Malicious
Malicious

664aa5effd504a38797baec277832f32

AutoIt Compiled Script
|
MD5: 664aa5effd504a38797baec277832f32
|
Size: 651.65 KB
|
application/x-dosexec

Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
664aa5effd504a38797baec277832f32
Sha1
21b107ea92337671983e34f06ac172ead45c07f6
Sha256
0bd69037d93fb6b7ce7d697dc3bd16ef7407ae1c834468fb190cd5c7c88a686f
Sha384
cb352a81cdd1ab460f5fa296f02dbee7d79c38de699142a98b63aa8049f2cbc0e4283feea142f6d69b58f1a52dde6f1d
Sha512
8797783d8bdb6bfbdf580b88ce4726a0bc663e2412b05410d6fcaa13e4c29a1e2cebed58f9eadc401e8b63281efad17df07069f90c42504b63e1e0f7fd827eda
SSDeep
12288:xhkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcbNyX:/RmJkcoQricOIQxiZY1WNyX
TLSH
50D4AF21B5C69036C2B323B19E7EF76A9A3D79360336D29727C82D315EA05416B39733

PeID

Microsoft Visual C++ 6.0 DLL (Debug)
Microsoft Visual C++ 7.0 - 8.0
Microsoft Visual C++ 8
Microsoft Visual C++ 8
Microsoft Visual C++ v6.0 DLL
VC8 -> Microsoft Corporation
File Structure
Overlay_d71da100.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
Resources
RT_ICON
ID:0001
ID:2057
ID:0002
ID:2057
ID:0003
ID:2057
ID:0004
ID:2057
ID:0005
ID:2057
ID:0006
ID:2057
ID:0007
ID:2057
ID:0008
ID:2057
ID:0009
ID:2057
ID:000A
ID:2057
ID:000B
ID:2057
ID:000C
ID:2057
RT_MENU
ID:00A6
ID:2057
RT_DIALOG
ID:03E8
ID:2057
RT_STRING
ID:0007
ID:2057
ID:0008
ID:2057
ID:0009
ID:2057
ID:000A
ID:2057
ID:000B
ID:2057
ID:000C
ID:2057
ID:0139
ID:1033
RT_GROUP_CURSOR4
ID:0063
ID:2057
ID:00A2
ID:2057
ID:00A4
ID:2057
ID:00A9
ID:2057
RT_VERSION
ID:0001
ID:2057
RT_MANIFEST
ID:0001
ID:1033
aut14.tmp
Malicious
[Cleaned].au3
Malicious
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Overlay extracted: Overlay_d71da100.bin (2436 bytes)

664aa5effd504a38797baec277832f32 (651.65 KB)
File Structure
Overlay_d71da100.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
Resources
RT_ICON
ID:0001
ID:2057
ID:0002
ID:2057
ID:0003
ID:2057
ID:0004
ID:2057
ID:0005
ID:2057
ID:0006
ID:2057
ID:0007
ID:2057
ID:0008
ID:2057
ID:0009
ID:2057
ID:000A
ID:2057
ID:000B
ID:2057
ID:000C
ID:2057
RT_MENU
ID:00A6
ID:2057
RT_DIALOG
ID:03E8
ID:2057
RT_STRING
ID:0007
ID:2057
ID:0008
ID:2057
ID:0009
ID:2057
ID:000A
ID:2057
ID:000B
ID:2057
ID:000C
ID:2057
ID:0139
ID:1033
RT_GROUP_CURSOR4
ID:0063
ID:2057
ID:00A2
ID:2057
ID:00A4
ID:2057
ID:00A9
ID:2057
RT_VERSION
ID:0001
ID:2057
RT_MANIFEST
ID:0001
ID:1033
aut14.tmp
Malicious
[Cleaned].au3
Malicious
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙