testingProtected.exe

First submission 2024-10-15 16:33:06

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 1886.32 KB (1931592 bytes)
Compile time: 2024-10-15 06:55:23
MD5: acb5119773d5585f9155c28f97fa6eb0
SHA1: 453df01f3bd50f76dfee7e5191c2ce1551ba015d
SHA256: f2679c3b00a15806c12940d49178a7fc583788001ae5ecac61e1c3ff2a579ad8
Import Hash : e0e5cba487d80ef75c8cfd3e40cc6131
Sections 3 .text .data .rsrc
Directories 3 import resource security

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 30/77 VT report date: 2024-10-15 16:08:22
Malware Type 1 trojan
Threat Type 2 zusy hcmm

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://94.154.172.127/iobj/testingProtected.exe VirusTotal Report 94.154.172.127 VirusTotal Report 2024-10-15 16:33:06

PE Sections 0 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x1c1f8c 1843200 b443681a5a2b942e353d7d8a42bcf3391762900b 9d75daf17c86386b236909ece09662a4
.data 0x1c3000 0x3d24 4096 1ceaf73df40e531df3bfb26b4fb7cd95fb7bff1d 620f0b67a91f7f74151bc5be745b7110
.rsrc 0x1c7000 0x10b18 69632 1e7fc3e6aadc410aa8a3e7529f44f96aa9ece16b 6e5d0a61baadef50c392b9c7894b85e8

PE Resources 3

Name Language Sublanguage Offset Size Data
RT_ICON LANG_NEUTRAL SUBLANG_NEUTRAL 0x1c70e8 67624
RT_GROUP_ICON LANG_NEUTRAL SUBLANG_NEUTRAL 0x1d7910 20
RT_VERSION LANG_GERMAN SUBLANG_GERMAN 0x1d7924 500

Meta infos 6

InternalName: acvm7qw909e
ProductVersion: 1.00
Translation: 0x0407 0x04b0
ProductName: Eamre_Cerqea
OriginalFilename: acvm7qw909e.exe
FileVersion: 1.00

File signature

MD5 SHA1 Block size Virtual Address
88473e8ab6b07059d4d938ec04f33cdb 8e611ec69e63018c68491b4c0a1c58a1374d07bd 10568 1921024

Strings analysis - File found

Autogen
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Library
USER32.dll
MSVBVM60.DLL
VB5!6&VB6DE.DLL
KERNEL32.dll
VBA6.DLL

Strings analysis - Possible URLs found 12

http://crl.globalsign.com/root-r6.crl0G
http://ocsp.globalsign.com/codesigningrootr450F
https://www.globalsign.com/repository/0
http://ocsp.globalsign.com/gsgccr45evcodesignca20200U
http://crl.globalsign.com/gsgccr45evcodesignca2020.crl0
http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0?
http://ocsp2.globalsign.com/rootr606
http://crl.globalsign.com/codesigningrootr45.crl0U
http://ocsp.globalsign.com/ca/gstsacasha384g40C
http://secure.globalsign.com/cacert/codesigningrootr45.crt0A
http://crl.globalsign.com/ca/gstsacasha384g4.crl0
http://secure.globalsign.com/cacert/gstsacasha384g4.crt0

Import functions

Name Latest seen MD5
xwormProtected.exe 2024-10-15 16:32:06 7e2087055a8ab78c0025757274549257