Suspicious
Suspect

0ed68b7b3c352c983fcd4230af19d359

PE Executable
MD5: 0ed68b7b3c352c983fcd4230af19d359
Size: 2.98 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0ed68b7b3c352c983fcd4230af19d359
Sha1 b78d629424f7829d9522a5340625dcbdd1a258ee
Sha256 e06cea49c482dd0ddc55cab8fdf5a042540db352139475a8019768481ef152af
Sha384 e85e608d6e8bf56faebae4044cd00e776ca1091e1c921cf4dbd8cc5052c3b66aee598a813cbe04bbee5815b54a6ce6c9
Sha512 4b64f1dda5cdefd59c2821aa2773e87dbabd66629eb77bfb6626984934b10c03d303de417e35352f21c15a734b62cd840d58076c74ac10e20453850a4ec1e264
SSDeep 24576:4hi/qTZh4SbG7T/PefvsluxX/ngo5wMNSeSORl5FEtRI48Y2VB/YFlb4+s/iiMTF:4hiyTZhQXnes8/ngSwjhHsHqSM7K0
TLSH 30D58CCBACE108A9C1E693368AB657927B75FC090B3263D72E50B23C2F727D05935764
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12tElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_0a9916e9.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
CUSTOM
ID:0087
ID:0
ID:0088
[Authenticode]_e4177044.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:2052
ZIPRES
ID:0085
img
-down.png
-down.png-preview.png
-hover.png
-hover.png-preview.png
-normal.png
-normal.png-preview.png
bkg
default
bkg1.png-preview.png
bkg2.png-preview.png
bkg3.png-preview.png
combo-lang-hot.png
combo-lang-hot.png-preview.png
combo-lang-normal.png
combo-lang-normal.png-preview.png
logo.png-preview.png
msgbox_info.png
msgbox_info.png-preview.png
opt-hover.png
opt-hover.png-preview.png
opt-normal.png
opt-normal.png-preview.png
opt-selected-hover.png
opt-selected-hover.png-preview.png
opt-selected-normal.png
opt-selected-normal.png-preview.png
process_light.png
process_light.png-preview.png
x-down.png
x-down.png-preview.png
x-hover.png
x-hover.png-preview.png
x-normal.png
x-normal.png-preview.png
messagebox.xml
tgbdownloader.xml
RT_ICON
ID:0001
ID:0
RT_MENU
ID:006D
ID:2052
RT_STRING
ID:0007
ID:2052
RT_GROUP_CURSOR4
ID:006B
ID:0
RT_VERSION
ID:0001
ID:2052
RT_MANIFEST
ID:0001
ID:1033
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x2D4400 size 10888 bytes
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #4 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #5 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #6 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #7 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #8 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #9 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #10 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #11 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #12 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #13 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #14 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #15 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #16 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #17 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #18 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #19 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #20 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #21 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #22 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #23 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #24 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #25 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #26 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #27 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #28 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #29 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #30 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #31 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #32 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #33 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #34 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #35 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #36 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #37 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Authenticode]_0a9916e9.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
CUSTOM
ID:0087
ID:0
ID:0088
[Authenticode]_e4177044.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:2052
ZIPRES
ID:0085
img
-down.png
-down.png-preview.png
-hover.png
-hover.png-preview.png
-normal.png
-normal.png-preview.png
bkg
default
bkg1.png-preview.png
bkg2.png-preview.png
bkg3.png-preview.png
combo-lang-hot.png
combo-lang-hot.png-preview.png
combo-lang-normal.png
combo-lang-normal.png-preview.png
logo.png-preview.png
msgbox_info.png
msgbox_info.png-preview.png
opt-hover.png
opt-hover.png-preview.png
opt-normal.png
opt-normal.png-preview.png
opt-selected-hover.png
opt-selected-hover.png-preview.png
opt-selected-normal.png
opt-selected-normal.png-preview.png
process_light.png
process_light.png-preview.png
x-down.png
x-down.png-preview.png
x-hover.png
x-hover.png-preview.png
x-normal.png
x-normal.png-preview.png
messagebox.xml
tgbdownloader.xml
RT_ICON
ID:0001
ID:0
RT_MENU
ID:006D
ID:2052
RT_STRING
ID:0007
ID:2052
RT_GROUP_CURSOR4
ID:006B
ID:0
RT_VERSION
ID:0001
ID:2052
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #2 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #3 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #4 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #5 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #6 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #7 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #8 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #9 URIsuspect
http:/huhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #10 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #11 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #12 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #13 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #14 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #15 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #16 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #17 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #18 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #19 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #20 URIsuspect
http:/huhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #21 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #22 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #23 URIsuspect
http:/huhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #24 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #25 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #26 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #27 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #28 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #29 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #30 URIsuspect
http:/huhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #31 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #32 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #33 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #34 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #35 URIsuspect
http:/huhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #36 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
URLs in VB Code - #37 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
0ed68b7b3c352c983fcd4230af19d359
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙