dControl.exe

First submission 2023-05-16 08:45:03 Last sumbission 2024-10-15 20:46:01

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
File size: 447.25 KB (457984 bytes)
Compile time: 2011-12-23 11:59:31
MD5: 58008524a6473bdf86c1040a9a9e39c3
SHA1: cb704d2e8df80fd3500a5b817966dc262d80ddb8
SHA256: 1ef6c1a4dfdc39b63bfe650ca81ab89510de6c0d3d7c608ac5be80033e559326
Import Hash : 890e522b31701e079a367b89393329e6
Sections 3 UPX0 UPX1 .rsrc
Directories 3 security resource import

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

URLs, FQDN and IP indicators 2

URL Host (FQDN/IP) Date Added
hXXp://testgenerateur.alwaysdata.net/downloads/dControl.exe VirusTotal Report testgenerateur.alwaysdata.net VirusTotal Report 2024-10-15 20:46:05
hXXp://195.161.114.43/smg/tools/dControl.exe VirusTotal Report 195.161.114.43 VirusTotal Report 2024-10-15 18:41:07

PE Sections 3 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
UPX0 0x1000 0x7b000 0 da39a3ee5e6b4b0d3255bfef95601890afd80709 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x7c000 0x42000 268800 972ce243cd0efd460371fafa471e0f47505c73a9 d1bc424aca3b6801d601ac9ce4acb047
.rsrc 0xbe000 0xf000 58880 00d48b7b234215249d4d6600764ae1617502bf9a f7c7f1ebf2b54ae37baf13d0e3bc5f73

Packers detected 1

UPX -> www.upx.sourceforge.net

File signature

MD5 SHA1 Block size Virtual Address
ec3323ddc9a7ea54649aff79f3f82320 e0ae2b363a1e1ca66b4d917e213a740e5469068d 7008 450960

Strings analysis - File found

Library
MPR.dll
COMDLG32.dll
KERNEL32.dll
WINMM.dll
GDI32.dll
USERENV.dll
WININET.dll
USER32.dll
ole32.dll
COMCTL32.dll
PSAPI.DLL
ICMP.DLL
SHELL32.dll
WSOCK32.dll
OLEAUT32.dll
VERSION.dll
ADVAPI32.dll

Strings analysis - Possible URLs found 10

http://subca.ocsp-certum.com02
http://crl.certum.pl/ctnca.crl0k
http://subca.ocsp-certum.com01
http://www.certum.pl/CPS0
http://repository.certum.pl/ctnca2.cer09
http://subca.ocsp-certum.com05
http://crl.certum.pl/ctnca2.crl0l
http://repository.certum.pl/ctnca.cer09
http://repository.certum.pl/ctsca2021.cer0@
http://crl.certum.pl/ctsca2021.crl0o