Static task
static1
Behavioral task
behavioral1
Sample
fd56bfbe2b88d06ffe9cccb5a7e93464eb05ae0f9a86b33ed8d96146a968841b.exe
Resource
win7-20240221-en
Behavioral task
behavioral2
Sample
fd56bfbe2b88d06ffe9cccb5a7e93464eb05ae0f9a86b33ed8d96146a968841b.exe
Resource
win10v2004-20240426-en
General
-
Target
fd56bfbe2b88d06ffe9cccb5a7e93464eb05ae0f9a86b33ed8d96146a968841b
-
Size
921KB
-
MD5
72211d984aeafde3d7d93ac923850b7b
-
SHA1
4eed3f9013d9f3ac9eda675e4336fc04fb429b47
-
SHA256
fd56bfbe2b88d06ffe9cccb5a7e93464eb05ae0f9a86b33ed8d96146a968841b
-
SHA512
54b919899ebc6ea72c5dfb5d6ce4c5d6ba9afec3f1992025492b636013122138c84a90909f6333a944387c4e218f0beaa8a3db34e0e4899fb8f19a45074b1feb
-
SSDEEP
24576:VYoZk9otYrwgGYPBD2YpIpTGamTbB2mQyT1z69kQ5MSlAi:Vtk9oklbPBCYpcC3TbB2HeGjbii
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource fd56bfbe2b88d06ffe9cccb5a7e93464eb05ae0f9a86b33ed8d96146a968841b
Files
-
fd56bfbe2b88d06ffe9cccb5a7e93464eb05ae0f9a86b33ed8d96146a968841b.exe windows:5 windows x86 arch:x86
7e2f80e9e7c23c6ede591b9f6768a9e9
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
Imports
kernel32
GetModuleHandleA
user32
GetAltTabInfoW
advapi32
RegCloseKey
Sections
Size: - Virtual size: 23.7MB
IMAGE_SCN_MEM_READ
Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 38KB - Virtual size: 38KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Size: 93KB - Virtual size: 96KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE