Malicious
AutoIt Compiled Script
MD5:
Size: 0 B
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
| Config. Field | Value |
|---|---|
| Config. Key (RC4) | B3-A7-huhuhuhuhuhuhuhuhuhuhu |
| Domains | Wealthhuhuhuhuhuhuhuhuhuhuhu |
| Domains | wealthhuhuhuhuhuhuhu |
| Password | suhuhuhuhu |
| Host ID | sunshuhuhuhuhuhuhu |
| Mutex | -huhuhuhu |
| Install Path | %AppDahuhuhuhuhuhuhu |
| Startup Name | -huhuhuhu |
| ActiveX Key | -huhuhuhu |
| KeyLog Dir | %AppDahuhuhuhuhuhuhu |
| Copy executable | Thuhuhuhu |
| Delete original | Fhuhuhuhu |
| Lock executable | Fhuhuhuhu |
| Registry autorun | Fhuhuhuhu |
| ActiveX autorun | Fhuhuhuhu |
| Use a mutex | Fhuhuhuhu |
| Offline keylogger | Thuhuhuhu |
| Proxy Option | Direchuhuhuhuhuhuhu |
| other Option | 0huhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_e1bbfc0c.bin (3410 bytes) |