Flex.dll?ex=670f643d&is=670e12bd&hm=5bf582024587d9ff5a4f1d3b879dc3a71af32abf218bc2d74f8b1b849f38a43b&
First submission 2024-10-15 20:31:02
File details
File type: | PE32+ executable (DLL) (GUI) x86-64, for MS Windows |
Mime type: | application/x-dosexec |
File size: | 483.5 KB (495104 bytes) |
Compile time: | 2024-04-12 23:17:46 |
MD5: | a4b4be6d4b29266af8e66aca3836fa4a |
SHA1: | 75c326f0c72721dfb2af4aa9756ff8ecb1158002 |
SHA256: | 4977ca8bb95e5104d62422242a975eb325288420379cf5b9e10d1e78645b3c5e |
Import Hash : | 8428cfcb4f57f8abe2f45132c19fd67d |
Sections 6 | .text .rdata .data .pdata .rsrc .reloc |
Directories 5 | import resource debug tls relocation |
File features detected
Anti VM
Signed
XOR
OSINT Enrichments
Virus Total: | 30/76 VT report date: 2024-10-15 15:22:20 |
Malware Type 1 | trojan |
Threat Type 1 | gamehack |
URLs, FQDN and IP indicators 1
PE Sections 0 suspicious
Name | VAddress | VSize | Size | SHA1 | MD5 | Suspicious |
---|---|---|---|---|---|---|
.text | 0x1000 | 0x609db | 395776 | bdd78ebb607d1c0e19b4b4f89d4afba5ae541ae4 | bfd78e9637161a4739be81d5cdf00d2e | |
.rdata | 0x62000 | 0x12af6 | 76800 | fdb48fe7c0f3ae9cb91181327ecdcc8378530735 | e0255e74a9268d8822ed04ca7ac8b756 | |
.data | 0x75000 | 0x13c0 | 2560 | 5edc427b59fb0e064809f74da8850d9d30644446 | e218af0f3794d2488dc5580598e4cc48 | |
.pdata | 0x77000 | 0x42b4 | 17408 | 2b9a1ce6d894b3998b986574d9c2ecab6a393e0a | aecf7f006ed7dca208b60791c1544ae3 | |
.rsrc | 0x7c000 | 0xf8 | 512 | 860dc11240532b464be020f0d55881adc4de0259 | 0deaaac3f0dc5653aa759e15c976e2c4 | |
.reloc | 0x7d000 | 0x2a8 | 1024 | 109efb55ff8ab5254f6cf95883e2b35fcfa7b544 | 09146ad7795e97ac8a0231b1340e6e08 |
PE Resources 1
Name | Language | Sublanguage | Offset | Size | Data |
---|---|---|---|---|---|
RT_MANIFEST | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x7c060 | 145 |
Anti debug functions 8
FindWindowA |
FindWindowW |
GetLastError |
GetWindowThreadProcessId |
IsDebuggerPresent |
IsProcessorFeaturePresent |
TerminateProcess |
UnhandledExceptionFilter |
Strings analysis - File found
Text |
imgui_log.txt |
Library |
xinput1_1.dll |
KERNEL32.dll |
Shcore.dll |
api-ms-win-crt-heap-l1-1-0.dll |
msvcp140.dll |
xinput1_3.dll |
xinput1_4.dll |
ntdll.dll |
api-ms-win-crt-stdio-l1-1-0.dll |
WS2_32.dll |
api-ms-win-crt-utility-l1-1-0.dll |
xinput1_2.dll |
dbghelp.dll |
USER32.dll |
jvm.dll |
vcruntime140.dll |
api-ms-win-crt-filesystem-l1-1-0.dll |
xinput9_1_0.dll |
OPENGL32.dll |
IMM32.dll |
api-ms-win-crt-string-l1-1-0.dll |
api-ms-win-crt-runtime-l1-1-0.dll |
api-ms-win-crt-convert-l1-1-0.dll |
VCRUNTIME140_1.dll |
api-ms-win-crt-math-l1-1-0.dll |
GDI32.dll |
KernelBase.dll |
Import functions
dbghelp.dll 1
api-ms-win-crt-convert-l1-1-0.dll 1
api-ms-win-crt-filesystem-l1-1-0.dll 2
OPENGL32.dll 10
MSVCP140.dll 50
GDI32.dll 1
api-ms-win-crt-string-l1-1-0.dll 3
jvm.dll 1
api-ms-win-crt-runtime-l1-1-0.dll 14
KERNEL32.dll 60
api-ms-win-crt-math-l1-1-0.dll 10
VCRUNTIME140_1.dll 1
api-ms-win-crt-utility-l1-1-0.dll 1
VCRUNTIME140.dll 14
api-ms-win-crt-stdio-l1-1-0.dll 19
WS2_32.dll 4
api-ms-win-crt-heap-l1-1-0.dll 3
USER32.dll 53
IMM32.dll 4