Malicious
1b0a6cd12965755f27237679ca3c34f4
AutoIt Compiled Script | MD5: 1b0a6cd12965755f27237679ca3c34f4 | Size: 1.37 MB | application/x-dosexec
AutoIt Compiled Script
MD5: 1b0a6cd12965755f27237679ca3c34f4
Size: 1.37 MB
application/x-dosexec
Infection Chain
Summary by MalvaGPT
Characteristics
|
Hash | Hash Value |
|---|---|
| MD5 | 1b0a6cd12965755f27237679ca3c34f4
|
| Sha1 | 29ea5365f423bc6ee1df8192e6bf61f38c00237a
|
| Sha256 | 915cd680a2253acc535668333c7147e97683c9a877b8b71c6256591ff42a2997
|
| Sha384 | 6762b32450c5102e66d983d8af817eea7017dd7fc3effd575fe354a251e427b30270b3fd3ac71295b764a0c59d4a217c
|
| Sha512 | d5c101f25c60fb397e09f53f5d6d50e51f25a04ccfd55535a366a72b85a68e55fa84a302e902e9c1a28965ff9187bd7ed888f8d167953d9e82bf3a08930fc81c
|
| SSDeep | 24576:K5xolYQY6M5EmXFtKaL4/oFe5T9yyXYfP1ijXdaGpUgwYgEN++2eBAj:dYDPVt/LZeJbInQRaGeegEj29
|
| TLSH | 3155BF02B380D026FFABD6720A66F6526B7C6D350623AD1F13841E79BD70263667E317
|
PeID
Microsoft Visual Basic v5.0 - v6.0
Microsoft Visual C++ 6.0 DLL (Debug)
Microsoft Visual C++ v6.0 DLL
Protect Shareware V1.1 -> eCompserv CMS
File Structure
1b0a6cd12965755f27237679ca3c34f4
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.tdata
Resources
RT_ICON
ID:7531
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
VB6 Structure
VB Header
VB VBAProject Info
VB Object Table
VB VBAProject Info 2
VB Register Info
Informations
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_e64cee5f.bin (1124764 bytes) |
1b0a6cd12965755f27237679ca3c34f4 (1.37 MB)
File Structure
1b0a6cd12965755f27237679ca3c34f4
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.tdata
Resources
RT_ICON
ID:7531
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
VB6 Structure
VB Header
VB VBAProject Info
VB Object Table
VB VBAProject Info 2
VB Register Info
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.