Malicious
Malicious

1b0a6cd12965755f27237679ca3c34f4

AutoIt Compiled Script
|
MD5: 1b0a6cd12965755f27237679ca3c34f4
|
Size: 1.37 MB
|
application/x-dosexec


Print
Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
1b0a6cd12965755f27237679ca3c34f4
Sha1
29ea5365f423bc6ee1df8192e6bf61f38c00237a
Sha256
915cd680a2253acc535668333c7147e97683c9a877b8b71c6256591ff42a2997
Sha384
6762b32450c5102e66d983d8af817eea7017dd7fc3effd575fe354a251e427b30270b3fd3ac71295b764a0c59d4a217c
Sha512
d5c101f25c60fb397e09f53f5d6d50e51f25a04ccfd55535a366a72b85a68e55fa84a302e902e9c1a28965ff9187bd7ed888f8d167953d9e82bf3a08930fc81c
SSDeep
24576:K5xolYQY6M5EmXFtKaL4/oFe5T9yyXYfP1ijXdaGpUgwYgEN++2eBAj:dYDPVt/LZeJbInQRaGeegEj29
TLSH
3155BF02B380D026FFABD6720A66F6526B7C6D350623AD1F13841E79BD70263667E317

PeID

Microsoft Visual Basic v5.0 - v6.0
Microsoft Visual C++ 6.0 DLL (Debug)
Microsoft Visual C++ v6.0 DLL
Protect Shareware V1.1 -> eCompserv CMS
File Structure
aut27B0.tmp.tok
Malicious
[Cleaned].au3
Malicious
Overlay_e64cee5f.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.tdata
Resources
RT_ICON
ID:7531
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
VB6 Structure
VB Header
VB VBAProject Info
VB Object Table
VB VBAProject Info 2
VB Register Info
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Overlay extracted: Overlay_e64cee5f.bin (1124764 bytes)

1b0a6cd12965755f27237679ca3c34f4 (1.37 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙