Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5:
Size: 0 B
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12tElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_0a9916e9.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
CUSTOM
ID:0087
ID:0
ID:0088
[Authenticode]_e4177044.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:2052
ZIPRES
ID:0085
img
-down.png
-down.png-preview.png
-hover.png
-hover.png-preview.png
-normal.png
-normal.png-preview.png
bkg
default
bkg1.png-preview.png
bkg2.png-preview.png
bkg3.png-preview.png
combo-lang-hot.png
combo-lang-hot.png-preview.png
combo-lang-normal.png
combo-lang-normal.png-preview.png
logo.png-preview.png
msgbox_info.png
msgbox_info.png-preview.png
opt-hover.png
opt-hover.png-preview.png
opt-normal.png
opt-normal.png-preview.png
opt-selected-hover.png
opt-selected-hover.png-preview.png
opt-selected-normal.png
opt-selected-normal.png-preview.png
process_light.png
process_light.png-preview.png
x-down.png
x-down.png-preview.png
x-hover.png
x-hover.png-preview.png
x-normal.png
x-normal.png-preview.png
messagebox.xml
tgbdownloader.xml
RT_ICON
ID:0001
ID:0
RT_MENU
ID:006D
ID:2052
RT_STRING
ID:0007
ID:2052
RT_GROUP_CURSOR4
ID:006B
ID:0
RT_VERSION
ID:0001
ID:2052
RT_MANIFEST
ID:0001
ID:1033
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x2ED400 size 10888 bytes
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #4 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #5 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #6 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #7 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #8 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #9 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #10 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #11 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #12 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #13 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #14 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #15 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #16 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #17 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #18 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #19 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #20 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #21 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #22 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #23 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #24 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #25 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #26 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #27 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #28 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #29 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #30 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #31 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #32 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #33 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #34 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #35 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #36 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #37 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙