madey.exe

First submission 2024-10-15 17:53:02

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 549.0 KB (562176 bytes)
Compile time: 2024-10-09 14:37:21
MD5: 689ff816fc3db38894e81abbdf63c02b
SHA1: aceb8ce81d4724d77a1b3031015f6e60d1139352
SHA256: f2ebbd96f7cf19aa8cc8b1273d1f80169de93ac4dde951ff4547177a11010945
Import Hash : 91d1583dab6f50e9cc35b0dbf587fb1f
Sections 5 .text .rdata .data .rsrc .reloc
Directories 5 import resource debug tls relocation

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 51/77 VT report date: 2024-10-11 11:14:51
Malware Type 2 trojan downloader
Threat Type 3 amadey zusy deyma

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://shopping-nice.com/files/madey.exe VirusTotal Report shopping-nice.com VirusTotal Report 2024-10-15 17:53:02

PE Sections 0 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x66292 418816 1fed8e96be773099d26ce580ebe6ec4d2f80d7a6 2a70a11d9a43b02b291920aa110febe6
.rdata 0x68000 0x1913e 102912 f7c1e4252dad5d8f8f6ee26c73d4102b05abf8cd 936fd796e0e393fb4948f4dadf8e936c
.data 0x82000 0x7c34 14336 e9c6bb7bd3f8cef8b822dfc7c726733de7332512 f22e261e21cd109e9874c76c2fcae315
.rsrc 0x8a000 0x1e0 512 7a47eb909928898bd871e80e9e8519ab0406bb49 e2d2f7647d61a156924612e95904ad1f
.reloc 0x8b000 0x5ff0 24576 e7fa9481341e34919b676f8b051770a8279a1d9f d937d458e0c1ae681285b05342fea117

PE Resources 1

Name Language Sublanguage Offset Size Data
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x8a060 381

Packers detected 2

Microsoft Visual C++ 8
VC8 -> Microsoft Corporation

Anti debug functions 8

GetLastError
IsDebuggerPresent
IsProcessorFeaturePresent
Process32FirstW
Process32NextW
RaiseException
TerminateProcess
UnhandledExceptionFilter

Anti debug functions 1

VMCheck.dll

Strings analysis - File found

Library
api-ms-win-core-synch-l1-2-0.dll
Bkernel32.dll
mscoree.dll
combase.dll
ADVAPI32.dll
SHELL32.dll
WININET.dll
WS2_32.dll
USER32.dll
gdiplus.dll
ntdll.dll
ole32.dll
GDI32.dll
KERNEL32.dll

Import functions