Suspicious
Suspect

f8b76bff833bf76d071006011c3779dc

AutoIt Compiled Script
|
MD5: f8b76bff833bf76d071006011c3779dc
|
Size: 4.19 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
f8b76bff833bf76d071006011c3779dc
Sha1
154d76d5109623208d728c170c126e2e3db906fe
Sha256
7696b0fa0d7e2199c486c54f8fd6334248ba50f024e160179a1f03648d580a2a
Sha384
7589812a09a654cea1f3eb6ea33b891f76bf790eedafba94392c78d6995d8dffbf16e942bfa638eb7fac63e7a32ae667
Sha512
211e163affe0df4cd45141cb59dfaaea41e254799c496c9fb6890d9996e8af6e4ea189382bf4d9e36539b41c8578c0b9839e3a2ac4f1315549b27d61f297e6ed
SSDeep
24576:pdtoOMQqLew0gkrRV47BwR0Dz42IYS+5waSPTJqKp12cDKDo8VxFZqVkejf9:1oOPqaLgkrRV49wqOh4SbE20xFgyiF
TLSH
0316D0B5B93852E3DD88326D01A117CF837671402B309A0AB6C74496FFB26BD57B887D

PeID

Microsoft Visual C++ 8
File Structure
Overlay_c85a3592.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.rsrc
.reloc
Resources
AVI
ID:0BB9
ID:1033
RT_ICON
ID:0001
ID:1033
RT_DIALOG
ID:07D1
ID:1033
ID:07D2
ID:1033
ID:07D3
ID:1033
ID:07D4
ID:1033
ID:07D5
ID:1033
ID:07D6
ID:1033
RT_STRING
ID:003F
ID:1033
ID:004C
ID:1033
ID:004D
ID:1033
ID:0050
ID:1033
ID:0053
ID:1033
ID:0055
ID:1033
RT_RCDATA
ID:0000
ID:1033
RT_GROUP_CURSOR4
ID:0BB8
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Concert.vsdm
Retrieved.vsdm
Should.vsdm
Performing.vsdm
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Overlay extracted: Overlay_c85a3592.bin (2639897 bytes)

Info

PDB Path: wextract.pdb

f8b76bff833bf76d071006011c3779dc (4.19 MB)
File Structure
Overlay_c85a3592.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.idata
.rsrc
.reloc
Resources
AVI
ID:0BB9
ID:1033
RT_ICON
ID:0001
ID:1033
RT_DIALOG
ID:07D1
ID:1033
ID:07D2
ID:1033
ID:07D3
ID:1033
ID:07D4
ID:1033
ID:07D5
ID:1033
ID:07D6
ID:1033
RT_STRING
ID:003F
ID:1033
ID:004C
ID:1033
ID:004D
ID:1033
ID:0050
ID:1033
ID:0053
ID:1033
ID:0055
ID:1033
RT_RCDATA
ID:0000
ID:1033
RT_GROUP_CURSOR4
ID:0BB8
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Concert.vsdm
Retrieved.vsdm
Should.vsdm
Performing.vsdm
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙