20230120_3.bin

First submission 2024-10-17 17:55:04

File details

File type: PE32+ executable (native) x86-64, for MS Windows
Mime type: application/x-dosexec
File size: 148.27 KB (151824 bytes)
Compile time: 2023-01-20 15:21:06
MD5: 919caff04831cd3ccd0e2053769cfd9d
SHA1: 9b15f19a2b028724144404a71829772445c59d22
SHA256: 64df21caada72b25868c916b897d5188935337edb476cf1c850317ac7aa28d1e
Import Hash : 118a2343ba7a5763d9034e65dcc58b46
Sections 7 .text .rdata .data .pdata INIT .reloc
Directories 3 import relocation security

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://124.248.65.242:8899/sys/20230120_3.bin VirusTotal Report 124.248.65.242 VirusTotal Report 2024-10-17 17:55:04

PE Sections 3 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x1c46 7680 85f97df56955cbc5168e3cbf70b625c835df6f4f 29c14e5a94f817e41a889a9d14bc67a6
.rdata 0x3000 0x63c 2048 f5669dd430e1861e0cc69cb871c4809eb96158e1 83ab56e7cd477e14ae1ea4e2df86ede3
.data 0x4000 0x1be30 114688 3a774e26d13861fb095e27d008659cc0e6f1945e 83b0cb3c380086bd5049046dfe036ab0
.pdata 0x20000 0x198 512 7055b154f6924777ac4f39c99fea67a33d05cc24 150aad2bbe68275ee35b3e24cdbdbb23
INIT 0x21000 0x432 1536 f996478714ae1dbdf99daf9998f786dfaa59d7ce d7406036dd7ca4d76ef2bddc3ba589a3
0x22000 0x3340 13312 7f69da48a5d625068951f0c06f5bef8010684726 128bfe3c607755eb6cf99ed4f1eb2cd1
.reloc 0x26000 0x14 512 c0484f20718fe1e57bcded0867bcb9a8dee3ca49 cfae0cacdcb3dbfdeeeb0ed3040da6c2

Anti debug functions 1

ZwQueryInformationFile

Anti debug functions 1

Virtual Box

File signature

MD5 SHA1 Block size Virtual Address
d1279f3143fb66651588d9f6b5deda89 a4875f0d782bbd9484a9234b4499b7cf1c3f8310 10512 141312

Strings analysis - File found

Binary
\SystemRoot\System32\GSDrv.bin
Library
\SystemRoot\System32\ntdll.dll

Strings analysis - Possible URLs found 8

http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0
http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
http://ocsp.comodoca.com0
https://sectigo.com/CPS0
http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y
http://crl.comodoca.com/AAACertificateServices.crl04
http://ocsp.sectigo.com0
http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#

Import functions

Name Latest seen MD5
20230120_1.bin 2024-10-17 17:52:05 2f3fd904ea51687468b39b707a1587a4
20230120_2.bin 2024-10-17 17:53:05 df090fc9db83229c47d072fca9b3da6b
20230120_4.bin 2024-10-17 17:54:07 b887f1eaec80d94a7b4a89f8521f857f