Suspicious
Suspect

1b64c9e45178275bc87d8bbb3ab3c4db

AutoIt Compiled Script
|
MD5: 1b64c9e45178275bc87d8bbb3ab3c4db
|
Size: 10.49 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
1b64c9e45178275bc87d8bbb3ab3c4db
Sha1
0d2f2a54492fc08e0e146b334623b32c3581fc2e
Sha256
9190af1c1e709da8949a355c9ea9c8e545640da65da4a6ee8e93ad7d036eb856
Sha384
9adacbfdc85d69dd5af5b4f5dbf44739a6123e0e0734e888eb0203af738eb8731b151ba15f92ad1ee8cd80fee9f7ab8b
Sha512
43cebaced738f0ad11cf9979b1d58d99824afd3c9a252f468ab904f6b2738b6e4d7d17ebe6c175c8d3ac7269e64eb8cb9b1e16685bc085fd9fd379039e0b9c33
SSDeep
24576:ZVD9H7qGJrf08jBAGZUeBJ5/uOf8x+Kq7bbRnc6qEkDm8y:ZvbqGNRj1mW/uOcwbbGmv
TLSH
94B66509E3044A67143BF60703B52113A4BA55E8B313365B5FE2AA1E378983FDF19AD7

PeID

Microsoft Visual C++ v6.0 DLL
Nullsoft PiMP Stub -> SFX
File Structure
Overlay_d499e2c9.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Overlay extracted: Overlay_d499e2c9.bin (10430941 bytes)

1b64c9e45178275bc87d8bbb3ab3c4db (10.49 MB)
File Structure
Overlay_d499e2c9.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙