1.3_hotfix.zip?ex=670eb34e&is=670d61ce&hm=c8ddcada9740eee4868a9caee8ddf2b14af906b4b8dfa86f1e5d5fa303b0b1c0&

First submission 2024-10-15 20:05:02

File details

File type: Zip archive data, at least v1.0 to extract
Mime type: application/zip
File size: 2541.02 KB (2602004 bytes)
MD5: d67688d07e3868e21c4c0978b4d09de8
SHA1: f6b9c2445750b4cc8b84ee211a59d8ec26c65b05
SHA256: 1a03770b1f49b9236449f9c488af4bca22c5494a506ae646076c99109da5bec5

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 28/77 VT report date: 2024-10-14 20:52:38
Malware Type 1 trojan
Threat Type 1 radrat

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXps://cdn.discordapp.com/attachments/1248194366070194237/1295452123349385306/1.3_hotfix.zip?ex=670eb34e&is=670d61ce&hm=c8ddcada9740eee4868a9caee8ddf2b14af906b4b8dfa86f1e5d5fa303b0b1c0& VirusTotal Report cdn.discordapp.com VirusTotal Report 2024-10-15 20:05:02

Strings analysis - File found

Text
1.3_hotfix/Wuthering Waves Game/Client/Binaries/Win64/libraries.txt
1.3_hotfix/README FIRST.txt
Library
1.3_hotfix/Wuthering Waves Game/Client/Binaries/Win64/winhttp.dll
1.3_hotfix/Wuthering Waves Game/Client/Binaries/Win64/shorekeeper.dll