newlife.exe

First submission 2023-09-14 04:31:03

File details

File type: PE32+ executable (GUI) x86-64, for MS Windows
Mime type: application/x-dosexec
File size: 285.93 KB (292792 bytes)
Compile time: 2023-09-07 02:58:39
MD5: 69c0ce8858c37ee1e29fbeb4d0acc928
SHA1: ce762c0b569a59bbd8f8aee39eb56ca9be5421b6
SHA256: 58334b23c64f5926faf1201c6875c2b44d60fa9ba85fba7ebc15f1ccabd0f803
Import Hash : 8a8dbe6ecfacdaceac22d14c24917858
Sections 7 .text .rdata .data .pdata _RDATA .rsrc .reloc
Directories 5 import resource debug relocation security
Virus Total: 16/69 VT report date: 2023-09-14 01:30:51

File features detected

Is DLL

Packers

Anti Debug

Anti VM

Signed

XOR

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://77.91.68.78/lend/newlife.exe VirusTotal Report 77.91.68.78 VirusTotal Report 2023-09-14 04:31:03

PE Sections 1 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x1f680 129024 9d47248eecc0e0f54f704c5e2b8e4e6ba542a252 622a8648e9320b22c3e012a095192f88
.rdata 0x21000 0xe9a8 59904 489940501b3d61c0ea64dd0cd2ccbfeadd4d2893 c2b328ba58e95a76f3bd6e55c13f0657
.data 0x30000 0x2a84 4608 486984b0452ca7b2b3e019270ede0e5ad9d566ea b535cad2568ea5d5cde03908b2b2eb5b
.pdata 0x33000 0x1f68 8192 3ca349e9ab9069d1336e80b5f318f883734c9d5a 26ef9da4aafd9a3905f8f3bee7f1617c
_RDATA 0x35000 0x15c 512 de4f7375a447c9b87cf01daeb2c53e3e09be7281 f994cd5c236c0705fe6198dc821b4371
.rsrc 0x36000 0x13678 79872 9468c0e299db928887a4a6b05c6da37f78c7cd63 10fd572e4b8d635d4db92141826bb92b
.reloc 0x4a000 0x91c 2560 1c694a8fd219bf6a9088c4af786069047e8e40c6 fcd0930df8bc2892d1115d30c4c03e1e

PE Resources 4

Name Language Sublanguage Offset Size Data
RT_ICON LANG_NEUTRAL SUBLANG_NEUTRAL 0x3613c 9640
RT_RCDATA LANG_NEUTRAL SUBLANG_NEUTRAL 0x386e4 69120
RT_GROUP_ICON LANG_NEUTRAL SUBLANG_NEUTRAL 0x494e4 20
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x494f8 381

Packers detected 1

Microsoft Visual C++ 8.0 (DLL)

Anti debug functions 6

GetLastError
IsDebuggerPresent
IsProcessorFeaturePresent
RaiseException
TerminateProcess
UnhandledExceptionFilter

File signature

MD5 SHA1 Block size Virtual Address
112563af23db8c866b11a8d4c23a7763 45027652e5267d1856ecd677958d0f382ef98b85 7096 285696

Strings analysis - File found

Library
mscoree.dll
OLEAUT32.dll
ole32.dll
KERNEL32.dll

Strings analysis - Possible URLs found 9

http://ocsp.digicert.com0C
http://ocsp.digicert.com0A
http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
http://ocsp.digicert.com0X

Import functions

Name Latest seen MD5
cryptusa.exe 2023-09-10 16:55:01 4fe88bc5440133565a8e28a78d3bbcbd
cryptnobaa.exe 2023-09-12 02:11:02 41bdf3bbb8d27902f5f22e9b5a88a25b