stories.exe

First submission 2024-10-14 22:12:03

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 4083.16 KB (4181152 bytes)
Compile time: 1992-06-20 00:22:17
MD5: b00c9bc606824dc90058f5ce00313ff6
SHA1: a59ca316a7299dce0b100f728223f27ef55116cc
SHA256: 90998a60d134ec92e788f0c2c79fe00cf27dd440a794d683bc01656db76e145a
Import Hash : 80417b621299e3e1de617305557a3c68
Sections 8 CODE DATA BSS .idata .tls .rdata .reloc .rsrc
Directories 3 import resource tls

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 19/77 VT report date: 2024-10-14 12:25:35
Malware Type 1 trojan
Threat Type 1 munp

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://46.8.229.59/thebig/stories.exe VirusTotal Report 46.8.229.59 VirusTotal Report 2024-10-14 22:12:03

PE Sections 4 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
CODE 0x1000 0x8f14 36864 4f5b247972a78bd5a57be3e743ef1e17a3a05ab0 19aec1c1a4ef2fb9fe30b219ab07ddb2
DATA 0xa000 0x248 1024 f910df09aeda22168281b3c43481dfacba38b824 6344b5e22b5b2675be150744885e2671
BSS 0xb000 0xe34 0 da39a3ee5e6b4b0d3255bfef95601890afd80709 d41d8cd98f00b204e9800998ecf8427e
.idata 0xc000 0x942 2560 e5bbfd028c58ac5bdb96dbb382d9a9202288a6c7 563cb4ae07a81b0403d850851e368293
.tls 0xd000 0x8 0 da39a3ee5e6b4b0d3255bfef95601890afd80709 d41d8cd98f00b204e9800998ecf8427e
.rdata 0xe000 0x18 512 217e47adc0fbd0a02677f10d9af22bb5dc7739cf d293bf8d4ebe9826d58e1d27c25fe4b6
.reloc 0xf000 0x880 0 da39a3ee5e6b4b0d3255bfef95601890afd80709 d41d8cd98f00b204e9800998ecf8427e
.rsrc 0x10000 0x3000 10240 be3ea1d33fe2bb9cec4e4a7fd44677129515edec 1440b0e9c043cee853bb698c13d1e2bf

PE Resources 6

Name Language Sublanguage Offset Size Data
RT_ICON LANG_DUTCH SUBLANG_DUTCH 0x10ccc 2216
RT_STRING LANG_NEUTRAL SUBLANG_NEUTRAL 0x11f60 174
RT_RCDATA LANG_NEUTRAL SUBLANG_NEUTRAL 0x12010 44
RT_GROUP_ICON LANG_ENGLISH SUBLANG_ENGLISH_US 0x1203c 62
RT_VERSION LANG_ENGLISH SUBLANG_ENGLISH_US 0x1207c 1020
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x12478 887

Meta infos 6

LegalCopyright:
FileVersion:
CompanyName:
Translation: 0x0409 0x04e4
FileDescription: Glass Video Converter Setup
Comments: This installation was built with Inno Setup: http://www.innosetup.com

Packers detected 4

Borland Delphi 3.0 (???)
Borland Delphi 4.0
Inno Installer v5.1.2] ;collides with: Borland Delphi 2.0 [Overlay
Inno Setup Module v5

Anti debug functions 2

GetLastError
RaiseException

Strings analysis - File found

Library
OLEAUT32.dll
USER32.dll
COMCTL32.dll
ADVAPI32.dll
KERNEL32.dll
SHELL32.dll

Strings analysis - Possible URLs found 1

http://www.innosetup.com

Import functions

Name Latest seen MD5
stail.exe 2024-10-08 22:56:03 bb3c2f437debeebefdc3fe010643b86f
getlab.exe 2024-10-10 01:15:02 22b5039fd243d842d12ac0cde7cc2beb
stail.exe 2024-10-14 22:11:02 c098830ac7a7e0ea481dba5c2d7e4f92