emptyfilename.tmp

First submission 2022-05-13 13:46:07

File details

File type: PE32+ executable (DLL) (GUI) x86-64, for MS Windows
File type: 532.5 KB (545280 bytes)
Compile time: 2022-05-13 00:09:28
MD5: 6449614c5045a9a5416d227a23f56908
SHA1: 6ac87c24867f023af22add538bc1dc5368041328
SHA256: dec47f6310059284f40b2b707fea62ac97ad34fa057c5deb236484b5b226cdb6
Import Hash : b268dbaa2e6eb6acd16e04d482356598
Sections 6 .text .rdata .data .pdata .rsrc .reloc
Directories 4 import export resource relocation
Virus Total:

File features detected

Is DLL

Packers

Anti Debug

Anti VM

Signed

XOR

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXps://ideoso.com.tw/cgi-bin/zLrnBd2Eg1N3UVy5yL/ VirusTotal Report ideoso.com.tw VirusTotal Report 2022-05-13 13:46:07

PE Sections 1 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x504ca 329216 afb0b05fb43170043cdc7c8ec75b8594c715ec9e 0b6c16a11849c5b1d4a00256cdee3ffd
.rdata 0x52000 0x3d5f 15872 d2b24e4ed9a14f6eaa818b72d2ab81eebc813ae2 0595df5a1b7cc396dd49af92224f39ee
.data 0x56000 0x20d8 4608 8eb4497c10e31e04b9efde77c140216e73107d92 7a3ce223ac74d490179e8b47d33a52ee
.pdata 0x59000 0xe1c 4096 0d6ada03aa06b7936160ba845687d8815c457d37 0cec33cb157341671ebfd84c470fcad0
.rsrc 0x5a000 0x2dffc 188416 6052fa48d51f8993ffd8c3b925512bffbb9e3190 5b4b294d7dd9eabd5ed0090810d9ac9f
.reloc 0x88000 0x6f8 2048 fe2653e6f0b54c8192959a0e794da037a45cb9bb e7ee2764ccb9c768740a08ceb647416f

PE Resources 2

Name Language Sublanguage Offset Size Data
RT_RCDATA LANG_ENGLISH SUBLANG_ENGLISH_US 0x5a0a0 187904
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x87ea0 346

Anti debug functions 4

GetLastError
IsDebuggerPresent
TerminateProcess
UnhandledExceptionFilter

Strings analysis - File found

Library
mscoree.dll
USER32.dll
Project1.dll
ole32.dll
ADVAPI32.dll
KERNEL32.dll

Import functions

PE Exports 2 suspicious

Function Address
DllRegisterServer 0x180042050
DllUnregisterServer 0x180042080
Name Latest seen MD5
emptyfilename.tmp 2022-05-13 13:41:03 a24a1b210bc73594b29f060b98f99f20
emptyfilename.tmp 2022-05-13 13:42:04 883daa2a5c78abb50def4accbfaca1ea
emptyfilename.tmp 2022-05-13 13:43:05 52b4534ea155ac66429d514518ac6310
emptyfilename.tmp 2022-05-13 13:44:04 6352385e34de0c1d25aff8dbc44fbf98
emptyfilename.tmp 2022-05-13 13:45:05 f833d9c8f2c0d9ad1ba6aa11093b4da7
emptyfilename.tmp 2022-05-13 20:26:02 e09490d01754c8f6e4343f0e948bb745
emptyfilename.tmp 2022-05-13 20:27:03 7c5e808d6b0e6ad9a12b87d76e7abaa8
emptyfilename.tmp 2022-05-13 20:28:03 62b70131e74722104ed923c6328b1e78
emptyfilename.tmp 2022-05-13 20:30:03 a78beb9fefec48fdb5fb737efd3d4ad9
emptyfilename.tmp 2022-05-13 23:00:02 b6c32a71dd62b71931bbed07894e27e9
emptyfilename.tmp 2022-05-13 23:26:06 d3cd6840fc8e544cca380c64d9a80743
emptyfilename.tmp 2022-05-13 23:27:07 312174ba161009051a5244355e5891cd
emptyfilename.tmp 2022-05-13 23:28:04 214d5d02c1f7ad064fac393bef88d2ab
emptyfilename.tmp 2022-05-13 23:29:04 d7102e67b35fa919941cc5c08b6c07ba
emptyfilename.tmp 2022-05-14 02:00:03 16ab3658210849e8a86e30f20b859e43