Malicious
00a4a51a26ac30c87349c2cc0acbdaf9
AutoIt Compiled Script | MD5: 00a4a51a26ac30c87349c2cc0acbdaf9 | Size: 803.33 KB | application/x-dosexec
AutoIt Compiled Script
MD5: 00a4a51a26ac30c87349c2cc0acbdaf9
Size: 803.33 KB
application/x-dosexec
Infection Chain
Summary by MalvaGPT
Characteristics
|
Hash | Hash Value |
|---|---|
| MD5 | 00a4a51a26ac30c87349c2cc0acbdaf9
|
| Sha1 | 2601f03601b6c02c0ecd85c56664ea650e0a157c
|
| Sha256 | 4fb5ba01653be0268ec6b25fcfe0a87c21c233787a109d449d95ec31f6cdc090
|
| Sha384 | e90bda4a1784ca46599c9b1f9491a05c4d2432695d74d3b66308ee468d2e90e08a0aa2f8ddeb8f67ead91db74adc272b
|
| Sha512 | 3eb7c0cb943ac94920b542247f10f8b4de1e6d9eda6496328446796a8103cfe08561379e4e652150bc7d94c56931d51158a186958aceda51fcffde2a2bf0a723
|
| SSDeep | 24576:Kq5TfcdHj4fmbxF6FmQlw5dW1VukuyX572j:KUTsamcmQlw5auqJq
|
| TLSH | 95052262691ACCFEFABB13F5447D3AB16A67BE20D80B154F25CBB28047F4190E467724
|
PeID
Microsoft Visual C++ v6.0 DLL
Packer=UPX Compresor..Gratuito... www.upx.sourceforge.net
UPX -> www.upx.sourceforge.net
UPX Modified >> *$igBy Ahmed18
UPX v0.89.6 - v1.02 / v1.05 -v1.24 -> Markus & Laszlo (overlay)]
UPX v1.25 (Delphi) Stub
UPX v3.0
File Structure
00a4a51a26ac30c87349c2cc0acbdaf9
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
UPX0
UPX1
.rsrc
Resources
RT_ICON
ID:0001
ID:2057
ID:0002
ID:2057
RT_STRING
ID:0007
ID:2057
RT_RCDATA
ID:0000
RT_GROUP_CURSOR4
ID:0063
ID:2057
ID:00A9
ID:2057
RT_VERSION
ID:0001
ID:2057
RT_MANIFEST
ID:0001
ID:2057
00a4a51a26ac30c87349c2cc0acbdaf9 (803.33 KB)
File Structure
00a4a51a26ac30c87349c2cc0acbdaf9
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
UPX0
UPX1
.rsrc
Resources
RT_ICON
ID:0001
ID:2057
ID:0002
ID:2057
RT_STRING
ID:0007
ID:2057
RT_RCDATA
ID:0000
RT_GROUP_CURSOR4
ID:0063
ID:2057
ID:00A9
ID:2057
RT_VERSION
ID:0001
ID:2057
RT_MANIFEST
ID:0001
ID:2057
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.