Superweaponcrack_nohwid.exe?ex=670cd02a&is=670b7eaa&hm=15f5d03c9a43023f5b2365254c1b509b8dc8436dc4dc1c77049a66b84121a907&

First submission 2024-10-13 17:08:01

File details

File type: PE32 executable (console) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 254.0 KB (260096 bytes)
Compile time: 2019-07-30 10:52:45
MD5: 44adf74740545a933323657c46f1728f
SHA1: 8213eee1e71980604989dbd634a86cedd669b883
SHA256: 85a8a94eaf795031450482074abe63aecaf7fd76d87814c292bd3acd07e37991
Import Hash : 2c5f2513605e48f2d8ea5440a870cb9e
Sections 5 .code .text .rdata .data .rsrc
Directories 2 import resource

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 51/79 VT report date: 2024-10-13 12:04:01
Malware Type 2 trojan downloader
Threat Type 3 disabler cobalt discord

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXps://cdn.discordapp.com/attachments/1216581381250093138/1239125624153706516/Superweaponcrack_nohwid.exe?ex=670cd02a&is=670b7eaa&hm=15f5d03c9a43023f5b2365254c1b509b8dc8436dc4dc1c77049a66b84121a907& VirusTotal Report cdn.discordapp.com VirusTotal Report 2024-10-13 17:08:01

PE Sections 2 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.code 0x1000 0x387e 14848 79689d07d23e494c8a40e425f6b58b6fcfcee935 46da2c5018752470fd3127bf22d63b95
.text 0x5000 0xd962 55808 838d55d26dd9efd6b0506c9c55f064f69bff3a1d e1a026e66953c410d7f60b1f1e3c560f
.rdata 0x13000 0x33a5 13312 597bcd6908d7d29b813201e8506c5ae636de4377 a16842a34a5da6feda9533bb3e83c3c1
.data 0x17000 0x178c 4608 76c56c34e10355cecde7ce970622ca31193980d3 f06e05c1447d7b2d5acd240cc9c558b3
.rsrc 0x19000 0x299d8 170496 fd176a43df3c1d8cde2d220cfe4ed3cfc815f01b b34cf84f57bdd33e7cf0fab2541cdf98

PE Resources 4

Name Language Sublanguage Offset Size Data
RT_ICON LANG_NEUTRAL SUBLANG_NEUTRAL 0x192ac 147329
RT_RCDATA LANG_NEUTRAL SUBLANG_NEUTRAL 0x4274c 19
RT_GROUP_ICON LANG_NEUTRAL SUBLANG_NEUTRAL 0x42760 20
RT_MANIFEST LANG_NEUTRAL SUBLANG_NEUTRAL 0x42774 611

Anti debug functions 3

GetLastError
GetWindowThreadProcessId
TerminateProcess

Strings analysis - File found

Library
ntdll.dll
SHELL32.dll
KERNEL32.dll
ole32.dll
USER32.dll
SHLWAPI.dll
COMCTL32.dll
GDI32.dll
MSVCRT.dll
WINMM.dll

Import functions

Name Latest seen MD5
antiLeak.exe 2023-02-26 14:57:02 7720f939b3f8755f2a5a34146fb5df41
av_downloader.exe 2024-09-25 19:47:03 8af4f985862c71682e796dcc912f27dc
0_flash_hisi_all_V5.1.exe 2024-09-02 20:40:31 2a79706dfb0b5bb59b394807ac7de234
onelove.exe 2024-10-02 14:00:02 d63f09ea72d529b15a58fad413e2ac0e
exit.exe 2024-10-02 14:01:02 22ba0f15051ed784999a0a4c5dad86e5
test.exe 2024-10-02 14:02:03 8a0eeb03409b2a89572ee13bbf55b65e
Secret_Weapon.exe?ex=670cbb6c&is=670b69ec&hm=feb7c9be36804118844e1aec332c8da303c7075117314079c8ce1120a330c837& 2024-10-13 17:31:02 497ea5f145901f80028099cb40f92def