusTotal Report data.yhydl.com VirusTotal Report 2024-10-15 19:46:32

PE Sections 2 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
UPX0 0x1000 0x43000 0 da39a3ee5e6b4b0d3255bfef95601890afd80709 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x44000 0x22000 136192 bd6660092e482923d13ce85dcfb48d358c1b4bce f2b7a08051764105095cfb8e95e0a535
.rsrc 0x66000 0x2000 8192 29d6763ad359bc004523692101f6844847c7db75 1cb0b8cfda782ef0485cb4a5d045d899

PE Resources 7

Name Language Sublanguage Offset Size Data
RT_ICON LANG_NEUTRAL SUBLANG_NEUTRAL 0x66ec4 2216
RT_DIALOG LANG_NEUTRAL SUBLANG_NEUTRAL 0x56820 440
RT_STRING LANG_NEUTRAL SUBLANG_NEUTRAL 0x57da0 708
RT_RCDATA LANG_NEUTRAL SUBLANG_NEUTRAL 0x598c8 35328
RT_GROUP_ICON LANG_NEUTRAL SUBLANG_NEUTRAL 0x67770 62
RT_VERSION LANG_NEUTRAL SUBLANG_NEUTRAL 0x677b4 568
RT_MANIFEST LANG_NEUTRAL SUBLANG_NEUTRAL 0x679f0 899

Meta infos 7

LegalCopyright: Copyright (C) 2015 BenQ
FileVersion: 1.3.0.168
FileDescription: BenQ QCast
Company: BenQ
ProductName: BenQ QCast
Translation: 0x0000 0x0000
ProductVersion: 1.3.0.168

Packers detected 2

MSLRH V0.31 -> emadicius
UPX -> www.upx.sourceforge.net

File signature

MD5 SHA1 Block size Virtual Address
d41d8cd98f00b204e9800998ecf8427e da39a3ee5e6b4b0d3255bfef95601890afd80709 6488 40237112

Strings analysis - File found

Library
OLEAUT32.dll
KERNEL32.dll
USER32.dll
COMCTL32.dll
ADVAPI32.dll
GDI32.dll
VERSION.dll
i32.dll
ole32.dll
SHELL32.dll

Strings analysis - Possible IPs found 1

1.3.0.168

Import functions