Malicious
Malicious

201a808756ea234893fee20bb524b05c

PE Executable
|
MD5: 201a808756ea234893fee20bb524b05c
|
Size: 196.61 KB
|
application/x-dosexec

Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
201a808756ea234893fee20bb524b05c
Sha1
48a29e13562467c647793978587b1d92648c83cc
Sha256
b8e4db27a7347c05c3e9d42a6e04f9bf8ae0b0df6a78fb68c9d818bccd7a68ec
Sha384
67e5f9269ac278069d780b7c91502d883a0670f328b709124661b631767ea00de769c267a03c823095777de05fab5209
Sha512
a7c42a4db4d1e79c9925186571ad11185156f2c1c20ba5fa35c78c895983518fd54f692e654434812f0a5fbd046b038f53137cbaa44e230d7f331f964361a76a
SSDeep
3072:8RLCJxDxQxsO8lM51B5GWp1icKAArDZz4N9GhbkrNEkOlKn/:NXDxQrbp0yN90QEHK
TLSH
09146B0927E610A6F0B66B7499F102934A3A7C637B7592FF5784803E0E336C4A971F63

PeID

Microsoft Visual C++ 8.0 (DLL)
File Structure
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
.rsrc
.reloc
Resources
AVI
ID:0BB9
ID:1033
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:1033-preview.png
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
RT_DIALOG
ID:07D1
ID:1033
ID:2057
ID:07D2
ID:1033
ID:07D3
ID:1033
ID:07D4
ID:1033
ID:2057
ID:07D5
ID:1033
ID:2057
ID:07D6
ID:1033
RT_STRING
ID:003F
ID:1033
ID:004C
ID:1033
ID:2057
ID:004D
ID:1033
ID:2057
ID:0050
ID:1033
ID:0053
ID:1033
ID:2057
ID:0055
ID:1033
ID:2057
RT_RCDATA
ID:0000
ID:1033
ID:2057
debug.bat
RT_GROUP_CURSOR4
ID:0BB8
ID:1033
RT_VERSION
ID:0001
ID:1033
ID:2057
RT_MANIFEST
ID:0001
ID:1033
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: wextract.pdb

201a808756ea234893fee20bb524b05c (196.61 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
.rsrc
.reloc
Resources
AVI
ID:0BB9
ID:1033
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:1033-preview.png
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
RT_DIALOG
ID:07D1
ID:1033
ID:2057
ID:07D2
ID:1033
ID:07D3
ID:1033
ID:07D4
ID:1033
ID:2057
ID:07D5
ID:1033
ID:2057
ID:07D6
ID:1033
RT_STRING
ID:003F
ID:1033
ID:004C
ID:1033
ID:2057
ID:004D
ID:1033
ID:2057
ID:0050
ID:1033
ID:0053
ID:1033
ID:2057
ID:0055
ID:1033
ID:2057
RT_RCDATA
ID:0000
ID:1033
ID:2057
debug.bat
RT_GROUP_CURSOR4
ID:0BB8
ID:1033
RT_VERSION
ID:0001
ID:1033
ID:2057
RT_MANIFEST
ID:0001
ID:1033
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙