Updater.exe

First submission 2024-10-15 17:51:02

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 912.5 KB (934400 bytes)
Compile time: 2023-07-08 07:25:57
MD5: 6b2e502201ddbcdc74f90c83474c091a
SHA1: 1dcce6035dbdf25413f7b6a9c66365eb74932079
SHA256: 26184d52dc378e018f77bbb42378c5eb701ba2c32bc88ca4b7e614c090695d4a
Import Hash : 8d813561e4ad07e9f8918a83e16f95c0
Sections 4 .text .rdata .data .rsrc
Directories 2 import resource

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://asurastrike.de/ERAB/Updater.exe VirusTotal Report asurastrike.de VirusTotal Report 2024-10-15 17:51:02

PE Sections 0 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0xa0731 657408 80eae0a0bad5087f159f0d2a340aa72cfc20704b 6cc0324f1402f1dae84a24ba7b553766
.rdata 0xa2000 0x23e16 147456 7a52e7a85dd3ce2585292d7d03d4905576aa93ed 5920a614da28cf6f1d2c504d7bb4b24e
.data 0xc6000 0x8fa4 13312 4566c18b3b264c499515b200cb08394be1de2b1f 93d8510a6fc7af6dffbc32c027387d7b
.rsrc 0xcf000 0x1c1b4 115200 1f31629e500f9d553a488efce38975348501bc0a d734ab62015541099e282efec6e38785

PE Resources 8

Name Language Sublanguage Offset Size Data
RT_ICON LANG_ENGLISH SUBLANG_ENGLISH_US 0xe89c8 296
RT_MENU LANG_ENGLISH SUBLANG_ENGLISH_US 0xe8af0 712
RT_DIALOG LANG_ENGLISH SUBLANG_ENGLISH_US 0xe8db8 232
RT_ACCELERATOR LANG_ENGLISH SUBLANG_ENGLISH_US 0xe8ea0 72
RT_RCDATA LANG_ENGLISH SUBLANG_ENGLISH_US 0xe8ee8 6999
RT_GROUP_ICON LANG_ENGLISH SUBLANG_ENGLISH_US 0xeaa90 20
RT_VERSION LANG_ENGLISH SUBLANG_ENGLISH_US 0xeaaa4 540
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0xeacc0 1268

Meta infos 9

LegalCopyright:
InternalName:
FileVersion: 1.1.37.01
CompanyName:
ProductVersion: 1.1.37.01
FileDescription:
Translation: 0x0409 0x04b0
OriginalFilename:
ProductName:

Packers detected 2

Microsoft Visual C++ 8
VC8 -> Microsoft Corporation

Anti debug functions 11

FindWindowW
GetLastError
GetWindowThreadProcessId
IsDebuggerPresent
IsProcessorFeaturePresent
OutputDebugStringW
Process32FirstW
Process32NextW
RaiseException
TerminateProcess
UnhandledExceptionFilter

Anti debug functions 1

VMCheck.dll

Strings analysis - File found

Text
*.txt
FileDelete, README.txt
URLDownloadToFile, %version_url%, README.txt
Library
USER32.dll
KERNEL32.dll
dwmapi.dll
ntdll.dll
mscoree.dll
WUSER32.DLL
nKERNEL32.DLL
SHELL32.dll
OLEAUT32.dll
ADVAPI32.dll
WININET.dll
COMCTL32.dll
Loop %A_WinDir%\System32\XInput1_*.dll
WINMM.dll
COMDLG32.dll
PSAPI.DLL
ole32.dll
VERSION.dll
GDI32.dll
WSOCK32.dll

Strings analysis - Possible URLs found 1

https://autohotkey.com

Import functions

Name Latest seen MD5
ERAB.exe 2024-08-26 18:12:03 dfa3bc45245a6f8f6c7085e625afbb99