Suspicious
Suspect

60d11b3f61f53dd9cb25dbccf7a4be56

AutoIt Compiled Script
|
MD5: 60d11b3f61f53dd9cb25dbccf7a4be56
|
Size: 1.65 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
60d11b3f61f53dd9cb25dbccf7a4be56
Sha1
066db5824753dfe61bdfcf70cce7ad7aa7fae49c
Sha256
893fe6d3172ca636d638fd3b84eb483922211878ab0e4eb170b14edafd562cb3
Sha384
455ed6ed49636caa09478d2fbd5299b7695c1fa3f5faf73182f8f5d5d2f805376d77be8e96d1aebcc3a5a57039549946
Sha512
80106b8f97fc0b99487424dac79889fcaea415aff3f56ce00bba656c66dc6fd645dd4c6a8b1f2c7f3ef2b16317aa0d7115e4c264b2469dd98e42dc217f918ce9
SSDeep
49152:ROd3sDe3fPAHsPN2wVlXIxl6RtjQFrQi:RQvPTjl4xgQFrH
TLSH
2A752347A1D6A87EC86117B469F523CF063A3C958F3D85DB378219874CE3AC469383B9

PeID

Microsoft Visual C++ 8
UPolyX 0.3 -> delikon
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.rsrc
.reloc
Resources
AVI
ID:0BB9
ID:1033
RT_ICON
ID:0001
ID:1033
RT_DIALOG
ID:07D1
ID:1033
ID:07D2
ID:1033
ID:07D3
ID:1033
ID:07D4
ID:1033
ID:07D5
ID:1033
ID:07D6
ID:1033
RT_STRING
ID:003F
ID:1033
ID:004C
ID:1033
ID:004D
ID:1033
ID:0050
ID:1033
ID:0053
ID:1033
ID:0055
ID:1033
RT_RCDATA
ID:0000
ID:1033
RT_GROUP_CURSOR4
ID:0BB8
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Frontier.dot
Attach.dot
Executed.dot
Relevance
Accountability
Corrections
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: wextract.pdb

60d11b3f61f53dd9cb25dbccf7a4be56 (1.65 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.rsrc
.reloc
Resources
AVI
ID:0BB9
ID:1033
RT_ICON
ID:0001
ID:1033
RT_DIALOG
ID:07D1
ID:1033
ID:07D2
ID:1033
ID:07D3
ID:1033
ID:07D4
ID:1033
ID:07D5
ID:1033
ID:07D6
ID:1033
RT_STRING
ID:003F
ID:1033
ID:004C
ID:1033
ID:004D
ID:1033
ID:0050
ID:1033
ID:0053
ID:1033
ID:0055
ID:1033
RT_RCDATA
ID:0000
ID:1033
RT_GROUP_CURSOR4
ID:0BB8
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Frontier.dot
Attach.dot
Executed.dot
Relevance
Accountability
Corrections
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙