stail.exe
First submission 2024-10-14 22:08:03
Last sumbission 2024-10-14 22:11:02
File details
File type: | PE32 executable (GUI) Intel 80386, for MS Windows |
Mime type: | application/x-dosexec |
File size: | 4052.99 KB (4150258 bytes) |
Compile time: | 1992-06-20 00:22:17 |
MD5: | c098830ac7a7e0ea481dba5c2d7e4f92 |
SHA1: | 8503f89c175563f4d931c760b2a7f6197247d1f8 |
SHA256: | b41a9ce2a1df8b96a0f1cbd95a54f55e6820867141df087c50e4d745e8b8f051 |
Import Hash : | 80417b621299e3e1de617305557a3c68 |
Sections 8 | CODE DATA BSS .idata .tls .rdata .reloc .rsrc |
Directories 3 | import resource tls |
File features detected
Anti VM
Signed
XOR
OSINT Enrichments
Virus Total: | 19/77 VT report date: 2024-10-14 11:25:20 |
Malware Type 1 | trojan |
Threat Type 1 | munp |
URLs, FQDN and IP indicators 2
PE Sections 4 suspicious
Name | VAddress | VSize | Size | SHA1 | MD5 | Suspicious |
---|---|---|---|---|---|---|
CODE | 0x1000 | 0x8f14 | 36864 | 4f5b247972a78bd5a57be3e743ef1e17a3a05ab0 | 19aec1c1a4ef2fb9fe30b219ab07ddb2 | |
DATA | 0xa000 | 0x248 | 1024 | f910df09aeda22168281b3c43481dfacba38b824 | 6344b5e22b5b2675be150744885e2671 | |
BSS | 0xb000 | 0xe34 | 0 | da39a3ee5e6b4b0d3255bfef95601890afd80709 | d41d8cd98f00b204e9800998ecf8427e | |
.idata | 0xc000 | 0x942 | 2560 | e5bbfd028c58ac5bdb96dbb382d9a9202288a6c7 | 563cb4ae07a81b0403d850851e368293 | |
.tls | 0xd000 | 0x8 | 0 | da39a3ee5e6b4b0d3255bfef95601890afd80709 | d41d8cd98f00b204e9800998ecf8427e | |
.rdata | 0xe000 | 0x18 | 512 | 217e47adc0fbd0a02677f10d9af22bb5dc7739cf | d293bf8d4ebe9826d58e1d27c25fe4b6 | |
.reloc | 0xf000 | 0x880 | 0 | da39a3ee5e6b4b0d3255bfef95601890afd80709 | d41d8cd98f00b204e9800998ecf8427e | |
.rsrc | 0x10000 | 0x3000 | 10240 | cd77c947a05f1e596b0a07f06a8d3fadb55a6d90 | 4d9b9a70a3cc86d5519de5d2ce781741 |
PE Resources 6
Name | Language | Sublanguage | Offset | Size | Data |
---|---|---|---|---|---|
RT_ICON | LANG_DUTCH | SUBLANG_DUTCH | 0x10ccc | 2216 | |
RT_STRING | LANG_NEUTRAL | SUBLANG_NEUTRAL | 0x11f60 | 174 | |
RT_RCDATA | LANG_NEUTRAL | SUBLANG_NEUTRAL | 0x12010 | 44 | |
RT_GROUP_ICON | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x1203c | 62 | |
RT_VERSION | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x1207c | 1020 | |
RT_MANIFEST | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x12478 | 887 |
Meta infos 6
LegalCopyright: | |
FileVersion: | |
CompanyName: | |
Translation: | 0x0409 0x04e4 |
FileDescription: | Glass Video Converter Setup |
Comments: | This installation was built with Inno Setup: http://www.innosetup.com |
Packers detected 4
Borland Delphi 3.0 (???) |
Borland Delphi 4.0 |
Inno Installer v5.1.2] ;collides with: Borland Delphi 2.0 [Overlay |
Inno Setup Module v5 |
Anti debug functions 2
GetLastError |
RaiseException |
Strings analysis - File found
Library |
OLEAUT32.dll |
USER32.dll |
COMCTL32.dll |
ADVAPI32.dll |
KERNEL32.dll |
SHELL32.dll |
Strings analysis - Possible URLs found 1
http://www.innosetup.com |
Import functions
Name | Latest seen | MD5 |
---|---|---|
stail.exe | 2024-10-08 22:56:03 | bb3c2f437debeebefdc3fe010643b86f |
getlab.exe | 2024-10-10 01:15:02 | 22b5039fd243d842d12ac0cde7cc2beb |
stories.exe | 2024-10-14 22:12:03 | b00c9bc606824dc90058f5ce00313ff6 |