mso-install.exe

First submission 2024-10-16 23:54:08

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
Mime type: application/x-dosexec
File size: 842.44 KB (862656 bytes)
Compile time: 2024-10-14 11:52:53
MD5: d16b9f62e697777a3b63f53c95a8c65c
SHA1: 712a2675c89888f78cfb2db0897c140753bf9d01
SHA256: f47857662ee05b4e6f3063940f737f87c116faaa25cf8ea9e7e0d6fb3d4ef166
Import Hash : fc6683d30d9f25244a50fd5357825e79
Sections 3 UPX0 UPX1 .rsrc
Directories 4 import resource relocation security

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 13/77 VT report date: 2024-10-16 23:30:27
Malware Type 1 trojan
Threat Type 1 povertel

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://se.maina-vira.ru:8080/distr/apps/mso-install.exe VirusTotal Report se.maina-vira.ru VirusTotal Report 2024-10-16 23:54:08

PE Sections 3 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
UPX0 0x1000 0xfd000 0 da39a3ee5e6b4b0d3255bfef95601890afd80709 d41d8cd98f00b204e9800998ecf8427e
UPX1 0xfe000 0x57000 353280 eae7a462d1ff24994af202fbff2c54a64f5445b0 4727224ea8c6d9c1e06777f419fe7cf3
.rsrc 0x155000 0x7c000 507392 62ac23fc7e76b7665d765971c8a0f1598ba141e9 655cf2eaba179d335a300faab96d1fb9

PE Resources 8

Name Language Sublanguage Offset Size Data
RT_ICON LANG_ENGLISH SUBLANG_ENGLISH_UK 0x16c8bc 4264
RT_MENU LANG_ENGLISH SUBLANG_ENGLISH_UK 0xe0948 80
RT_DIALOG LANG_ENGLISH SUBLANG_ENGLISH_UK 0xe0998 252
RT_STRING LANG_ENGLISH SUBLANG_ENGLISH_UK 0xe2c04 344
RT_RCDATA LANG_NEUTRAL SUBLANG_NEUTRAL 0x16d968 403719
RT_GROUP_ICON LANG_ENGLISH SUBLANG_ENGLISH_UK 0x1d02e8 20
RT_VERSION LANG_ENGLISH SUBLANG_ENGLISH_UK 0x1d0300 668
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_UK 0x1d05a0 1018

Meta infos 8

LegalCopyright: \xa9 Acme Inc
FileVersion: 1.0.0.0
CompanyName: Acme Inc.
ProductVersion: 1.0.0.0
FileDescription: A short description of the program
Translation: 0x0809 0x04b0
Comments: Program made by Acme Inc.
ProductName: MyProg

Packers detected 1

UPX -> www.upx.sourceforge.net

File signature

MD5 SHA1 Block size Virtual Address
71551d85d9285948cf70d8e5af53165b f78fe5caa7bb0c83431f02cc56a3974ba722a811 960 861696

Strings analysis - File found

Library
ADVAPI32.dll
OLEAUT32.dll
UxTheme.dll
WSOCK32.dll
SHELL32.dll
VERSION.dll
PSAPI.DLL
COMCTL32.dll
IPHLPAPI.DLL
ole32.dll
WININET.dll
USER32.dll
USERENV.dll
GDI32.dll
WINMM.dll
KERNEL32.dll
COMDLG32.dll
MPR.dll

Import functions

Name Latest seen MD5
AAQ.exe 2024-06-01 06:55:04 6c495bef7c3b6622ff56e49822dc6796
ExtExport2.exe 2024-06-24 18:26:02 901a623dbccaa22525373cd36195ee14