vur.exe

First submission 2023-09-12 21:51:02

File details

File type: PE32 executable (console) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 276.5 KB (283136 bytes)
Compile time: 2023-09-12 21:50:34
MD5: 73a427553c9c3d8b5f5377630c5d9c61
SHA1: 27ff7774709f7dae0508241527d41b64a462145b
SHA256: 1e645eaf6838de6fd68cf4e293a8fee949512f19aa20d86f29afdf307d16e11f
Import Hash : 29c8b785823d6c11cf3aae5ebbb5f0e6
Sections 6 .text .rdata .data .bsp .rsrc .reloc
Directories 6 import export resource debug tls relocation
Virus Total:

File features detected

Is DLL

Packers

Anti Debug

Anti VM

Signed

XOR

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://77.91.124.231/smo/vur.exe VirusTotal Report 77.91.124.231 VirusTotal Report 2023-09-12 21:51:03

PE Sections 1 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x2967c 169984 5255d2ee1d0dbf2c6f13603672b31a9eb96a9574 e401759721431b264499436cf2ba1a4f
.rdata 0x2b000 0xefa4 61440 7727ae5fd5b730cab6f41484d613f43c7ffe4d75 862262869583e9218d7e53e838700755
.data 0x3a000 0x2b10 7168 fefb6b70c80057e7f8b64544dd1869073489b200 ed3356dfdf856ccbae026cf6e70449f8
.bsp 0x3d000 0x8290 33792 d3fdd256ce42bada3f4a30b92ef14b2c87dfa344 437a582c75fe22c5fd230285a70e2c38
.rsrc 0x46000 0x1e0 512 0c4cf7ebbc143c7e4d8999528427acfafff801a6 83417fcae73ddfc36ec916d353fad7fd
.reloc 0x47000 0x22f0 9216 da2c82382ea48281c99469408c7451386ce94b6b 7b2f50f4561f7994a8a87fcd061a3525

PE Resources 1

Name Language Sublanguage Offset Size Data
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x46060 381

Packers detected 2

Microsoft Visual C++ 8
VC8 -> Microsoft Corporation

Anti debug functions 6

GetLastError
IsDebuggerPresent
IsProcessorFeaturePresent
RaiseException
TerminateProcess
UnhandledExceptionFilter

Strings analysis - File found

Library
api-ms-win-core-synch-l1-2-0.dll
mscoree.dll
KERNEL32.dll
USER32.dll
ole32.dll

Import functions

PE Exports 1 suspicious

Function Address
_jbxjgbguyw3@4 0x405420
Name Latest seen MD5
fotod445.exe 2023-09-12 20:11:03 4f125016bafd01db0f30a335c199497c
foto5445.exe 2023-09-13 10:55:03 3ee86d1734ad1891b99c7fdeb5382960
cryptedBB.exe 2023-09-13 15:12:02 3dd01710d9d6f58e5588ad656f0441a1