.�>��KY�J�YE�4B�D�ײ�@јA� �-���mQ��9� "�ax�VF��H�;��*����a{�a��|���g�����9���9|����Sd`ê4Ym®/���OM]*�E-��D�,v��V�}�"Q�&QƹȈt��=��&�~��l�f�~e�lm�� G6�;Ҭ��+:M4Ѵ��t�Kj q�ᆰ��~]��H,�e��憃�l�r��qw���qT�D��j֑�Q�A���p.GL�!'� $���n)�6r$�E� �Ad?8�g'�>D�[�b �W���}?WEѡ#_�^��nC��/�X�Յ�����"�I��{xCO�����A��ELa���2j��7���jƅ�8��V����Ư��-K���MQ���5���K��P)N@�$�oR���r�ͫ�|�� �#n���ED/3a�������d��{�k�z*_�k!���I/gF��S�Ū$���.Oy]~�= �؛4�-)~_�ɂF_x,Z>�,��g�U�W�(`lU;��6�R�]?���qf�kkM���0ee�l��q�!:&�u�W�/y8�X���)���U�{���K4����f�q&���ڄ�uq�@��Y�G0�8n-٩C/�Eҩ���;���������IR8j������`�ݭ`_84����˯\���^��4b��V�W��@=}j�F7�rw�����22>�Ԟ����%r��s��&�@^� �����B^��9s�ʵ����g_���ʃ\��G<k4z��>#��5��C7�NR���H�����l��!�`��i]�<�8�]洟�G#}���9�0��� �����E�0�� �XA��}:p�O���:�&�1��rO�}b��ީ���z�kD F��f�Z��_!��Վ����6����_c���c���7v�[�\�g��U�B0TbzU�j !_ 8y��m-c���28&V����a��-����i��9X�aru\GF\c-�4Z!��V~4\�@�H�#�O6�z��Q�ha���40~��1v4Qt�.I��l���vIX��u���� � H�=�F��>CBZ�w�Gqh�3<���W�>e��M�\�ʇ0_�9��fۻe��g�y^i������g��������~E�q��gt~F�{���G�=�NM�S���-XFY/4v*�^��^ ʟ�0[k��B�8��r��R��;�<��!�y����:�� <�H}� 'J�/� J�h���1�.��Y�oY�3�b�S�w���C�� �]�������s)b�Hb�R�ÈY�H�)N�!����ѩ���-�TX��s)l�19i��-��������%x�c�X�9>��t+lP��Xo�^i28��e�M�d��$9>�j�%���J����N�ٴ<�l���vK���ò��'g�yJ�v���4�HO$��~���3�l�c>lw��=ҍ�w*��E_8�nq�������uD��"�O�t���G�;�^��M}���_Pel�\5�E�����k3y"��c��*�d;�}�F�5v��]��7����V��B������T��Vy������_ՠ���-��y2t���C����y�����;G��}��*�{�C �(2�TW���� ]!���os�?��� ��R��]w�Ɉ��,��W��qa`M�p�U�A��G$�����)L��MeX��:XZ�I�-�-���㼊�p�[>��Җs����KK��ʙ(3nXk5��]7����[�N����t�EA�<�riZ�#� ��m�.�+NL�����S.� �6x��dx0�WhB��mH�-� ׄ?�����:��w��Qm���F;,">j��Ҿtբ���� Ԇ��`��9���.F����Þ���p�����WA&k�����T /`Aūgo2W��I�3�խ�.�LA�ʑ���C���y�EE�yGtI�S�6i�z��$�]!�<Ք�+�1$te�{�}��6�v?�i-�3�������4�s��|��"� ^ɒp[d� � ��rf��z��ځ��o��Ǐ�: �-mB$:����b�F�A�(O���g0D�t��<�OklY �\m��<��t�{��蜿ʝ�o�L����))�E����5u:��Aа�ܡo�'|s�SO��q�@����S��J�e�yЭ�� [�j�p���mx�: tOY��{/��̊6�D�uX���P�%W��`D����B49�������5R<k�L� ꜰ�Z��R�&*#��;G�s3Y�ѻ���3�mN�D���is�0��������<���[XS*�"�fI��s:1)(��8*������s@���\N1�3��� �Dj�Z��$/�m��,T��f�S�ˉ)@���'� ^ �0;��[d: )/8%}��g��_�����$���J�1�g"95�~��VX�ԑ9�� �2���. 0 �������L��� ��Kk ��cSʘ0�'_�Ku�&x&^{����O� '���F�ř����J����_���J��E��}��OL�����I�/�|��Thu�v����q��S,W�*U�K��TD8������a7mCq"#]��3��/E[VL l ��np�.J[�z\��>Ve����o�pP�4nv2�i��քP���b3�o@~b]T��{��E���5�(Xڗ)ZJ�s�DV��]��0��W�vqhb)��c��\��«�5Y����Ԋ�B�]f�x0�������t��&_,6���I?�d��@���[�ZMu�FzJY�jf��=ix�[�M����ix��]=x:��+|h��!����|�U�d���T���k�ߢ$��L�K�/�ݖ�YyW�v�������{�m٦��U��0�g�o�'5��)�}8�I�������8O6�ַI�H�=���z��h^�`��dFڻR�~1�������B�]�E�f�/\�8��8��� ؗfBY��Wpw�Jԇ��D���f��;����"}Ԭ/��z�SQd�z���G�@�e�/�XY-Q���@�\����M�p��|�|���\�#d��� lp���Q�`�S7��D�\{ ~��df7��8N��'�S�-NB3En���\�\���h����<�����3XM<h�p�>m`e��J&)�2hC(���^>�pz�h�T���?W7I�hU�P}\�Yhd�+��Sׁ���ӓ�#�*J�H����m;�Z���gP\f�^�昁=ΰ�m� C}�O%��Ő�����`1Md��+(�%L�¿z�"�Q�"j��rfX�O:��"M����yqq:"���-ηտP�vMY>+x9��I�!ڍ���ޤSF�ިB��6�����:/�>#,~�0�@����^O-�'�SyC���ՊAE��`Ǣu�d?���|U�5��63�� �|�j�
Static task
static1
Behavioral task
behavioral1
Sample
773e8af03da6e64f25166e7df67d71fe.exe
Resource
win7-20240419-en
General
-
Target
773e8af03da6e64f25166e7df67d71fe.exe
-
Size
2.4MB
-
MD5
773e8af03da6e64f25166e7df67d71fe
-
SHA1
db43e8714ce1c8d496e0eef1f9f61fafa5dfa0ad
-
SHA256
03b6b9b10aad113cb8e9bd43d0ed189dde70170e6141aa2bd3cbec5644e7553e
-
SHA512
70bb1a7bf085b4373d06db5f1fe8acd011d5fac4d0c3f631b2d2ec7ba355cd05127b21eab290de500c09326674948a8b788eb49eb1ce21d1f58e53c3f22fafe6
-
SSDEEP
49152:InkYmh7/egM/WXtzFAmlR0yIwsMa720naH3QqN2zw0XTUzQaQo6Az99ZP:InkvZmgCeM8KTN60aH3QqN2z5XUQawAB
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 773e8af03da6e64f25166e7df67d71fe.exe
Files
-
773e8af03da6e64f25166e7df67d71fe.exe.exe windows:5 windows x86 arch:x86
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
Exports
Exports
Sections
Size: 41KB - Virtual size: 108KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 16KB - Virtual size: 32KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 1024B - Virtual size: 2.1MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 8KB - Virtual size: 20KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 202KB - Virtual size: 7.5MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.data Size: 2.1MB - Virtual size: 2.1MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE