Bossf.exe
First submission 2023-09-14 09:32:02
File details
File type: | PE32 executable (GUI) Intel 80386, for MS Windows |
Mime type: | application/x-dosexec |
File size: | 172.5 KB (176640 bytes) |
Compile time: | 2012-07-14 00:47:16 |
MD5: | 638c636255e504c4770e02f7271daa6c |
SHA1: | 16c708fe8846e65d3dca54b3d040d375d5cb54df |
SHA256: | a19f1949995aa24c6afd60e3c19b54dd3823322385fe2e80734c09dabdec0131 |
Import Hash : | bf5a4aa99e5b160f8521cadd6bfe73b8 |
Sections 4 | .text .rdata .data .rsrc |
Directories 3 | import resource debug |
Virus Total: | 32/58 VT report date: 2023-09-14 07:29:27 |
File features detected
Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR
URLs, FQDN and IP indicators 1
PE Sections 1 suspicious
Name | VAddress | VSize | Size | SHA1 | MD5 | Suspicious |
---|---|---|---|---|---|---|
.text | 0x1000 | 0x19718 | 104448 | a794c9e84636b01533e536d4d35732ebc58ecd74 | 7a9d705c0cef9ebd22c396f1515efacc | |
.rdata | 0x1b000 | 0x6db4 | 28160 | ac050a1809ae127615e1683adb73d87013096d10 | 5826801f33fc1b607aa8e942aa92e9fa | |
.data | 0x22000 | 0x30c0 | 5632 | c5c9b70d1fbe0cb0f1d48ea41ef1cd0da70d708d | 2fe51a72ede820cd7cf55a77ba59b1f4 | |
.rsrc | 0x26000 | 0x9200 | 37376 | e673d0f46f0baaeb7edbc43ae3d7c089054a89fc | 42a4e440e264ac6cfa221cbc83f7919d |
PE Resources 3
Name | Language | Sublanguage | Offset | Size | Data |
---|---|---|---|---|---|
RT_RCDATA | LANG_NEUTRAL | SUBLANG_NEUTRAL | 0x2ece8 | 32 | |
RT_VERSION | LANG_NEUTRAL | SUBLANG_NEUTRAL | 0x2ed08 | 780 | |
RT_MANIFEST | LANG_NEUTRAL | SUBLANG_NEUTRAL | 0x2f014 | 490 |
Meta infos 12
LegalCopyright: | Copyright \xa9 2023 |
Assembly Version: | 1.0.0.0 |
InternalName: | NNnNnB.exe |
FileVersion: | 1.0.0.0 |
CompanyName: | |
LegalTrademarks: | |
Comments: | |
ProductName: | NNnNnB |
ProductVersion: | 1.0.0.0 |
FileDescription: | NNnNnB |
Translation: | 0x0000 0x04b0 |
OriginalFilename: | NNnNnB.exe |
Packers detected 2
Microsoft Visual C++ 8 |
VC8 -> Microsoft Corporation |
Anti debug functions 5
GetLastError |
IsDebuggerPresent |
RaiseException |
TerminateProcess |
UnhandledExceptionFilter |
Strings analysis - File found
Library |
KERNEL32.dll |
mscoree.dll |
USER32.dll |
OLEAUT32.dll |
ole32.dll |
Import functions
Name | Latest seen | MD5 |
---|---|---|
.NetFramework.exe | 2023-06-22 19:16:03 | b8bee86a938a8b2245aa9343077958a6 |
Lion.exe | 2023-06-27 19:52:02 | 1cbb726aada6d392c55f2a52113d05eb |
mo.exe | 2023-06-28 10:56:02 | 8ef917494a0e51cc61e491173b16150d |
btt.exe | 2023-06-29 07:32:01 | e052e7de9592d69a07411a1d2bb182b6 |
haitianzx.exe | 2023-07-05 07:31:03 | 2d2e577e7bb99c8854fdc99d94eb1338 |
looorlki.exe | 2023-07-07 08:36:02 | 02702bec6d76bf792b0ce39f6fab58e9 |
NBbH87.exe | 2023-07-14 12:42:01 | e8a59b068f08284eb4159afadb10110e |
Asx.exe | 2023-07-14 14:24:02 | af2e78a40b94d6e6b5f1d002d340c059 |
MNKLOP873.exe | 2023-07-20 07:25:02 | a79a555d8074362ce42e03465fc6655d |
SuWar3Tools.exe | 2023-09-04 20:11:05 | 8306a21a9f7d2d20d2ef8df82d9a7750 |
B.exe | 2023-09-13 09:52:03 | 1c91d91d58c62fb93b9d3a7ee6f273fc |
CB.exe | 2023-09-13 11:12:02 | f89a7590147ed0c19e142705acf490af |
F.exe | 2023-09-13 11:13:02 | be5d8aca3a377e02a7effcdc07029afd |
Gen.exe | 2023-09-13 17:34:03 | d0fa181e7c69e0b03b243c2190910ddd |
Bossk.exe | 2023-09-14 09:33:03 | 81c2a78ac19f048e31da4ca0fa9b001a |