Flex.dll?ex=670f643d&is=670e12bd&hm=5bf582024587d9ff5a4f1d3b879dc3a71af32abf218bc2d74f8b1b849f38a43b&

First submission 2024-10-15 20:31:02

File details

File type: PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Mime type: application/x-dosexec
File size: 483.5 KB (495104 bytes)
Compile time: 2024-04-12 23:17:46
MD5: a4b4be6d4b29266af8e66aca3836fa4a
SHA1: 75c326f0c72721dfb2af4aa9756ff8ecb1158002
SHA256: 4977ca8bb95e5104d62422242a975eb325288420379cf5b9e10d1e78645b3c5e
Import Hash : 8428cfcb4f57f8abe2f45132c19fd67d
Sections 6 .text .rdata .data .pdata .rsrc .reloc
Directories 5 import resource debug tls relocation

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 30/76 VT report date: 2024-10-15 15:22:20
Malware Type 1 trojan
Threat Type 1 gamehack

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXps://cdn.discordapp.com/attachments/1295642004386091039/1295642102079688714/Flex.dll?ex=670f643d&is=670e12bd&hm=5bf582024587d9ff5a4f1d3b879dc3a71af32abf218bc2d74f8b1b849f38a43b& VirusTotal Report cdn.discordapp.com VirusTotal Report 2024-10-15 20:31:02

PE Sections 0 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x609db 395776 bdd78ebb607d1c0e19b4b4f89d4afba5ae541ae4 bfd78e9637161a4739be81d5cdf00d2e
.rdata 0x62000 0x12af6 76800 fdb48fe7c0f3ae9cb91181327ecdcc8378530735 e0255e74a9268d8822ed04ca7ac8b756
.data 0x75000 0x13c0 2560 5edc427b59fb0e064809f74da8850d9d30644446 e218af0f3794d2488dc5580598e4cc48
.pdata 0x77000 0x42b4 17408 2b9a1ce6d894b3998b986574d9c2ecab6a393e0a aecf7f006ed7dca208b60791c1544ae3
.rsrc 0x7c000 0xf8 512 860dc11240532b464be020f0d55881adc4de0259 0deaaac3f0dc5653aa759e15c976e2c4
.reloc 0x7d000 0x2a8 1024 109efb55ff8ab5254f6cf95883e2b35fcfa7b544 09146ad7795e97ac8a0231b1340e6e08

PE Resources 1

Name Language Sublanguage Offset Size Data
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x7c060 145

Anti debug functions 8

FindWindowA
FindWindowW
GetLastError
GetWindowThreadProcessId
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
UnhandledExceptionFilter

Strings analysis - File found

Text
imgui_log.txt
Library
xinput1_1.dll
KERNEL32.dll
Shcore.dll
api-ms-win-crt-heap-l1-1-0.dll
msvcp140.dll
xinput1_3.dll
xinput1_4.dll
ntdll.dll
api-ms-win-crt-stdio-l1-1-0.dll
WS2_32.dll
api-ms-win-crt-utility-l1-1-0.dll
xinput1_2.dll
dbghelp.dll
USER32.dll
jvm.dll
vcruntime140.dll
api-ms-win-crt-filesystem-l1-1-0.dll
xinput9_1_0.dll
OPENGL32.dll
IMM32.dll
api-ms-win-crt-string-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-convert-l1-1-0.dll
VCRUNTIME140_1.dll
api-ms-win-crt-math-l1-1-0.dll
GDI32.dll
KernelBase.dll

Import functions