Malicious
Malicious

4c5a391992cb8082c641fbf1f6edc5b7

AutoIt Compiled Script
|
MD5: 4c5a391992cb8082c641fbf1f6edc5b7
|
Size: 1.31 MB
|
application/x-msdownload

Executable
AutoIt
Suspect
Decompiled
PE (Portable Executable)
Win 32 Exe
x86
PDB Path

Print
General
Structural Analysis
Config.0
Yara Rules51
Sync
Community
Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
4c5a391992cb8082c641fbf1f6edc5b7
Sha1
d8b9a4b91f31cdc7f631c1d0a6938c63ee6c78d2
Sha256
ebd00edd8f33400c1b9fa03df3bfcceb4871fa5e96a05d218eb9e092243ef4cc
Sha384
e86903c3de6558167f2c44757164ee4275aeac8920fa74b2bba85995927ea16aa8b9e71543220f7ab4b6d8dde6d02378
Sha512
72f02be5a6b6a62e0318831ce21b26af17a72a825b82c710ddcb2cc8c105d7bb91d28182bc6d6c7fb33899fa5a9c7d7b3233920181b27f78f3e8cbb41052beef
SSDeep
24576:2tb20pkaCqT5TBWgNQ7auMItbVTS/PKDQvVZ6A:jVg5tQ7aunBuwaP5
TLSH
CB55D02273DEC3A0C7B25173BA157702AEBF782506B1F4EB2FD8093DA921161525E673

PeID

Microsoft Visual C++ 6.0 DLL (Debug)
Microsoft Visual C++ 7.0 - 8.0
Microsoft Visual C++ 8
Microsoft Visual C++ 8
Microsoft Visual C++ v6.0 DLL
VC8 -> Microsoft Corporation
File Structure
4c5a391992cb8082c641fbf1f6edc5b7
Executable
AutoIt
Suspect
Decompiled
PE (Portable Executable)
Win 32 Exe
x86
PDB Path
Malicious
aut4413.tmp.tok
AutoIt
Suspect
Decompiled
Malicious
[Cleaned].au3
AutoIt
Suspect
Decompiled
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:2057
ID:0002
ID:2057
ID:0003
ID:2057
ID:0004
ID:2057
ID:0005
ID:2057
ID:0006
ID:2057
ID:0007
ID:2057
RT_MENU
ID:00A6
ID:2057
RT_STRING
ID:0007
ID:2057
ID:0008
ID:2057
ID:0009
ID:2057
ID:000A
ID:2057
ID:000B
ID:2057
ID:000C
ID:2057
ID:0139
ID:2057
RT_RCDATA
ID:0000
ID:0
Executable
AutoIt
RT_GROUP_CURSOR4
ID:0063
ID:2057
ID:00A2
ID:2057
ID:00A4
ID:2057
ID:00A9
ID:2057
RT_VERSION
ID:0001
ID:2057
RT_MANIFEST
ID:0001
ID:2057
Artefacts
Name
Value
PDB Path

????

4c5a391992cb8082c641fbf1f6edc5b7 (1.31 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙