r.exe
First submission 2023-09-14 14:32:04
File details
File type: | PE32 executable (GUI) Intel 80386, for MS Windows |
Mime type: | application/x-dosexec |
File size: | 1208.48 KB (1237485 bytes) |
Compile time: | 2022-03-03 14:15:57 |
MD5: | 7eec2626da27debbdef59bcb7427f8a4 |
SHA1: | c8d29e22c4e501919a69581466e504dc5b8059ed |
SHA256: | bf1a2173cdf3a47abd060cbd86fc8c3cda7d01443694d7253bbd547f7feb21f4 |
Import Hash : | 12e12319f1029ec4f8fcbed7e82df162 |
Sections 6 | .text .rdata .data .didat .rsrc .reloc |
Directories 5 | import export resource debug relocation |
Virus Total: | 53/71 VT report date: 2023-09-14 12:14:29 |
File features detected
Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR
URLs, FQDN and IP indicators 1
PE Sections 0 suspicious
Name | VAddress | VSize | Size | SHA1 | MD5 | Suspicious |
---|---|---|---|---|---|---|
.text | 0x1000 | 0x31bdc | 203776 | 619c1d2d3a247d5ea0748c89b0b9d66a30b6417c | 2831bb8b11e3209658a53131886cdf98 | |
.rdata | 0x33000 | 0xaec0 | 45056 | 6ecf068cbcb8b25488348341dfe9cd146d7efff1 | 042f11346230ca5aa360727d9908e809 | |
.data | 0x3e000 | 0x24720 | 4096 | f645e3c9267ab7df17b1b1f7196a59a1fa9b097a | 9670b581969e508258d8bc903025de5e | |
.didat | 0x63000 | 0x190 | 512 | 08a8f0e687db994f8484fd20dc56094f4c219de5 | c83554035c63bb446c6208d0c8fa0256 | |
.rsrc | 0x64000 | 0xdff8 | 57344 | a881e58590da632c259501ba5202ebc259ffaa84 | ba08fbcd0ed7d9e6a268d75148d9914b | |
.reloc | 0x72000 | 0x233c | 9216 | f1f4ef62479ee5ed243652eb278d24f467b2beee | 40b5e17755fd6fdd34de06e5cdb7f711 |
PE Resources 6
Name | Language | Sublanguage | Offset | Size | Data |
---|---|---|---|---|---|
PNG | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x65198 | 5545 | |
RT_ICON | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x6beb8 | 15729 | |
RT_DIALOG | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x6fc98 | 594 | |
RT_STRING | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x71f20 | 214 | |
RT_GROUP_ICON | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x6fc30 | 104 | |
RT_MANIFEST | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x70810 | 1875 |
Packers detected 2
Microsoft Visual C++ 8 |
VC8 -> Microsoft Corporation |
Anti debug functions 6
GetLastError |
IsDebuggerPresent |
IsProcessorFeaturePresent |
RaiseException |
TerminateProcess |
UnhandledExceptionFilter |
Strings analysis - File found
Temporary |
%s.%d.tmp |
winrarsfxmappingfile.tmp |
Library |
Crypt32.dll |
peerdist.dll |
msasn1.dll |
profapi.dll |
RpcRtRemote.dll |
sfc_os.dll |
XmlLite.dll |
USERENV.dll |
ntmarta.dll |
rasadhlp.dll |
mscoree.dll |
mlang.dll |
cryptsp.dll |
linkinfo.dll |
UxTheme.dll |
imageres.dll |
shdocvw.dll |
cscapi.dll |
usp10.dll |
wkscli.dll |
devrtl.dll |
secur32.dll |
wintrust.dll |
atl.dll |
WINNSI.DLL |
rsaenh.dll |
riched20.dll |
comres.dll |
cryptui.dll |
ntshrui.dll |
slc.dll |
oleaccrc.dll |
PSAPI.DLL |
propsys.dll |
NETAPI32.dll |
aclui.dll |
dhcpcsvc6.dll |
cryptbase.dll |
ws2help.dll |
SHELL32.dll |
samlib.dll |
KERNEL32.dll |
VERSION.dll |
dwmapi.dll |
cabinet.dll |
MPR.dll |
WS2_32.dll |
WindowsCodecs.dll |
dnsapi.dll |
SSPICLI.DLL |
samcli.dll |
apphelp.dll |
dfscli.dll |
dsrole.dll |
ieframe.dll |
lpk.dll |
netutils.dll |
clbcatq.dll |
dhcpcsvc.dll |
IPHLPAPI.DLL |
srvcli.dll |
DXGIDebug.dll |
browcli.dll |
SETUPAPI.dll |
SHLWAPI.dll |
OLEAUT32.dll |
COMCTL32.dll |
ole32.dll |
USER32.dll |
ADVAPI32.dll |
gdiplus.dll |
GDI32.dll |
COMDLG32.dll |
Strings analysis - Possible URLs found 1
http://schemas.microsoft.com/SMI/2005/WindowsSettings |
Import functions
Name | Latest seen | MD5 |
---|---|---|
updater.exe | 2023-05-27 00:32:02 | da9c79f7e1fb381ce030fbfc31d3af6a |
7e8e3c8b54a3dd86e1b6afb3300169b0f41449d860921fef25d1038c26215f3f6f88efa1616203fc5b51 | 2023-06-04 15:41:03 | c4b9d83a65b7a0b05d7d24d4abcb29ae |
file.sfx.exe | 2023-07-20 08:55:01 | 839d6cbb65ab2966767e4b6619f14874 |