Malicious
Malicious

82ec03a5872682040a32b56620436705

AutoIt Compiled Script
|
MD5: 82ec03a5872682040a32b56620436705
|
Size: 1.32 MB
|
application/x-dosexec

Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
82ec03a5872682040a32b56620436705
Sha1
7d0dcc4c20a43d17954b6264d1e915c8e8f82345
Sha256
60ca1d32e2a19f4df9278382f81b3b460181dab8060b9ee2922ce9c497fb181d
Sha384
6b25ad65a5254ebe6b9aa89949ea4dc617961c91484e58dea101759371f3bc0a28a29cf920cb96feed85f3fc06f9fd01
Sha512
9a0133767adbb12450ee74741e3a575231b497c72dc4971d1a0e1662112f66ef4b2b90d3cd16379701e08e94d74e4044c66a6ec47c0b61b0cd54fdd2108aaa9f
SSDeep
24576:K5xolYQY6O5EmXFtKaL4/oFe5T9yyXYfP1ijXda2/Dreuq9q:dYVPVt/LZeJbInQRa2/DrN
TLSH
0F55BF0373809027FFAB95724E16F621AB787D320663AD1F13941E79B970163A63E367

PeID

Microsoft Visual Basic v5.0 - v6.0
Microsoft Visual C++ 6.0 DLL (Debug)
Microsoft Visual C++ v6.0 DLL
Protect Shareware V1.1 -> eCompserv CMS
File Structure
aut596D.tmp.tok
Malicious
[Cleaned].au3
Malicious
Overlay_9e36d127.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.tdata
Resources
RT_ICON
ID:7531
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
VB6 Structure
VB Header
VB VBAProject Info
VB Object Table
VB VBAProject Info 2
VB Register Info
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Overlay extracted: Overlay_9e36d127.bin (1070616 bytes)

82ec03a5872682040a32b56620436705 (1.32 MB)
File Structure
aut596D.tmp.tok
Malicious
[Cleaned].au3
Malicious
Overlay_9e36d127.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.tdata
Resources
RT_ICON
ID:7531
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
VB6 Structure
VB Header
VB VBAProject Info
VB Object Table
VB VBAProject Info 2
VB Register Info
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙