clean.exe

First submission 2024-10-16 22:48:02

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 896.0 KB (917504 bytes)
Compile time: 2024-10-14 20:42:46
MD5: acafa6fa58da4d3ec756a5cdac02e996
SHA1: d504add90c19296f86d58ab7a77f3c64c0137dad
SHA256: 3e1596483acaba69fa5630819e85b60fa282f4eb6daab25605716d44396bd6cf
Import Hash : 948cc502fe9226992dce9417f952fce3
Sections 5 .text .rdata .data .rsrc .reloc
Directories 5 import resource debug tls relocation

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://185.215.113.103/test/clean.exe VirusTotal Report 185.215.113.103 VirusTotal Report 2024-10-16 22:48:02

PE Sections 1 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x9ab1d 633856 25c1457c129ee77c0aaf98beb58f3526677687d4 0a1473f3064dcbc32ef93c5c8a90f3a6
.rdata 0x9c000 0x2fb82 195584 dd2c684a16b3f370a7c66588627005befd670b80 c9cf2468b60bf4f80f136ed54b3989fb
.data 0xcc000 0x706c 18432 b958d08b90b56aff3f2e0d6daf36b91c8f31ca4c 53b9025d545d65e23295e30afdbd16d9
.rsrc 0xd4000 0x9470 38400 f57a95c136ad2b524927b67481d6c8da97a1ef8e 6fda7610df198ae65d981b3d81f79817
.reloc 0xde000 0x7594 30208 359f6b9001cbad77104e5ed741f6d8024a1e6ffd c68ee8931a32d45eb82dc450ee40efc3

PE Resources 7

Name Language Sublanguage Offset Size Data
RT_ICON LANG_ENGLISH SUBLANG_ENGLISH_UK 0xda038 1128
RT_MENU LANG_ENGLISH SUBLANG_ENGLISH_UK 0xda4a0 80
RT_STRING LANG_ENGLISH SUBLANG_ENGLISH_UK 0xdc660 344
RT_RCDATA LANG_NEUTRAL SUBLANG_NEUTRAL 0xdc7b8 1848
RT_GROUP_ICON LANG_ENGLISH SUBLANG_ENGLISH_UK 0xdcf90 20
RT_VERSION LANG_ENGLISH SUBLANG_ENGLISH_UK 0xdcfa4 220
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_UK 0xdd080 1007

Meta infos 1

Translation: 0x0809 0x04b0

Packers detected 2

Microsoft Visual C++ 8
VC8 -> Microsoft Corporation

Anti debug functions 12

FindWindowExW
FindWindowW
GetLastError
GetWindowThreadProcessId
IsDebuggerPresent
IsProcessorFeaturePresent
OutputDebugStringW
Process32FirstW
Process32NextW
RaiseException
TerminateProcess
UnhandledExceptionFilter

Anti debug functions 1

VMCheck.dll

Strings analysis - File found

Library
KERNEL32.dll
api-ms-win-core-synch-l1-2-0.dll
mscoree.dll
UxTheme.dll
SHELL32.dll
WININET.dll
OLEAUT32.dll
USER32.dll
VERSION.dll
PSAPI.DLL
USERENV.dll
ADVAPI32.dll
COMCTL32.dll
COMDLG32.dll
ole32.dll
MPR.dll
WINMM.dll
IPHLPAPI.DLL
GDI32.dll
WSOCK32.dll

Strings analysis - Possible IPs found 1

255.255.255.255

Import functions

Name Latest seen MD5
go.exe 2024-05-25 13:47:02 8fd5d84bd93a95a1ff016b2cfb921405
well.exe 2024-05-30 13:35:02 dd9a4a97f676e1a67fbb26876cd1679b
go.exe 2024-05-30 14:12:02 2e1caaf0a1fb87d6d3ff1780cfe68bca
go.exe 2024-05-30 16:46:02 a2ea30062de6998cf64ff7590eb51b5a
well.exe 2024-05-30 16:58:02 8d2fcc23ecc609ef46b191353bb8da4c
anon.exe 2024-06-01 03:18:01 16faec5f9aeecaaa1ee5dd1911236618
random.exe 2024-06-04 22:56:02 1dc1aeb9d05e1693877fe7a78839bde5
dude.exe 2024-06-07 07:48:01 aaf735aafa732fc96d2091354795185a
random.exe 2024-06-14 16:27:07 eeca7475e0c5e8d6935c229b7c0d83d2
go.exe 2024-06-28 21:45:01 bfe4e166869e2c50d669054444f00f39
random.exe 2024-07-26 01:54:02 2671133e91863dbf94703fa872313a68
industries.exe 2024-07-26 03:00:02 b77405e92a8557ab11d1d6ed25d6b390
fodhelper.exe 2024-08-26 15:11:03 fcb34a54159d0de7cb5fa2fae1c82e72
csrss.exe 2024-08-27 08:14:03 a1c95767e2aae895bca002778203b26e
MeMpEng.exe 2024-08-29 09:53:01 27cd8bf989a43004d8dea02d83aa760e
MeMpEng.exe 2024-08-30 10:19:03 2de33a20655435a626ae19973654e95c
wels.exe 2024-09-21 10:41:02 0568c4bcf6acda54e2251b1e35929608
random.exe 2024-09-20 17:01:02 adbcf5048cb3fe3f89f45085751875b0
random.exe 2024-09-21 02:10:02 d23aac5d0b47654754a6e6d79085c871
well_clean.exe 2024-10-16 22:10:02 18e64b3509e95557b6614610df2fcf20
login.exe 2024-10-16 22:47:02 0538d8a54c0f7b2af395ff7322714d0b