OGYS_MACRO.exe?ex=670c2148&is=670acfc8&hm=a51a7fc2b2407aa19e6e89a41e317ba6c89544aa6228d1d5c61183ba40177f17&
First submission 2024-10-13 19:25:02
File details
File type: | PE32+ executable (console) x86-64, for MS Windows |
Mime type: | application/x-dosexec |
File size: | 23.0 KB (23552 bytes) |
Compile time: | 2024-04-21 16:52:17 |
MD5: | 5656520dd201e786dbcbd4043409c921 |
SHA1: | c1ffb9889a94f6fb5d34386ebdd0e7dac3b2858c |
SHA256: | fd8d9c433aad9059017c03b07f6d59458b1c9cb0829ee08dc65f816b15ddfdfc |
Import Hash : | 671a1463842121ba57af655bdf3da007 |
Sections 6 | .text .rdata .data .pdata .rsrc .reloc |
Directories 4 | import resource debug relocation |
File features detected
Anti VM
Signed
XOR
OSINT Enrichments
Virus Total: | 34/77 VT report date: 2024-10-12 20:57:58 |
Malware Type 1 | trojan |
URLs, FQDN and IP indicators 1
PE Sections 0 suspicious
Name | VAddress | VSize | Size | SHA1 | MD5 | Suspicious |
---|---|---|---|---|---|---|
.text | 0x1000 | 0x2783 | 10240 | 579a7460c7c0b22dd8e343bb81020aedb89f8328 | aee0326a47efbae5b6a166ad9fded467 | |
.rdata | 0x4000 | 0x2512 | 9728 | c2b943f68b494aec038355939ffabdac54e7017e | 324fa72e122befaee26ee8668e0a7bf5 | |
.data | 0x7000 | 0x7a0 | 512 | 0155cca051e37ccb56e0d3f39793769c89b94a2e | a5251d34c90bd7c6631fde061fd04ce5 | |
.pdata | 0x8000 | 0x324 | 1024 | cce9a11412ebbae6824459a20a8a101e4cf95ddf | e10ed82ae93ecf908c5154341ee7b855 | |
.rsrc | 0x9000 | 0x1e8 | 512 | 25359da070b6b64e5caddd1a09957a43a83b5c07 | b62c408e2a33a54eed41bd643e2fddee | |
.reloc | 0xa000 | 0x64 | 512 | e2040f7a82d97c581253769f3735c4771b0d7a99 | a42c7e1b05d224021d9f580ecd543fd9 |
PE Resources 1
Name | Language | Sublanguage | Offset | Size | Data |
---|---|---|---|---|---|
RT_MANIFEST | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x9060 | 392 |
Packers detected 1
Microsoft Visual C++ 8.0 (DLL) |
Anti debug functions 4
IsDebuggerPresent |
IsProcessorFeaturePresent |
TerminateProcess |
UnhandledExceptionFilter |
Strings analysis - File found
Library |
api-ms-win-crt-math-l1-1-0.dll |
api-ms-win-crt-runtime-l1-1-0.dll |
api-ms-win-crt-heap-l1-1-0.dll |
msvcp140.dll |
KERNEL32.dll |
vcruntime140.dll |
api-ms-win-crt-stdio-l1-1-0.dll |
USER32.dll |
VCRUNTIME140_1.dll |
api-ms-win-crt-locale-l1-1-0.dll |