4.exe
First submission 2024-10-12 12:53:04
File details
File type: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
Mime type: | application/x-dosexec |
File size: | 7157.0 KB (7328768 bytes) |
Compile time: | 2024-10-11 19:25:45 |
MD5: | 49d7ba824b7249c26927e8a086eb879b |
SHA1: | 51596a606413b95477c9f655c2dfad328a94baf0 |
SHA256: | a10386e4d53db8a045aedf7261adfbe05c0afd80a2550b7ad856cec3663cc66d |
Import Hash : | 41db2083dac89343aef584a51a80b293 |
Sections 9 | .text .data .rdata .eh_fram .bss .idata .CRT .tls .reloc |
Directories 3 | import tls relocation |
URLs, FQDN and IP indicators 1
PE Sections 3 suspicious
Name | VAddress | VSize | Size | SHA1 | MD5 | Suspicious |
---|---|---|---|---|---|---|
.text | 0x1000 | 0x499c68 | 4824576 | 99f1247905efcd6bbcd9952fb9e81b2bccb0769e | 131aeb790fa1b4069f4d079a79edd45d | |
.data | 0x49b000 | 0x1e7100 | 1995264 | 3468a2cfac0b06e852a679d82f5cb5e64c23e7f1 | 22aba8ab8718b3b9e4bbdc722bc9e203 | |
.rdata | 0x683000 | 0xe324 | 58368 | 50f7c973684e53015cb06471e9abe8ce6ad0d293 | 42911933f7edfadeaed86f31b5cf337f | |
.eh_fram | 0x692000 | 0x210c | 8704 | 089c3e7ef8a2f1536952c1d084eafec25ee88c7f | 03b25ad11df83c6377a854105026d1c7 | |
.bss | 0x695000 | 0xb74 | 0 | da39a3ee5e6b4b0d3255bfef95601890afd80709 | d41d8cd98f00b204e9800998ecf8427e | |
.idata | 0x696000 | 0xb78 | 3072 | a367ed782ea4d1330709a126cea75dd784460811 | aa8b0559c664205cc5a5e0b0104ebb08 | |
.CRT | 0x697000 | 0x30 | 512 | e49e627b7c6243bf7494f5adc26113ffaa38338d | 947565758601e59a9e2e145caaaaefe2 | |
.tls | 0x698000 | 0x8 | 512 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 | bf619eac0cdf3f68d496ea9344137e8b | |
.reloc | 0x699000 | 0x6a8f8 | 436736 | 5dea728600e4c4b21b05f3165a1db233292f83ad | 2b166d1a394213febf3ce2718928b3c1 |
Anti debug functions 1
GetLastError |
Strings analysis - File found
Library |
MSVCRT.dll |
ADVAPI32.dll |
KERNEL32.dll |
libgcc_s_dw2-1.dll |
Import functions
Name | Latest seen | MD5 |
---|---|---|
javumarfirst.exe | 2024-10-03 21:30:03 | 506f20dc6d2d9a4bd2725a726679b74e |
3.exe | 2024-10-07 02:00:06 | 4574de6b9f970058f5306aa830f3a132 |
11.exe | 2024-10-07 02:55:06 | 284c99e2aa6644acd914e7d1a245deed |
sadsay.exe | 2024-10-10 06:26:03 | 735bb5f55a17215700840c04a8b40a03 |
JavUmar.exe | 2024-10-10 21:07:03 | 3394808f2d5c141b86e33a51ace8a577 |
33.exe | 2024-10-12 23:11:10 | e071b6dd90f4c7a9d23632bfb9517925 |
JavUmar1.exe | 2024-10-14 09:37:02 | 7105a2ba8c897b6c2072a6ab0bdecdf1 |