cryptnobaa.exe

First submission 2023-09-12 02:11:02

File details

File type: PE32+ executable (GUI) x86-64, for MS Windows
Mime type: application/x-dosexec
File size: 282.43 KB (289208 bytes)
Compile time: 2023-09-07 02:58:39
MD5: 41bdf3bbb8d27902f5f22e9b5a88a25b
SHA1: 715db0885a5929a8978bdd25269134719c26f6f0
SHA256: e2622b67c87d3e730dbd1312d1160faac1ef9bd98f00041e15c00f347d47a949
Import Hash : 8a8dbe6ecfacdaceac22d14c24917858
Sections 7 .text .rdata .data .pdata _RDATA .rsrc .reloc
Directories 5 import resource debug relocation security
Virus Total: 11/69 VT report date: 2023-09-11 23:48:11

File features detected

Is DLL

Packers

Anti Debug

Anti VM

Signed

XOR

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://77.91.68.78/lend/cryptnobaa.exe VirusTotal Report 77.91.68.78 VirusTotal Report 2023-09-12 02:11:03

PE Sections 1 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x1f680 129024 9d47248eecc0e0f54f704c5e2b8e4e6ba542a252 622a8648e9320b22c3e012a095192f88
.rdata 0x21000 0xe9a8 59904 489940501b3d61c0ea64dd0cd2ccbfeadd4d2893 c2b328ba58e95a76f3bd6e55c13f0657
.data 0x30000 0x2a84 4608 486984b0452ca7b2b3e019270ede0e5ad9d566ea b535cad2568ea5d5cde03908b2b2eb5b
.pdata 0x33000 0x1f68 8192 3ca349e9ab9069d1336e80b5f318f883734c9d5a 26ef9da4aafd9a3905f8f3bee7f1617c
_RDATA 0x35000 0x15c 512 de4f7375a447c9b87cf01daeb2c53e3e09be7281 f994cd5c236c0705fe6198dc821b4371
.rsrc 0x36000 0x12878 76288 c202893db239d4c51951927005baacf5637ba9d1 65539b076406e09b0a291e583882082f
.reloc 0x49000 0x91c 2560 1c694a8fd219bf6a9088c4af786069047e8e40c6 fcd0930df8bc2892d1115d30c4c03e1e

PE Resources 4

Name Language Sublanguage Offset Size Data
RT_ICON LANG_NEUTRAL SUBLANG_NEUTRAL 0x3613c 9640
RT_RCDATA LANG_NEUTRAL SUBLANG_NEUTRAL 0x386e4 65536
RT_GROUP_ICON LANG_NEUTRAL SUBLANG_NEUTRAL 0x486e4 20
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x486f8 381

Packers detected 1

Microsoft Visual C++ 8.0 (DLL)

Anti debug functions 6

GetLastError
IsDebuggerPresent
IsProcessorFeaturePresent
RaiseException
TerminateProcess
UnhandledExceptionFilter

File signature

MD5 SHA1 Block size Virtual Address
7d1412d36762b387287064f3bc2a3991 3ebeb4e67a72ad6d330f6e0d906c4e75418508b3 7096 282112

Strings analysis - File found

Library
mscoree.dll
OLEAUT32.dll
ole32.dll
KERNEL32.dll

Strings analysis - Possible URLs found 9

http://ocsp.digicert.com0C
http://ocsp.digicert.com0A
http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
http://ocsp.digicert.com0X

Import functions

Name Latest seen MD5
cryptusa.exe 2023-09-10 16:55:01 4fe88bc5440133565a8e28a78d3bbcbd
newlife.exe 2023-09-14 04:31:03 69c0ce8858c37ee1e29fbeb4d0acc928