r.exe

First submission 2023-09-14 14:32:04

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 1208.48 KB (1237485 bytes)
Compile time: 2022-03-03 14:15:57
MD5: 7eec2626da27debbdef59bcb7427f8a4
SHA1: c8d29e22c4e501919a69581466e504dc5b8059ed
SHA256: bf1a2173cdf3a47abd060cbd86fc8c3cda7d01443694d7253bbd547f7feb21f4
Import Hash : 12e12319f1029ec4f8fcbed7e82df162
Sections 6 .text .rdata .data .didat .rsrc .reloc
Directories 5 import export resource debug relocation
Virus Total: 53/71 VT report date: 2023-09-14 12:14:29

File features detected

Is DLL

Packers

Anti Debug

Anti VM

Signed

XOR

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://89.23.98.75:7777/r.exe VirusTotal Report 89.23.98.75 VirusTotal Report 2023-09-14 14:32:05

PE Sections 0 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x31bdc 203776 619c1d2d3a247d5ea0748c89b0b9d66a30b6417c 2831bb8b11e3209658a53131886cdf98
.rdata 0x33000 0xaec0 45056 6ecf068cbcb8b25488348341dfe9cd146d7efff1 042f11346230ca5aa360727d9908e809
.data 0x3e000 0x24720 4096 f645e3c9267ab7df17b1b1f7196a59a1fa9b097a 9670b581969e508258d8bc903025de5e
.didat 0x63000 0x190 512 08a8f0e687db994f8484fd20dc56094f4c219de5 c83554035c63bb446c6208d0c8fa0256
.rsrc 0x64000 0xdff8 57344 a881e58590da632c259501ba5202ebc259ffaa84 ba08fbcd0ed7d9e6a268d75148d9914b
.reloc 0x72000 0x233c 9216 f1f4ef62479ee5ed243652eb278d24f467b2beee 40b5e17755fd6fdd34de06e5cdb7f711

PE Resources 6

Name Language Sublanguage Offset Size Data
PNG LANG_ENGLISH SUBLANG_ENGLISH_US 0x65198 5545
RT_ICON LANG_ENGLISH SUBLANG_ENGLISH_US 0x6beb8 15729
RT_DIALOG LANG_ENGLISH SUBLANG_ENGLISH_US 0x6fc98 594
RT_STRING LANG_ENGLISH SUBLANG_ENGLISH_US 0x71f20 214
RT_GROUP_ICON LANG_ENGLISH SUBLANG_ENGLISH_US 0x6fc30 104
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x70810 1875

Packers detected 2

Microsoft Visual C++ 8
VC8 -> Microsoft Corporation

Anti debug functions 6

GetLastError
IsDebuggerPresent
IsProcessorFeaturePresent
RaiseException
TerminateProcess
UnhandledExceptionFilter

Strings analysis - File found

Temporary
%s.%d.tmp
winrarsfxmappingfile.tmp
Library
Crypt32.dll
peerdist.dll
msasn1.dll
profapi.dll
RpcRtRemote.dll
sfc_os.dll
XmlLite.dll
USERENV.dll
ntmarta.dll
rasadhlp.dll
mscoree.dll
mlang.dll
cryptsp.dll
linkinfo.dll
UxTheme.dll
imageres.dll
shdocvw.dll
cscapi.dll
usp10.dll
wkscli.dll
devrtl.dll
secur32.dll
wintrust.dll
atl.dll
WINNSI.DLL
rsaenh.dll
riched20.dll
comres.dll
cryptui.dll
ntshrui.dll
slc.dll
oleaccrc.dll
PSAPI.DLL
propsys.dll
NETAPI32.dll
aclui.dll
dhcpcsvc6.dll
cryptbase.dll
ws2help.dll
SHELL32.dll
samlib.dll
KERNEL32.dll
VERSION.dll
dwmapi.dll
cabinet.dll
MPR.dll
WS2_32.dll
WindowsCodecs.dll
dnsapi.dll
SSPICLI.DLL
samcli.dll
apphelp.dll
dfscli.dll
dsrole.dll
ieframe.dll
lpk.dll
netutils.dll
clbcatq.dll
dhcpcsvc.dll
IPHLPAPI.DLL
srvcli.dll
DXGIDebug.dll
browcli.dll
SETUPAPI.dll
SHLWAPI.dll
OLEAUT32.dll
COMCTL32.dll
ole32.dll
USER32.dll
ADVAPI32.dll
gdiplus.dll
GDI32.dll
COMDLG32.dll

Strings analysis - Possible URLs found 1

http://schemas.microsoft.com/SMI/2005/WindowsSettings

Import functions

Name Latest seen MD5
updater.exe 2023-05-27 00:32:02 da9c79f7e1fb381ce030fbfc31d3af6a
7e8e3c8b54a3dd86e1b6afb3300169b0f41449d860921fef25d1038c26215f3f6f88efa1616203fc5b51 2023-06-04 15:41:03 c4b9d83a65b7a0b05d7d24d4abcb29ae
file.sfx.exe 2023-07-20 08:55:01 839d6cbb65ab2966767e4b6619f14874