Suspicious
Suspect

5111b3fc664db7f8f072f27088383f30

AutoIt Compiled Script
|
MD5: 5111b3fc664db7f8f072f27088383f30
|
Size: 1.24 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
5111b3fc664db7f8f072f27088383f30
Sha1
38b1721fb0cec8247809a1aa846f652abfaf189b
Sha256
6258e673b8bfafeeb1c5a3e928af342d91d70fd42e940b8a011b66eb154c1e8c
Sha384
35896f0ff9b55777b89e089b802498027a046a781e794046adfd9b6740d2a480d4f2eae534a22b4948abd7de9dfabc73
Sha512
0437b8788ae3e4401495e007ec9c7aa777c1438f67ccc68ae4ab474e7aa0ed5ba14f6f56d50fdcc0114a9a35c4019d0eb38ca1afea000bfba3ca4e6e6ea2d0df
SSDeep
24576:ejqJFW9SrWc5IznII6/1Er4rg/RlAk5GMZljatzkHNIf1oO1Oyn2m+PmiEB6T9FF:ejGM9EWc5IfagPsMG2gNktRPml67t/
TLSH
B945234702FD14F7E8B65B7546B121039B3078A10B7AAAAF7288C8381F667C16773B57

PeID

Microsoft Visual C++ 8.0 (DLL)
UPolyX 0.3 -> delikon
File Structure
[Authenticode]_9d7ab24b.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
AVI
ID:0BB9
ID:1033
RT_ICON
ID:0001
ID:1033
RT_DIALOG
ID:07D1
ID:1033
ID:07D2
ID:1033
ID:07D3
ID:1033
ID:07D4
ID:1033
ID:07D5
ID:1033
ID:07D6
ID:1033
RT_STRING
ID:003F
ID:1033
ID:004C
ID:1033
ID:004D
ID:1033
ID:0050
ID:1033
ID:0053
ID:1033
ID:0055
ID:1033
RT_RCDATA
ID:0000
ID:1033
RT_GROUP_CURSOR4
ID:0BB8
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Chair.msi
Aluminium
Acknowledged
Maintained
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x12C000 size 10320 bytes

Info

PDB Path: wextract.pdb

5111b3fc664db7f8f072f27088383f30 (1.24 MB)
File Structure
[Authenticode]_9d7ab24b.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
AVI
ID:0BB9
ID:1033
RT_ICON
ID:0001
ID:1033
RT_DIALOG
ID:07D1
ID:1033
ID:07D2
ID:1033
ID:07D3
ID:1033
ID:07D4
ID:1033
ID:07D5
ID:1033
ID:07D6
ID:1033
RT_STRING
ID:003F
ID:1033
ID:004C
ID:1033
ID:004D
ID:1033
ID:0050
ID:1033
ID:0053
ID:1033
ID:0055
ID:1033
RT_RCDATA
ID:0000
ID:1033
RT_GROUP_CURSOR4
ID:0BB8
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Chair.msi
Aluminium
Acknowledged
Maintained
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙