support.exe
First submission 2024-10-16 18:14:02
File details
File type: | PE32 executable (GUI) Intel 80386, for MS Windows |
Mime type: | application/x-dosexec |
File size: | 792.0 KB (811008 bytes) |
Compile time: | 2020-09-15 18:09:42 |
MD5: | 69a8ed0b8edc940968f8535c20b4bbe4 |
SHA1: | 3557d87e895d994b7099c428b20f9088475194b5 |
SHA256: | 0498fcaffbcc80f86c8a6cb1ef655b9713bd96e2d08af2468570d087caa53ff7 |
Import Hash : | 3e985254f2e34ad96da799a2a5d33efe |
Sections 4 | .text .rdata .data .rsrc |
Directories 2 | import resource |
File features detected
URLs, FQDN and IP indicators 1
PE Sections 0 suspicious
Name | VAddress | VSize | Size | SHA1 | MD5 | Suspicious |
---|---|---|---|---|---|---|
.text | 0x1000 | 0x8dbba | 581632 | 0129e574fb713215dd6042453cafc0ed79ceddeb | aca20b512ec0bcae35e2424bc01947f9 | |
.rdata | 0x8f000 | 0x1a5a6 | 110592 | 49aef74be74bb96ad1bc51640e399712e06b70e3 | 9e1fe715f2c3b902583721ecc37f38a2 | |
.data | 0xaa000 | 0x1ebb8 | 94208 | 5ca32bd3663a5310caf4b68beee852bfd214c0e3 | 412166ee57c4d2a693a2839a2298f167 | |
.rsrc | 0xc9000 | 0x45cc | 20480 | 015862cb261bcc5ef446e18626d89df0c9189d3f | fa54b5a72bd44e10a073598c6b6afcd2 |
PE Resources 5
Name | Language | Sublanguage | Offset | Size | Data |
---|---|---|---|---|---|
BINARY | LANG_NEUTRAL | SUBLANG_NEUTRAL | 0xc91e8 | 79 | |
RT_ICON | LANG_NEUTRAL | SUBLANG_NEUTRAL | 0xcc888 | 1128 | |
RT_GROUP_ICON | LANG_NEUTRAL | SUBLANG_NEUTRAL | 0xcccf0 | 48 | |
RT_VERSION | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0xccd20 | 744 | |
RT_MANIFEST | LANG_NEUTRAL | SUBLANG_NEUTRAL | 0xcd008 | 1474 |
Meta infos 13
LegalCopyright: | |
InternalName: | Ammyy Admin |
FileVersion: | 3.10 |
FileDescription: | Ammyy Admin |
SpecialBuild: | |
CompanyName: | Ammyy LLC |
LegalTrademarks: | |
Comments: | |
ProductName: | Ammyy Admin |
ProductVersion: | 3.10 |
PrivateBuild: | |
Translation: | 0x0409 0x04b0 |
OriginalFilename: |
Packers detected 3
Microsoft Visual C++ v6.0 |
Microsoft Visual C++ 5.0 |
Microsoft Visual C++ |
Anti debug functions 7
FindWindowA |
FindWindowW |
GetLastError |
GetWindowThreadProcessId |
Process32First |
Process32Next |
TerminateProcess |
Anti debug functions 1
VMCheck.dll |
Strings analysis - File found
Binary |
Ammyy_Contact_Book.bin |
*.bin |
contacts3.bin |
_tmp\AMMYY_Admin.bin |
settings3.bin |
settings.bin |
contacts.bin |
sessions.bin |
Log |
eAMMYY_service.log |
access.log |
ammyy.log |
ammyy_id.log |
Temporary |
%sAmmyy_%X.tmp |
_%.4hu-%.2hu%.2hu-%.2hu%.2hu%.2hu-%.3hu.tmp |
Object |
hhctrl.ocx |
Data |
%u-%u-%u-%u.dat |
Library |
W\winsta.dll |
Shcore.dll |
ewmsgapi.dll |
ADVAPI32.dll |
SHLWAPI.dll |
dwmapi.dll |
WININET.dll |
WTSAPI32.dll |
MSVCRT.dll |
SHELL32.dll |
WS2_32.dll |
COMCTL32.dll |
secur32.dll |
USER32.dll |
USERENV.dll |
SETUPAPI.dll |
GDI32.dll |
KERNEL32.dll |
DSOUND.dll |
COMDLG32.dll |
IPHLPAPI.DLL |
Strings analysis - Possible IPs found 1
127.0.0.1 |
Strings analysis - Possible URLs found 5
http://rl.a4on.tv |
http://www.ammyy.com/?lang= |
http://www.ammyy.com/ |
https:// |
http://www.ammyy.com |
Import functions
Name | Latest seen | MD5 |
---|---|---|
ammyadmin.exe | 2024-10-18 05:20:12 | 90aadf2247149996ae443e2c82af3730 |
AA_v3.exe | 2024-10-16 18:10:02 | ee50ecb3152bdebe5fff2cc3cfb4d451 |