CB.exe

First submission 2023-09-13 11:12:02

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 172.5 KB (176640 bytes)
Compile time: 2012-07-14 00:47:16
MD5: f89a7590147ed0c19e142705acf490af
SHA1: 3bbc2a96efdf56282e770f6b3d9bf9f26213950d
SHA256: 784cda9f8d5a1f70a189644e78f76d69c5b41434ac8ee66f77dff5141f0c4fb2
Import Hash : bf5a4aa99e5b160f8521cadd6bfe73b8
Sections 4 .text .rdata .data .rsrc
Directories 3 import resource debug
Virus Total: 28/71 VT report date: 2023-09-13 09:00:58

File features detected

Is DLL

Packers

Anti Debug

Anti VM

Signed

XOR

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://194.180.49.211/D/CB.exe VirusTotal Report 194.180.49.211 VirusTotal Report 2023-09-13 11:12:03

PE Sections 1 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x19718 104448 34dd3bb40ea1e91ce1596461f7d8502bd3d0e45c b2d4ac063f2fab284d2949e64a5bc359
.rdata 0x1b000 0x6db4 28160 ac050a1809ae127615e1683adb73d87013096d10 5826801f33fc1b607aa8e942aa92e9fa
.data 0x22000 0x30c0 5632 c5c9b70d1fbe0cb0f1d48ea41ef1cd0da70d708d 2fe51a72ede820cd7cf55a77ba59b1f4
.rsrc 0x26000 0x9064 37376 d705c4d6d7633abc4154b4db79a58a549096bbaa cb4eeaaa9b609a441e13a71191d8d54d

PE Resources 3

Name Language Sublanguage Offset Size Data
RT_RCDATA LANG_NEUTRAL SUBLANG_NEUTRAL 0x2eb3c 32
RT_VERSION LANG_NEUTRAL SUBLANG_NEUTRAL 0x2eb5c 796
RT_MANIFEST LANG_NEUTRAL SUBLANG_NEUTRAL 0x2ee78 490

Meta infos 12

LegalCopyright: Copyright \xa9 2023
Assembly Version: 1.0.0.0
InternalName: NNnNh887.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: NNnNh887
ProductVersion: 1.0.0.0
FileDescription: NNnNh887
Translation: 0x0000 0x04b0
OriginalFilename: NNnNh887.exe

Packers detected 2

Microsoft Visual C++ 8
VC8 -> Microsoft Corporation

Anti debug functions 5

GetLastError
IsDebuggerPresent
RaiseException
TerminateProcess
UnhandledExceptionFilter

Strings analysis - File found

Library
KERNEL32.dll
mscoree.dll
USER32.dll
OLEAUT32.dll
ole32.dll

Import functions

Name Latest seen MD5
.NetFramework.exe 2023-06-22 19:16:03 b8bee86a938a8b2245aa9343077958a6
Lion.exe 2023-06-27 19:52:02 1cbb726aada6d392c55f2a52113d05eb
mo.exe 2023-06-28 10:56:02 8ef917494a0e51cc61e491173b16150d
btt.exe 2023-06-29 07:32:01 e052e7de9592d69a07411a1d2bb182b6
haitianzx.exe 2023-07-05 07:31:03 2d2e577e7bb99c8854fdc99d94eb1338
looorlki.exe 2023-07-07 08:36:02 02702bec6d76bf792b0ce39f6fab58e9
NBbH87.exe 2023-07-14 12:42:01 e8a59b068f08284eb4159afadb10110e
Asx.exe 2023-07-14 14:24:02 af2e78a40b94d6e6b5f1d002d340c059
MNKLOP873.exe 2023-07-20 07:25:02 a79a555d8074362ce42e03465fc6655d
SuWar3Tools.exe 2023-09-04 20:11:05 8306a21a9f7d2d20d2ef8df82d9a7750
B.exe 2023-09-13 09:52:03 1c91d91d58c62fb93b9d3a7ee6f273fc
F.exe 2023-09-13 11:13:02 be5d8aca3a377e02a7effcdc07029afd
Gen.exe 2023-09-13 17:34:03 d0fa181e7c69e0b03b243c2190910ddd
Bossf.exe 2023-09-14 09:32:02 638c636255e504c4770e02f7271daa6c
Bossk.exe 2023-09-14 09:33:03 81c2a78ac19f048e31da4ca0fa9b001a