Static task
static1
Behavioral task
behavioral1
Sample
e8c19e6aa4bc88269c931163aab5a898017d99815fe251a9c322c6ce97cc3f16.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral2
Sample
e8c19e6aa4bc88269c931163aab5a898017d99815fe251a9c322c6ce97cc3f16.exe
Resource
win11-20240508-en
General
-
Target
e8c19e6aa4bc88269c931163aab5a898017d99815fe251a9c322c6ce97cc3f16
-
Size
1.9MB
-
MD5
2f1f802934cacd8dd25e4ddc8e9f936b
-
SHA1
77b452018a448d78914e21945cc95c63380bac0a
-
SHA256
e8c19e6aa4bc88269c931163aab5a898017d99815fe251a9c322c6ce97cc3f16
-
SHA512
562294f15aa23ec54aff0c9d533b64487d25658e63f7038b799c4d34cb6e7727e770cf8ad7395c193c9e7b5c6e820850b2f7c044b01a73572e3efee31f2dd068
-
SSDEEP
49152:DloJr+0n4eBBu0JevC2VChbWR/qCiaX6zUIaACt:Jyr+0n4eThJOpghESHaX6SAM
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource e8c19e6aa4bc88269c931163aab5a898017d99815fe251a9c322c6ce97cc3f16
Files
-
e8c19e6aa4bc88269c931163aab5a898017d99815fe251a9c322c6ce97cc3f16.exe windows:6 windows x86 arch:x86
2eabe9054cad5152567f0699947a2c5b
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
Imports
kernel32
lstrcpy
Sections
Size: 183KB - Virtual size: 416KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 512B - Virtual size: 480B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.idata Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 512B - Virtual size: 2.7MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
fltimbbr Size: 1.7MB - Virtual size: 1.7MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
amtfcnho Size: 1024B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.taggant Size: 8KB - Virtual size: 12KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE