FreeTP.OrgThe-Binding-of-Isaac-Multiplayer-Fix-Online.exe?ex=670fd363&is=670e81e3&hm=db0185353bc5a0bc751f5467bbf50786628aba6a22cd560af3e954b28b429e9a&

First submission 2024-10-15 20:04:02

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 1212.23 KB (1241325 bytes)
Compile time: 2012-07-26 15:09:48
MD5: aa849dc239432feeff294d67f8d10432
SHA1: 86f26ba31a0e8da553750a2cf9a48802462620d8
SHA256: 45e01833e752a67751d60f2dffeb817fae98b5de21e2ba773435bb0532556514
Import Hash : 483f0c4259a9148c34961abbda6146c1
Sections 8 .text .itext .data .bss .idata .tls .rdata .rsrc
Directories 3 import resource tls

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXps://cdn.discordapp.com/attachments/1247136923126988801/1295761446847910009/FreeTP.OrgThe-Binding-of-Isaac-Multiplayer-Fix-Online.exe?ex=670fd363&is=670e81e3&hm=db0185353bc5a0bc751f5467bbf50786628aba6a22cd560af3e954b28b429e9a& VirusTotal Report cdn.discordapp.com VirusTotal Report 2024-10-15 20:04:02

PE Sections 3 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x143f8 82944 0816ead74f84da89b3a6af4ee4e67e409c055459 345db2b6911addc85b53f32245f969a0
.itext 0x16000 0xbe8 3072 5fcb2b9b02cf13f4fbf445a1b98ef88f074dbf68 2e74d968caedeb2d71b9505530d43907
.data 0x17000 0xd9c 3584 6f2aff1b87c311ecfcd609b3b4588e75af4484d2 d5b22eff9e08edaa95f493c1a71158c0
.bss 0x18000 0x5750 0 da39a3ee5e6b4b0d3255bfef95601890afd80709 d41d8cd98f00b204e9800998ecf8427e
.idata 0x1e000 0xf9e 4096 56a0ec8ac42ef35b0ee132508701868d83befc42 b47eaca4c149ee829de76a342b5560d5
.tls 0x1f000 0x8 0 da39a3ee5e6b4b0d3255bfef95601890afd80709 d41d8cd98f00b204e9800998ecf8427e
.rdata 0x20000 0x18 512 65e8dad930c8c32d40ca9aff4890630f20d87074 3746f5876803f8f30db5bb2deb8772ae
.rsrc 0x21000 0x17370 95232 98f4f455eb262497f578ffce62c1a2bab84aa37f 9d1bd0ea779224fb6c4ca05733743583

PE Resources 6

Name Language Sublanguage Offset Size Data
RT_ICON LANG_ENGLISH SUBLANG_ENGLISH_US 0x2138c 54372
RT_STRING LANG_NEUTRAL SUBLANG_NEUTRAL 0x2f1dc 660
RT_RCDATA LANG_NEUTRAL SUBLANG_NEUTRAL 0x37918 44
RT_GROUP_ICON LANG_ENGLISH SUBLANG_ENGLISH_US 0x37944 20
RT_VERSION LANG_ENGLISH SUBLANG_ENGLISH_US 0x37958 1208
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x37e10 1376

Meta infos 8

LegalCopyright:
FileVersion:
CompanyName: FreeTP.Org - The Binding of Isaac Multiplayer Fix
ProductVersion: 1-1
FileDescription: The Binding of Isaac
Translation: 0x0000 0x04b0
Comments: This installation was built with Inno Setup.
ProductName: The Binding of Isaac

Packers detected 2

Borland Delphi 3.0 (???)
Borland Delphi 4.0

Anti debug functions 3

GetLastError
RaiseException
UnhandledExceptionFilter

Strings analysis - File found

Library
KERNEL32.dll
OLEAUT32.dll
SHELL32.dll
USER32.dll
COMCTL32.dll
ADVAPI32.dll

Strings analysis - Possible URLs found 1

http://schemas.microsoft.com/SMI/2005/WindowsSettings

Import functions

Name Latest seen MD5
zov.txt 2023-04-20 09:11:18 c48a400ccdb846dfeecdb8564ed29e6a