Malicious
bf6a83c1d0500ae0f58c3fcb1cea8463
AutoIt Compiled Script | MD5: bf6a83c1d0500ae0f58c3fcb1cea8463 | Size: 728.06 KB | application/x-dosexec
AutoIt Compiled Script
MD5: bf6a83c1d0500ae0f58c3fcb1cea8463
Size: 728.06 KB
application/x-dosexec
Infection Chain
Summary by MalvaGPT
Characteristics
|
Hash | Hash Value |
|---|---|
| MD5 | bf6a83c1d0500ae0f58c3fcb1cea8463
|
| Sha1 | 903400f69ad5cc1f797d940aea452e4930098700
|
| Sha256 | 3725b84aa81f643a91d085c07db5c804995689c4d603e2e83ae83910c0f32ded
|
| Sha384 | 802a516d0d6a911814465d4798c1d5155f6bf7a8b4e54fa4a2f5ba90de16367fe7436b7b8cb9b5ef2dc2af2822bf16ec
|
| Sha512 | 2e416fafd7309798a3ba52a3932159c0f07d1757636b2c3d5a2bd42b552516bb8ec610e01ade168e268fb6bfa79ea236ea239fb26e120e2b581ad205442fb633
|
| SSDeep | 12288:/z7hU5I5yuNHIgzSFKxWltRohBfSTso93UVTcApp9Mz6LgkhILYx3UvuTP2acF6:/f+iN57Gtene3OALggkQvvcP2acQ
|
| TLSH | E1F4239465C16994C0946370D827CCA94E383CF09E25A73A472DEBAF3C713D3AB5AB1D
|
PeID
Microsoft Visual C++ v6.0 DLL
Packer=UPX Compresor..Gratuito... www.upx.sourceforge.net
UPX -> www.upx.sourceforge.net
UPX Modified >> *$igBy Ahmed18
UPX v0.89.6 - v1.02 / v1.05 -v1.24 -> Markus & Laszlo (overlay)]
UPX v1.25 (Delphi) Stub
UPX v3.0
File Structure
bf6a83c1d0500ae0f58c3fcb1cea8463
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
UPX0
UPX1
.rsrc
Resources
RT_ICON
ID:0001
ID:2057
ID:0002
ID:2057
ID:0003
ID:2057
ID:0004
ID:2057
ID:0005
ID:2057
ID:0006
ID:2057
ID:0007
ID:2057
ID:0008
ID:2057
ID:0009
ID:2057
ID:000A
ID:2057
ID:000B
ID:2057
RT_MENU
ID:00A6
ID:2057
RT_RCDATA
ID:0000
RT_GROUP_CURSOR4
ID:0063
ID:2057
ID:00A2
ID:2057
ID:00A4
ID:2057
ID:00A9
ID:2057
RT_VERSION
ID:0001
ID:2057
RT_MANIFEST
ID:0001
ID:2057
Informations
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
bf6a83c1d0500ae0f58c3fcb1cea8463 (728.06 KB)
File Structure
bf6a83c1d0500ae0f58c3fcb1cea8463
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
UPX0
UPX1
.rsrc
Resources
RT_ICON
ID:0001
ID:2057
ID:0002
ID:2057
ID:0003
ID:2057
ID:0004
ID:2057
ID:0005
ID:2057
ID:0006
ID:2057
ID:0007
ID:2057
ID:0008
ID:2057
ID:0009
ID:2057
ID:000A
ID:2057
ID:000B
ID:2057
RT_MENU
ID:00A6
ID:2057
RT_RCDATA
ID:0000
RT_GROUP_CURSOR4
ID:0063
ID:2057
ID:00A2
ID:2057
ID:00A4
ID:2057
ID:00A9
ID:2057
RT_VERSION
ID:0001
ID:2057
RT_MANIFEST
ID:0001
ID:2057
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.