Malicious
Malicious

ae5f34e4f2d7050a30e55343616ae6ec

MS Office Document
|
MD5: ae5f34e4f2d7050a30e55343616ae6ec
|
Size: 7.85 MB
|
application/vnd.ms-office


Print
Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
ae5f34e4f2d7050a30e55343616ae6ec
Sha1
8d2320c94f6cbf90c71b37e66ef4a56a633242b9
Sha256
bbfd88a3102722503502810aaf93a6e0e91227b020432bd71e7cf7043d06e1f7
Sha384
868712dd8fbfff066d254a588a77f5b2cbc4f019164746cb00008eaef4ad42372cb69386a1fc25d6440c5ec5dc69ac1d
Sha512
c36038c74871fac5c5414ca73957069653ea20d02984a94b4c633727bc171de59a2d4f215d76b18d441d8f7d58332846f11e9ce66164643dad1fb29faff5d7fb
SSDeep
196608:9xF4FM8chWwNWmDiB1OfUX9sjkgUZDalFGxq0E:F4FM8chWrgUXSUZhI0E
TLSH
60862222B38BC526E25D0277F92DFE2E14396E63077001E776E97D4D5C748C263BAA42
File Structure
Root Entry
䡀䌏䈯
䡀㲞䈝䗻
䡀䈖䌧䠤
䡀䌋䄱䜵
䡀䌍䏤䊲
䡀䕎䒵䠵
䌋䄱䜵㷾䚨
䌋䄱䜵㾾䠳
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䈛䌪䗶䜵
䡀䋌䆨㫮䛲
䡀䒌䗱䒵䠯
䡀䓞䕪䇤䠨
䡀䕙䓲䕨䜷
䌋䄱䜵䌾䉱䠲
䡀䆊䌷䑲䈝䗻
䡀䈝䗻䗜䏼䠨
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䌋䄱䜵䗾䅤䄥䎦
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䄛䌧㫲䗸䒷䠱
䡀䒌䗱䒵㮯䈹䗱
䡀䕌䄨䈷䒏䇯䕨
䡀䘌䗶䐲䆊䌷䑲
䡀䙎䑨㶷䓤䌳䊱
䌋䄱䜵䆾䐲䏳䗨䠬
䌋䄱䜵䆾䖸䌷䒦䠱
䌋䄱䜵䈾䆻䄯䌰䠦
䌋䄱䜵䌾䖱䌷䒦䠱
䌋䄱䜵䕾䐨䙲䆬䠲
䌋䄱䜵䕾䓨䌤䌵䠦
䌋䄱䜵䅾䑤䈱䞵䓭䠪
䌋䄱䜵䅾䑤䈱䞵䓭䠪-preview.png
䌋䄱䜵䅾䑤䈱䞵䙶䠪
䌋䄱䜵䅾䑤䈱䞵䙶䠪-preview.jpg
䌋䄱䜵䇾䄬䒯䞪䓭䠪
䌋䄱䜵䇾䄬䒯䞪䓭䠪-preview.png
䌋䄱䜵䇾䄬䒯䞪䙶䠪
䌋䄱䜵䇾䄬䒯䞪䙶䠪-preview.jpg
䡀䄕䑸䋦䒌䇱䗬䒬䠱
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䒌䗱䒵㬯䑲䌧䌷䑲
[Authenticode]_5b668031.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
REGISTRY
ID:27DA
ID:1033
RT_DIALOG
ID:2AB7
ID:1033
RT_STRING
ID:09C5
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
䌋䄱䜵䆾䇰䌯䎱䕤䒵䠺
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
䡀䒋䗲䗶䄵䓳䕨㲞䈜䘴䑨䈦
䌋䄱䜵䅾䑤䈱䞵䆶䏤㡨㠅䍾䊳
䌋䄱䜵䅾䑤䈱䞵䆶䏤㡨㠅䍾䊳-preview.png
䌋䄱䜵䅾䑤䈱䞵䆶䏤㡨㥂䍾䊳
䌋䄱䜵䅾䑤䈱䞵䆶䏤㡨㥂䍾䊳-preview.png
䌋䄱䜵䅾䑤䈱䞵䆶䏤㢨㠀䍾䊳
䌋䄱䜵䅾䑤䈱䞵䆶䏤㢨㠀䍾䊳-preview.png
䌋䄱䜵䇾䄬䒯䞪䆶䏤㡨㠅䍾䊳
䌋䄱䜵䇾䄬䒯䞪䆶䏤㡨㠅䍾䊳-preview.png
䌋䄱䜵䇾䄬䒯䞪䆶䏤㡨㥂䍾䊳
䌋䄱䜵䇾䄬䒯䞪䆶䏤㡨㥂䍾䊳-preview.png
䌋䄱䜵䇾䄬䒯䞪䆶䏤㢨㠀䍾䊳
䌋䄱䜵䇾䄬䒯䞪䆶䏤㢨㠀䍾䊳-preview.png
DigitalSignature
SummaryInformation
MsiDigitalSignatureEx
ae5f34e4f2d7050a30e55343616ae6ec
0x00024016.svg
0x0004B989.svg
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.rsrc
.data
Resources
RT_CURSOR
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
RT_BITMAP
ID:0000
ID:1033
ID:1033.deobfuscated.vbs
RT_STRING
ID:0FC7
ID:0
ID:0FC8
ID:0
ID:0FC9
ID:0
ID:0FCA
ID:0
ID:0FCB
ID:0
ID:0FCC
ID:0
ID:0FCD
ID:0
ID:0FCE
ID:0
ID:0FCF
ID:0
ID:0FD0
ID:0
ID:0FD1
ID:0
ID:0FD2
ID:0
ID:0FD3
ID:0
ID:0FD4
ID:0
ID:0FD5
ID:0
ID:0FD6
ID:0
ID:0FD7
ID:0
ID:0FD8
ID:0
ID:0FD9
ID:0
ID:0FDA
ID:0
ID:0FDB
ID:0
ID:0FDC
ID:0
ID:0FDD
ID:0
ID:0FDE
ID:0
ID:0FDF
ID:0
ID:0FE0
ID:0
ID:0FE1
ID:0
ID:0FE2
ID:0
ID:0FE3
ID:0
ID:0FE4
ID:0
ID:0FE5
ID:0
ID:0FE6
ID:0
ID:0FE7
ID:0
ID:0FE8
ID:0
ID:0FE9
ID:0
ID:0FEA
ID:0
ID:0FEB
ID:0
ID:0FEC
ID:0
ID:0FED
ID:0
ID:0FEE
ID:0
ID:0FEF
ID:0
ID:0FF0
ID:0
ID:0FF1
ID:0
ID:0FF2
ID:0
ID:0FF3
ID:0
ID:0FF4
ID:0
ID:0FF5
ID:0
ID:0FF6
ID:0
ID:0FF7
ID:0
ID:0FF8
ID:0
ID:0FF9
ID:0
ID:0FFA
ID:0
ID:0FFB
ID:0
ID:0FFC
ID:0
ID:0FFD
ID:0
ID:0FFE
ID:0
ID:0FFF
ID:0
ID:1000
ID:0
RT_VERSION
ID:0001
ID:1033
[Authenticode]_a3febf28.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.gfids
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
RT_MENU
ID:006D
ID:1033
RT_DIALOG
ID:0067
ID:1033
RT_STRING
ID:0007
ID:1033
RT_ACCELERATOR
ID:006D
ID:1033
RT_GROUP_CURSOR4
ID:006B
ID:1033
ID:006C
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Artefacts
Name
Value
URLs in VB Code - #1

http://ns.adobe.com/xap/1.0/

URLs in VB Code - #2

http://www.w3.org/1999/02/22-rdf-syntax-ns#

URLs in VB Code - #3

http://ns.adobe.com/xap/1.0/mm/

URLs in VB Code - #4

http://ns.adobe.com/xap/1.0/sType/ResourceRef#

URLs in VB Code - #5

http://www.w3.org/2000/svg

URLs in VB Code - #6

http://www.w3.org/1999/xlink

URLs in VB Code - #7

http://www.microsoft.com/pkiops/crl/Microsoft%20ID%20Verified%20CS%20AOC%20CA%2001.crl0

URLs in VB Code - #8

http://www.microsoft.com/pkiops/certs/Microsoft%20ID%20Verified%20CS%20AOC%20CA%2001.crt0

URLs in VB Code - #9

http://oneocsp.microsoft.com/ocsp0f

URLs in VB Code - #10

http://www.microsoft.com/pkiops/Docs/Repository.htm0

URLs in VB Code - #11

http://www.microsoft.com/pkiops/crl/Microsoft%20ID%20Verified%20Code%20Signing%20PCA%202021.crl0

URLs in VB Code - #12

http://www.microsoft.com/pkiops/certs/Microsoft%20ID%20Verified%20Code%20Signing%20PCA%202021.crt0

URLs in VB Code - #13

http://oneocsp.microsoft.com/ocsp0

URLs in VB Code - #14

http://www.microsoft.com/pkiops/crl/Microsoft%20Identity%20Verification%20Root%20Certificate%20Authority%202020.crl0

URLs in VB Code - #15

http://www.microsoft.com/pkiops/certs/Microsoft%20Identity%20Verification%20Root%20Certificate%20Authority%202020.crt0

URLs in VB Code - #16

http://www.microsoft.com/pkiops/crl/Microsoft%20Public%20RSA%20Timestamping%20CA%202020.crl0y

URLs in VB Code - #17

http://www.microsoft.com/pkiops/certs/Microsoft%20Public%20RSA%20Timestamping%20CA%202020.crt0

URLs in VB Code - #18

http://ocsp.digicert.com0

URLs in VB Code - #19

http://cacerts.digicert.com/DigiCertTrustedG4TimeStampingRSA4096SHA2562025CA1.crt0_

URLs in VB Code - #20

http://crl3.digicert.com/DigiCertTrustedG4TimeStampingRSA4096SHA2562025CA1.crl0

URLs in VB Code - #21

http://ocsp.digicert.com0A

URLs in VB Code - #22

http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C

URLs in VB Code - #23

http://crl3.digicert.com/DigiCertTrustedRootG4.crl0

URLs in VB Code - #24

http://ocsp.digicert.com0C

URLs in VB Code - #25

http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E

URLs in VB Code - #26

http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0

URLs in VB Code - #1

http://www.microsoft.com/pkiops/crl/Microsoft%20ID%20Verified%20CS%20AOC%20CA%2001.crl0

URLs in VB Code - #2

http://www.microsoft.com/pkiops/certs/Microsoft%20ID%20Verified%20CS%20AOC%20CA%2001.crt0

URLs in VB Code - #3

http://oneocsp.microsoft.com/ocsp0f

URLs in VB Code - #4

http://www.microsoft.com/pkiops/Docs/Repository.htm0

URLs in VB Code - #5

http://www.microsoft.com/pkiops/crl/Microsoft%20ID%20Verified%20Code%20Signing%20PCA%202021.crl0

URLs in VB Code - #6

http://www.microsoft.com/pkiops/certs/Microsoft%20ID%20Verified%20Code%20Signing%20PCA%202021.crt0

URLs in VB Code - #7

http://oneocsp.microsoft.com/ocsp0

URLs in VB Code - #8

http://www.microsoft.com/pkiops/crl/Microsoft%20Identity%20Verification%20Root%20Certificate%20Authority%202020.crl0

URLs in VB Code - #9

http://www.microsoft.com/pkiops/certs/Microsoft%20Identity%20Verification%20Root%20Certificate%20Authority%202020.crt0

URLs in VB Code - #10

http://www.microsoft.com/pkiops/crl/Microsoft%20Public%20RSA%20Timestamping%20CA%202020.crl0y

URLs in VB Code - #11

http://www.microsoft.com/pkiops/certs/Microsoft%20Public%20RSA%20Timestamping%20CA%202020.crt0

ae5f34e4f2d7050a30e55343616ae6ec (7.85 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙