Malicious
Malicious

3e9a23f7da32e528f29d014a2d5a42ba

PE Executable
|
MD5: 3e9a23f7da32e528f29d014a2d5a42ba
|
Size: 6.19 MB
|
application/x-dosexec


Print
Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
3e9a23f7da32e528f29d014a2d5a42ba
Sha1
93e7ae5071e553a689cbc466101f6a5c886e9e36
Sha256
e3a317e4f425477561ced4167bb16eac007a58a484e79c263425fbfe73257cab
Sha384
23f18b89bcff6cf358f62cbbddb455265f3b59faa6f707052bd9e6fa894f456907c0fd35cee529e3e0f8c6f90e68c7f6
Sha512
a23b93fb5790dd22c7dce33059d0985aba6162208a3cb76433b981946778388c6fcc42150c81544e2a390b3bac4260c89f64492e2ebc750d23ff8eeb85f6d004
SSDeep
98304:qkwgd/I6OFPYJRGyi1sSjOAT5ibJdBFwjc4xntri/ncN4dV3SZlj22qiwGYO1HZR:qkX/1ONwgyoLT5ibJ/ijcEri0Y6B1pYo
TLSH
B75633867F49D33EF2276C7888D0E1F2332BBDDA215CAB9613CC3D4A97119227768651

PeID

Microsoft Visual C++ v6.0 DLL
File Structure
[NSIS Installer] @ #00031A08
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
IlDasm.chm
Overlay_eb539ef6.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
Overlay_58619ede.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
gacutil.exe.config
Overlay_4a9fe948.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.tls
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_STRING
ID:003F
ID:1033
RT_GROUP_CURSOR4
ID:0088
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Overlay_5f091dab.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
.Net Resources
SR.resources
CommonResStrings.resources
lc.exe.config
Overlay_281e2a90.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_VERSION
ID:0001
ID:1033
.Net Resources
mage.Application.resources
Microsoft.Build.LicenseUtil.LicenseTemplate.xml
Overlay_c3e6c453.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
.Net Resources
MgmtClassGen.resources
Overlay_7435ff23.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
.Net Resources
mpgo.resources
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
Overlay_34c5d724.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Overlay extracted: Overlay_34c5d724.bin (5983091 bytes)

3e9a23f7da32e528f29d014a2d5a42ba (6.19 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙