Suspicious
Suspect

75c78b5218d8128396b3ad03b6190a95

AutoIt Compiled Script
|
MD5: 75c78b5218d8128396b3ad03b6190a95
|
Size: 10.49 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
75c78b5218d8128396b3ad03b6190a95
Sha1
89ea57c8e9eae99a387f0a6a35e133a5eb966e8c
Sha256
cb6f2bac0167f527d2bbf2e80c1f85b0a213036ee46580a41a8df84cb3ba3682
Sha384
fc84c8dae644d2366e56dd55a2b0dcc3593ba762e19946bcd4f97b631cb332aab7907c05817216d8b392013d74eb9c1b
Sha512
3ef654f396622f2bdc4e183b74e1b65b1d965c85631a0810fc7070ab7b9b9c8618f78a570a692f97fad3e26d03de179a2a00a5f0f89923b00f63ae47abe56850
SSDeep
24576:IzZKhALys8YaSUEvAq4XFM3B+avLDXns6vi/TT1619Eib3QI:IMqrrpvn4XFc+uXFvi7Q1Wibx
TLSH
A3B6544CD3048A5B107FF64B02F5151AA4BA91C8B25335574BE3EA0F378983EDB1AAD7

PeID

Microsoft Visual C++ v6.0 DLL
Nullsoft PiMP Stub -> SFX
File Structure
Organic.pptx
Nipples.pptx
Estimated.pptx
Deadly.pptx
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
[SETUP_DECOMPILED.NSI]
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:1033-preview.png
ID:0003
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
75c78b5218d8128396b3ad03b6190a95 (10.49 MB)
File Structure
Organic.pptx
Nipples.pptx
Estimated.pptx
Deadly.pptx
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
[SETUP_DECOMPILED.NSI]
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:1033-preview.png
ID:0003
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙