temp.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 61/73 Related 2790
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 347.50 KB (355840 bytes)
Compile time: 2020-01-06 11:38:16
MD5: 3b879cfdeb1567142e077f9956faf618
SHA1: 158c2efd2ba719fb3f66ee53757a4b3b1d2fe59a
SHA256: c960dc7aeadf52b354fac14ba3280106bce522479a0ea0daa16eaa92484882ea
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2020-01-28 00:21:09
Last submission: 2020-01-28 01:24:04
Filename detected: - Temp.exe (2)
URL file hosting
hXXp://xmr.haoqing.me/2/Temp.exeVirusTotal
hXXp://185.150.2.234/2/temp.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2020-01-15 12:25:18 [61/73] VirusTotal
PE Sections 1 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x56164 352768 4ad5208eec8e54230e53826407d60bae 21016879eb117140a5229dc0d55935faea1a92ca
.rsrc 0x5a000 0x800 2048 a0099238a79c36d03b65c5535813727c 789849ca83e66caf0b647822e1b7cc5b5cf58014
.reloc 0x5c000 0xc 512 6c31a5bbe7b15a283f2411e7f3f690e7 5373a4eebebfe60919a4150adbbe0053e1f3464e
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: XML
{0}\FileZilla\sitemanager.xml
{0}\FileZilla\recentservers.xml
System.Xml
FIle type: Library
\msvcp120.dll
\mozglue.dll
\msvcr120.dll
\msvcp100.dll
\nss3.dll
\msvcr100.dll
USER32.dll
KERNEL32.dll
ntdll.dll
IPHLPAPI.DLL
mscoree.dll
MSVCRT.dll
GDI32.dll
SHELL32.dll
SHLWAPI.dll
ole32.dll
ADVAPI32.dll
OLEAUT32.dll
IP Found
No IP detected
URL(s)
http://ip-api.com/json/
http://
http://api.ipify.org/
file:///
http://schemas.microsoft.com/SMI/2005/WindowsSettings
http://freegeoip.net/xml/

#infosec #automation

TheSystem Itself @ 2020-01-28 00:21:10