General
Structural Analysis
Config.0
Yara Rules90
Sync
Community
Infection Chain
Summary by MalvaGPT
Characteristics
|
Hash | Hash Value |
|---|---|
| MD5 | 3e9a23f7da32e528f29d014a2d5a42ba
|
| Sha1 | 93e7ae5071e553a689cbc466101f6a5c886e9e36
|
| Sha256 | e3a317e4f425477561ced4167bb16eac007a58a484e79c263425fbfe73257cab
|
| Sha384 | 23f18b89bcff6cf358f62cbbddb455265f3b59faa6f707052bd9e6fa894f456907c0fd35cee529e3e0f8c6f90e68c7f6
|
| Sha512 | a23b93fb5790dd22c7dce33059d0985aba6162208a3cb76433b981946778388c6fcc42150c81544e2a390b3bac4260c89f64492e2ebc750d23ff8eeb85f6d004
|
| SSDeep | 98304:qkwgd/I6OFPYJRGyi1sSjOAT5ibJdBFwjc4xntri/ncN4dV3SZlj22qiwGYO1HZR:qkX/1ONwgyoLT5ibJ/ijcEri0Y6B1pYo
|
| TLSH | B75633867F49D33EF2276C7888D0E1F2332BBDDA215CAB9613CC3D4A97119227768651
|
PeID
Microsoft Visual C++ v6.0 DLL
File Structure
3e9a23f7da32e528f29d014a2d5a42ba
Malicious
[NSIS Installer] @ #00031A08
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
IlDasm.chm
Overlay_eb539ef6.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
Overlay_58619ede.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
gacutil.exe.config
Overlay_4a9fe948.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.tls
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_STRING
ID:003F
ID:1033
RT_GROUP_CURSOR4
ID:0088
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
lc.exe
Overlay_5f091dab.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
.Net Resources
SR.resources
CommonResStrings.resources
lc.exe.config
mage.exe
Overlay_281e2a90.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_VERSION
ID:0001
ID:1033
.Net Resources
mage.Application.resources
Microsoft.Build.LicenseUtil.LicenseTemplate.xml
mgmtclassgen.exe
Overlay_c3e6c453.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
.Net Resources
MgmtClassGen.resources
mix.html
mpgo.exe
Overlay_7435ff23.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
.Net Resources
mpgo.resources
[SETUP_DECOMPILED.NSI]
Malicious
Overlay_34c5d724.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Informations
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_34c5d724.bin (5983091 bytes) |
3e9a23f7da32e528f29d014a2d5a42ba (6.19 MB)
File Structure
3e9a23f7da32e528f29d014a2d5a42ba
Malicious
[NSIS Installer] @ #00031A08
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
IlDasm.chm
Overlay_eb539ef6.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
Overlay_58619ede.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
gacutil.exe.config
Overlay_4a9fe948.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.tls
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_STRING
ID:003F
ID:1033
RT_GROUP_CURSOR4
ID:0088
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
lc.exe
Overlay_5f091dab.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
.Net Resources
SR.resources
CommonResStrings.resources
lc.exe.config
mage.exe
Overlay_281e2a90.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_VERSION
ID:0001
ID:1033
.Net Resources
mage.Application.resources
Microsoft.Build.LicenseUtil.LicenseTemplate.xml
mgmtclassgen.exe
Overlay_c3e6c453.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
.Net Resources
MgmtClassGen.resources
mix.html
mpgo.exe
Overlay_7435ff23.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
.Net Resources
mpgo.resources
[SETUP_DECOMPILED.NSI]
Malicious
Overlay_34c5d724.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.