support.exe

First submission 2024-10-16 18:14:02

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 792.0 KB (811008 bytes)
Compile time: 2020-09-15 18:09:42
MD5: 69a8ed0b8edc940968f8535c20b4bbe4
SHA1: 3557d87e895d994b7099c428b20f9088475194b5
SHA256: 0498fcaffbcc80f86c8a6cb1ef655b9713bd96e2d08af2468570d087caa53ff7
Import Hash : 3e985254f2e34ad96da799a2a5d33efe
Sections 4 .text .rdata .data .rsrc
Directories 2 import resource

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://rl.a4on.tv/support.exe VirusTotal Report rl.a4on.tv VirusTotal Report 2024-10-16 18:14:02

PE Sections 0 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x8dbba 581632 0129e574fb713215dd6042453cafc0ed79ceddeb aca20b512ec0bcae35e2424bc01947f9
.rdata 0x8f000 0x1a5a6 110592 49aef74be74bb96ad1bc51640e399712e06b70e3 9e1fe715f2c3b902583721ecc37f38a2
.data 0xaa000 0x1ebb8 94208 5ca32bd3663a5310caf4b68beee852bfd214c0e3 412166ee57c4d2a693a2839a2298f167
.rsrc 0xc9000 0x45cc 20480 015862cb261bcc5ef446e18626d89df0c9189d3f fa54b5a72bd44e10a073598c6b6afcd2

PE Resources 5

Name Language Sublanguage Offset Size Data
BINARY LANG_NEUTRAL SUBLANG_NEUTRAL 0xc91e8 79
RT_ICON LANG_NEUTRAL SUBLANG_NEUTRAL 0xcc888 1128
RT_GROUP_ICON LANG_NEUTRAL SUBLANG_NEUTRAL 0xcccf0 48
RT_VERSION LANG_ENGLISH SUBLANG_ENGLISH_US 0xccd20 744
RT_MANIFEST LANG_NEUTRAL SUBLANG_NEUTRAL 0xcd008 1474

Meta infos 13

LegalCopyright:
InternalName: Ammyy Admin
FileVersion: 3.10
FileDescription: Ammyy Admin
SpecialBuild:
CompanyName: Ammyy LLC
LegalTrademarks:
Comments:
ProductName: Ammyy Admin
ProductVersion: 3.10
PrivateBuild:
Translation: 0x0409 0x04b0
OriginalFilename:

Packers detected 3

Microsoft Visual C++ v6.0
Microsoft Visual C++ 5.0
Microsoft Visual C++

Anti debug functions 7

FindWindowA
FindWindowW
GetLastError
GetWindowThreadProcessId
Process32First
Process32Next
TerminateProcess

Anti debug functions 1

VMCheck.dll

Strings analysis - File found

Binary
Ammyy_Contact_Book.bin
*.bin
contacts3.bin
_tmp\AMMYY_Admin.bin
settings3.bin
settings.bin
contacts.bin
sessions.bin
Log
eAMMYY_service.log
access.log
ammyy.log
ammyy_id.log
Temporary
%sAmmyy_%X.tmp
_%.4hu-%.2hu%.2hu-%.2hu%.2hu%.2hu-%.3hu.tmp
Object
hhctrl.ocx
Data
%u-%u-%u-%u.dat
Library
W\winsta.dll
Shcore.dll
ewmsgapi.dll
ADVAPI32.dll
SHLWAPI.dll
dwmapi.dll
WININET.dll
WTSAPI32.dll
MSVCRT.dll
SHELL32.dll
WS2_32.dll
COMCTL32.dll
secur32.dll
USER32.dll
USERENV.dll
SETUPAPI.dll
GDI32.dll
KERNEL32.dll
DSOUND.dll
COMDLG32.dll
IPHLPAPI.DLL

Strings analysis - Possible IPs found 1

127.0.0.1

Strings analysis - Possible URLs found 5

http://rl.a4on.tv
http://www.ammyy.com/?lang=
http://www.ammyy.com/
https://
http://www.ammyy.com

Import functions

Name Latest seen MD5
ammyadmin.exe 2024-10-18 05:20:12 90aadf2247149996ae443e2c82af3730
AA_v3.exe 2024-10-16 18:10:02 ee50ecb3152bdebe5fff2cc3cfb4d451