MalScore
100/100
MalFamily
Quasar

test.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 51/68 Related 2635
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 288.50 KB (295424 bytes)
Compile time: 2018-12-17 10:05:25
MD5: 7c7b2b92922c95615d8e2dd08602fe7b
SHA1: ad709fa3a30c2d299b9deb84b1bb711a347307df
SHA256: 3c5f100f7fc7d3b63efc567d07b5db4948ce194114533b99e684a4e270281dfc
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2019-01-28 19:48:07
Last submission: 2019-01-28 19:48:07
Filename detected: - test.exe (1)
URL file hosting
hXXp://151.80.8.17/test.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2019-01-23 21:41:47 [51/68] VirusTotal
PE Sections 1 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x47444 292352 4b8f6b883e20bcd5bdc6495457d2be18 7c0752085c26329ff7e63f6f8e6c727617a9d22f
.rsrc 0x4a000 0x800 2048 a027b6bc741b57fb7aedeed9de1ffae2 3503f929c295c326c3f3ab9bd5ea9ca37f47867d
.reloc 0x4c000 0xc 512 b5fc73aca94693e22d120cfda3c0a7a5 35b07353cd957dd3d84750f5fe101f648eb68467
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: XML
{0}\FileZilla\recentservers.xml
{0}\FileZilla\sitemanager.xml
System.Xml
FIle type: Library
\msvcp120.dll
SbieDll.dll
\msvcr120.dll
\mozglue.dll
\msvcp100.dll
\nss3.dll
\msvcr100.dll
USER32.dll
KERNEL32.dll
WINMM.dll
ntdll.dll
IPHLPAPI.DLL
mscoree.dll
SHELL32.dll
MSVCRT.dll
GDI32.dll
SHLWAPI.dll
ole32.dll
ADVAPI32.dll
OLEAUT32.dll
IP Found
No IP detected
URL(s)
http://ip-api.com/json/
http://
http://api.ipify.org/
file:///
http://schemas.microsoft.com/SMI/2005/WindowsSettings
http://freegeoip.net/xml/
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven04_64 Seven04_64 VirtualBox 2019-01-28 19:43:09 2019-01-28 19:46:07 178

0 Summary items with data

Files

Nothing to display

Read Files

Nothing to display

Write Files

Nothing to display

Delete Files

Nothing to display

Keys

Nothing to display

Read Keys

Nothing to display

Write Keys

Nothing to display

Delete Keys

Nothing to display

Mutexes

Resolved APIs

Nothing to display

Execute Commands

Nothing to display

Started Services

Nothing to display

Created Services

Nothing to display

#infosec #automation

TheSystem Itself @ 2019-01-28 19:48:10

Detected family: #Quasar

TheSystem Itself @ 2019-01-28 19:54:02