Bossf.exe

First submission 2023-09-14 09:32:02

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 172.5 KB (176640 bytes)
Compile time: 2012-07-14 00:47:16
MD5: 638c636255e504c4770e02f7271daa6c
SHA1: 16c708fe8846e65d3dca54b3d040d375d5cb54df
SHA256: a19f1949995aa24c6afd60e3c19b54dd3823322385fe2e80734c09dabdec0131
Import Hash : bf5a4aa99e5b160f8521cadd6bfe73b8
Sections 4 .text .rdata .data .rsrc
Directories 3 import resource debug
Virus Total: 32/58 VT report date: 2023-09-14 07:29:27

File features detected

Is DLL

Packers

Anti Debug

Anti VM

Signed

XOR

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://194.180.49.211/D/Bossf.exe VirusTotal Report 194.180.49.211 VirusTotal Report 2023-09-14 09:32:02

PE Sections 1 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x19718 104448 a794c9e84636b01533e536d4d35732ebc58ecd74 7a9d705c0cef9ebd22c396f1515efacc
.rdata 0x1b000 0x6db4 28160 ac050a1809ae127615e1683adb73d87013096d10 5826801f33fc1b607aa8e942aa92e9fa
.data 0x22000 0x30c0 5632 c5c9b70d1fbe0cb0f1d48ea41ef1cd0da70d708d 2fe51a72ede820cd7cf55a77ba59b1f4
.rsrc 0x26000 0x9200 37376 e673d0f46f0baaeb7edbc43ae3d7c089054a89fc 42a4e440e264ac6cfa221cbc83f7919d

PE Resources 3

Name Language Sublanguage Offset Size Data
RT_RCDATA LANG_NEUTRAL SUBLANG_NEUTRAL 0x2ece8 32
RT_VERSION LANG_NEUTRAL SUBLANG_NEUTRAL 0x2ed08 780
RT_MANIFEST LANG_NEUTRAL SUBLANG_NEUTRAL 0x2f014 490

Meta infos 12

LegalCopyright: Copyright \xa9 2023
Assembly Version: 1.0.0.0
InternalName: NNnNnB.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: NNnNnB
ProductVersion: 1.0.0.0
FileDescription: NNnNnB
Translation: 0x0000 0x04b0
OriginalFilename: NNnNnB.exe

Packers detected 2

Microsoft Visual C++ 8
VC8 -> Microsoft Corporation

Anti debug functions 5

GetLastError
IsDebuggerPresent
RaiseException
TerminateProcess
UnhandledExceptionFilter

Strings analysis - File found

Library
KERNEL32.dll
mscoree.dll
USER32.dll
OLEAUT32.dll
ole32.dll

Import functions

Name Latest seen MD5
.NetFramework.exe 2023-06-22 19:16:03 b8bee86a938a8b2245aa9343077958a6
Lion.exe 2023-06-27 19:52:02 1cbb726aada6d392c55f2a52113d05eb
mo.exe 2023-06-28 10:56:02 8ef917494a0e51cc61e491173b16150d
btt.exe 2023-06-29 07:32:01 e052e7de9592d69a07411a1d2bb182b6
haitianzx.exe 2023-07-05 07:31:03 2d2e577e7bb99c8854fdc99d94eb1338
looorlki.exe 2023-07-07 08:36:02 02702bec6d76bf792b0ce39f6fab58e9
NBbH87.exe 2023-07-14 12:42:01 e8a59b068f08284eb4159afadb10110e
Asx.exe 2023-07-14 14:24:02 af2e78a40b94d6e6b5f1d002d340c059
MNKLOP873.exe 2023-07-20 07:25:02 a79a555d8074362ce42e03465fc6655d
SuWar3Tools.exe 2023-09-04 20:11:05 8306a21a9f7d2d20d2ef8df82d9a7750
B.exe 2023-09-13 09:52:03 1c91d91d58c62fb93b9d3a7ee6f273fc
CB.exe 2023-09-13 11:12:02 f89a7590147ed0c19e142705acf490af
F.exe 2023-09-13 11:13:02 be5d8aca3a377e02a7effcdc07029afd
Gen.exe 2023-09-13 17:34:03 d0fa181e7c69e0b03b243c2190910ddd
Bossk.exe 2023-09-14 09:33:03 81c2a78ac19f048e31da4ca0fa9b001a