real.exe

First submission 2024-10-14 08:06:09

File details

File type: PE32+ executable (GUI) x86-64, for MS Windows
Mime type: application/x-dosexec
File size: 22978.29 KB (23529772 bytes)
Compile time: 2024-10-10 16:55:46
MD5: 7f598dc2ae60de57f8002472e608b5f9
SHA1: 24a84cb59503d1f336dfd5cb1453abe804e4c140
SHA256: 3dbc1915ce8e63922df52bd00f8845a1bfb3ec4f14495e784dacfc84edb28bf2
Import Hash : a9827d13e19b1fcf3bfb108f25cfeebe
Sections 21 .text .data .rdata /4 .pdata .xdata .bss .idata .CRT .tls .rsrc .reloc /14 /29 /41 /55 /67 /80 /91 /107 /123
Directories 4 import resource tls relocation

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://107.175.73.38/real.exe VirusTotal Report 107.175.73.38 VirusTotal Report 2024-10-14 08:06:09

PE Sections 3 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x1b28 7168 085d40c02d537d6739f5d773039e8d48f903ee8a acb7d4357e2f8ad094ad8cfe1e072569
.data 0x3000 0xa0 512 29040dbf11f1269bf1c63305f11af9cb54a3642b 4ac64bb02ed88c4f71c0b41e381921a1
.rdata 0x4000 0x8e0 2560 8b2fd8ef0775a85d48acbc6ed6d799214dd75ea9 7e7fad0127e636d9c1800602d1a35a58
/4 0x5000 0x4 512 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 bf619eac0cdf3f68d496ea9344137e8b
.pdata 0x6000 0x270 1024 d49df5427624c165ae2391e96dff314c3c8141ee d3f0b2fa0b88a8e72692497c37a23457
.xdata 0x7000 0x1ec 512 b5276ed35c086011902e7f8c72fca645b1765814 5553ab462ae9492afe38a5d59a9d8913
.bss 0x8000 0x1e0 0 da39a3ee5e6b4b0d3255bfef95601890afd80709 d41d8cd98f00b204e9800998ecf8427e
.idata 0x9000 0x84c 2560 ea9cff792e3edd6371cc268cf64aecdc32a7f994 b7cfe1ecc3a6bc07041505aafd04babe
.CRT 0xa000 0x60 512 4642793b0504a681cb667d6963424568f6f98c37 213e244059a45f865ad95bf854a902d9
.tls 0xb000 0x10 512 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 bf619eac0cdf3f68d496ea9344137e8b
.rsrc 0xc000 0x16501a8 23396864 2154a29f9200756b4594502d6e35d00d2bbc9420 ef513ff0fee5d1629d5cfb900ba91410
.reloc 0x165d000 0x78 512 241f0f39d513080eed626acf5cf7584cd4c9ecc5 c7cd7b709240feeb83740ba65a86cca7
/14 0x165e000 0x460 1536 63a233b0f0cad616f6e3352b5c6f4b3e0287f403 d3edb6e2273457f3dc4f49f207db53c4
/29 0x165f000 0xaae9 44032 ace9edaaf3a69b10264c01937d8b3d16339dbb44 9e45ee215a1c39b42557ddb9aca1f443
/41 0x166a000 0x1cb8 7680 0bf7cf6312c5764c8b5b6ac52a0668ec760697ff 089bd22e9162cbfa4761dd2e0e909a38
/55 0x166c000 0x1b32 7168 9c19602655c6ab49cfc4e4f9badaf0df20270216 2d3d87a1d677a08875d79ca659befe61
/67 0x166e000 0xad0 3072 5c9c76ee818c4fde16c8105cd702aa1cde1365e9 564f61c3414b6b035e1a857e6c6a8ed1
/80 0x166f000 0x354 1024 a40def3e59e56c244b7f1ee9e4d2758cc286e7db a5657ca8b7b4d6587b37b69dca0759a0
/91 0x1670000 0x205b 8704 6a74e6e58cbb49e6a89961f7071d5710271c5c31 9bbe9dd66e6ef5ad08d3fe0304d7e852
/107 0x1673000 0x120d 5120 6adbfb9c98fc58017e73c6ae09ebbbfef3e18b02 b766092a75cab20f3c0bd4b595f53148
/123 0x1675000 0x195 512 a2a125cb7390661b9af98659661b28127255ba37 0a478305b637270896b63c2f3a8d9a48

PE Resources 2

Name Language Sublanguage Offset Size Data
WAVE LANG_ENGLISH SUBLANG_ENGLISH_US 0xc0d8 15102030
RT_BITMAP LANG_ENGLISH SUBLANG_ENGLISH_US 0xe73128 8294524

Packers detected 1

Microsoft Visual C++ 8.0 (DLL)

Anti debug functions 1

GetLastError

Strings analysis - File found

Library
USER32.dll
KERNEL32.dll
libgcc_s_dw2-1.dll
MSVCRT.dll
WINMM.dll
GDI32.dll

Import functions

Name Latest seen MD5
lock2.exe 2024-10-14 08:39:12 3812c2d4d4dfa94c499267326af9f1eb