Secret_Weapon.exe?ex=670cbb6c&is=670b69ec&hm=feb7c9be36804118844e1aec332c8da303c7075117314079c8ce1120a330c837&

First submission 2024-10-13 17:31:02

File details

File type: PE32 executable (console) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 822.0 KB (841728 bytes)
Compile time: 2019-07-30 10:52:45
MD5: 497ea5f145901f80028099cb40f92def
SHA1: 1a633b4e74cba143d99b6f67c16a5aef94230ae9
SHA256: ad541c4b251600a52fb80d6167e2071328b4c83030914ee19646528b0570c0dd
Import Hash : 2c5f2513605e48f2d8ea5440a870cb9e
Sections 5 .code .text .rdata .data .rsrc
Directories 2 import resource

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 24/79 VT report date: 2024-10-13 10:43:19
Malware Type 2 hacktool trojan

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXps://cdn.discordapp.com/attachments/1267403265054867548/1294911082300964914/Secret_Weapon.exe?ex=670cbb6c&is=670b69ec&hm=feb7c9be36804118844e1aec332c8da303c7075117314079c8ce1120a330c837& VirusTotal Report cdn.discordapp.com VirusTotal Report 2024-10-13 17:31:02

PE Sections 2 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.code 0x1000 0x387e 14848 79689d07d23e494c8a40e425f6b58b6fcfcee935 46da2c5018752470fd3127bf22d63b95
.text 0x5000 0xd962 55808 838d55d26dd9efd6b0506c9c55f064f69bff3a1d e1a026e66953c410d7f60b1f1e3c560f
.rdata 0x13000 0x33a5 13312 597bcd6908d7d29b813201e8506c5ae636de4377 a16842a34a5da6feda9533bb3e83c3c1
.data 0x17000 0x178c 4608 3ab2aeb8c66070ee9f0dd2dc962b6dcf67589ac1 25a80cf67fef24741bb9b25b38a39553
.rsrc 0x19000 0xb7998 752128 f8ade0659f0eb20f71d1b8fd97be1faaa4558218 50d35ab56d16e84ba3d18c2f05fc668c

PE Resources 4

Name Language Sublanguage Offset Size Data
RT_ICON LANG_NEUTRAL SUBLANG_NEUTRAL 0x192ac 91763
RT_RCDATA LANG_NEUTRAL SUBLANG_NEUTRAL 0xd0714 12
RT_GROUP_ICON LANG_NEUTRAL SUBLANG_NEUTRAL 0xd0720 20
RT_MANIFEST LANG_NEUTRAL SUBLANG_NEUTRAL 0xd0734 611

Anti debug functions 3

GetLastError
GetWindowThreadProcessId
TerminateProcess

Strings analysis - File found

Library
ntdll.dll
SHELL32.dll
KERNEL32.dll
GDI32.dll
MSVCRT.dll
ole32.dll
COMCTL32.dll
USER32.dll
SHLWAPI.dll
WINMM.dll

Import functions

Name Latest seen MD5
antiLeak.exe 2023-02-26 14:57:02 7720f939b3f8755f2a5a34146fb5df41
av_downloader.exe 2024-09-25 19:47:03 8af4f985862c71682e796dcc912f27dc
0_flash_hisi_all_V5.1.exe 2024-09-02 20:40:31 2a79706dfb0b5bb59b394807ac7de234
onelove.exe 2024-10-02 14:00:02 d63f09ea72d529b15a58fad413e2ac0e
exit.exe 2024-10-02 14:01:02 22ba0f15051ed784999a0a4c5dad86e5
test.exe 2024-10-02 14:02:03 8a0eeb03409b2a89572ee13bbf55b65e
Superweaponcrack_nohwid.exe?ex=670cd02a&is=670b7eaa&hm=15f5d03c9a43023f5b2365254c1b509b8dc8436dc4dc1c77049a66b84121a907& 2024-10-13 17:08:01 44adf74740545a933323657c46f1728f