Static task
static1
General
-
Target
0dbea9ae994a846cdbbac5ac4c2edd99c0943d729ae79c0c6295ff05edd31058
-
Size
1.8MB
-
MD5
14a42aaee72769ed4ee724667de1b199
-
SHA1
858fc48ede89dd5938c82707b2fc17276792f009
-
SHA256
0dbea9ae994a846cdbbac5ac4c2edd99c0943d729ae79c0c6295ff05edd31058
-
SHA512
4d5b334e2b843b006b6a20bcf7a2f7b8cea8fb7361777a851d017e021f53e71d872d58c7f2c9532cca16a7f1eeacd0a440a5d7a1ed237261fc8666b21ffed612
-
SSDEEP
49152:1l3LMlER7zqGd9NB9cNyTWUyx75lcvAs3Qrm:L3wszhlcNyTWbltrm
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 0dbea9ae994a846cdbbac5ac4c2edd99c0943d729ae79c0c6295ff05edd31058
Files
-
0dbea9ae994a846cdbbac5ac4c2edd99c0943d729ae79c0c6295ff05edd31058.exe windows:6 windows x86 arch:x86
2eabe9054cad5152567f0699947a2c5b
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
Imports
kernel32
lstrcpy
Sections
Size: 183KB - Virtual size: 416KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 512B - Virtual size: 480B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.idata Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 512B - Virtual size: 2.7MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
wubqzqsc Size: 1.6MB - Virtual size: 1.6MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
expdgshr Size: 1024B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.taggant Size: 8KB - Virtual size: 12KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE