Malicious
Malicious

c2196d395e1c4dd5764216936dc09384

PE Executable
|
MD5: c2196d395e1c4dd5764216936dc09384
|
Size: 4.09 MB
|
application/x-msdownload

Executable
PE (Portable Executable)
Win 32 Exe
x86
PDB Path
Obfuscated
VBScript Encoded
.Net Obfuscator
.Net Reactor
.Net
WScript.Shell
Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
c2196d395e1c4dd5764216936dc09384
Sha1
59ad7ca9e5d44fc6c86d8acbebe162ec777f6d1c
Sha256
b08e30edb0abe2ce72facff2c05ce3055499ca0ed8f607d49ad8f8681db9b3d2
Sha384
8ad4c7d6882aa9f9d26227ecbbcacfabbb3dddf6c08e6fe2693cf60f2620483a7aa1d27e55e614512c88d074ba4571d8
Sha512
09bb2d26119c52495105e057ff9abe42512de9ebba8b973be0c50271c6b0a1e4e29871b7fcf3ff38568544d847399d0c8d7affe93f6ec143755b17ce8b50d654
SSDeep
98304:yBVI6WScmLPp6YHwDc9g0XST3dcyXV2ElCn:aVIdaLPUDigL1G
TLSH
0A16F10275D28E33C2621B318597023D93A1D7223A52EF5B366F94C3A8177F29E761B3

PeID

Microsoft Visual C++ 6.0 DLL (Debug)
Microsoft Visual C++ 7.0 - 8.0
Microsoft Visual C++ 8
Microsoft Visual C++ 8
Microsoft Visual C++ v6.0 DLL
UPolyX 0.3 -> delikon
VC8 -> Microsoft Corporation
File Structure
c2196d395e1c4dd5764216936dc09384
Executable
PE (Portable Executable)
Win 32 Exe
x86
PDB Path
Obfuscated
VBScript Encoded
.Net Obfuscator
.Net Reactor
.Net
WScript.Shell
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.didat
.rsrc
.reloc
Resources
PNG
ID:0065
ID:1033
ID:1033-preview.png
ID:0066
ID:1033
ID:1033-preview.png
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
RT_DIALOG
ID:0000
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1033
RT_MANIFEST
ID:0001
ID:1033
c2196d395e1c4dd5764216936dc09384.decoded.vbs
Visual Basic
VBScript
VBScript Encoded
WScript.Shell
Malicious
Artefacts
Name
Value
PDB Path

D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb

c2196d395e1c4dd5764216936dc09384 (4.09 MB)
File Structure
c2196d395e1c4dd5764216936dc09384
Executable
PE (Portable Executable)
Win 32 Exe
x86
PDB Path
Obfuscated
VBScript Encoded
.Net Obfuscator
.Net Reactor
.Net
WScript.Shell
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.didat
.rsrc
.reloc
Resources
PNG
ID:0065
ID:1033
ID:1033-preview.png
ID:0066
ID:1033
ID:1033-preview.png
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
RT_DIALOG
ID:0000
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1033
RT_MANIFEST
ID:0001
ID:1033
c2196d395e1c4dd5764216936dc09384.decoded.vbs
Visual Basic
VBScript
VBScript Encoded
WScript.Shell
Malicious
Characteristics
No malware configuration were found at this point.
Artefacts
Name
Value Location
PDB Path

D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb

c2196d395e1c4dd5764216936dc09384

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙