H:\其他\git\Maplespe\ExplorerBlurMica\build\x64\Release\ExplorerBlurMica.pdb
Static task
static1
Behavioral task
behavioral1
Sample
ExplorerBlurMica/Release/ExplorerBlurMica.dll
Resource
win11-20240611-en
Behavioral task
behavioral2
Sample
ExplorerBlurMica/Release/register.cmd
Resource
win11-20240508-en
Behavioral task
behavioral3
Sample
ExplorerBlurMica/Release/uninstall.cmd
Resource
win11-20240611-en
General
-
Target
ExplorerBlurMica by VIN STAR.zip
-
Size
109KB
-
MD5
d5ed3990c539fcbadb86a4b740b57e68
-
SHA1
f48a4755accd7d87bfe742d9111c1c7d2ecac28d
-
SHA256
4f0afb62a9fdbb29421dd965640fbe4de1af3ac1206b2165fb3d54fffc1a95a5
-
SHA512
8a211555be77efdeeeee6b45ab384d45a680e9a3978967dc8bffde72f25313ba4d07cb898876b393d9ede6073899996b490e3bb96f3cb0de8e241d037852f622
-
SSDEEP
3072:MAO2RJcJmzn1DdPtq0ZpA78t+9CobJZkI5H/eWYxoTw:MAODYzVdDDTglbMg42w
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource unpack001/ExplorerBlurMica/Release/ExplorerBlurMica.dll
Files
-
ExplorerBlurMica by VIN STAR.zip.zip
-
ExplorerBlurMica/ReadMe.txt
-
ExplorerBlurMica/Release/ExplorerBlurMica.dll.dll regsvr32 windows:6 windows x64 arch:x64
ee68df415b04ab5147bea3989b43a4f9
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
Imports
kernel32
HeapAlloc
HeapDestroy
GetThreadContext
GetThreadId
GetCurrentProcessId
FlushInstructionCache
SetThreadContext
OpenThread
WriteConsoleW
HeapSize
SetStdHandle
GetConsoleMode
GetConsoleOutputCP
WriteFile
FlushFileBuffers
GetStringTypeW
GetProcessHeap
HeapReAlloc
GetEnvironmentStringsW
WideCharToMultiByte
MultiByteToWideChar
GetCommandLineW
GetCommandLineA
GetCPInfo
GetOEMCP
GetACP
IsValidCodePage
FindNextFileW
FindFirstFileExW
SetFilePointerEx
GetFileType
GetStdHandle
TerminateThread
LCMapStringW
CreateToolhelp32Snapshot
ResumeThread
SuspendThread
ReleaseMutex
CloseHandle
Thread32First
CreateMutexW
Thread32Next
HeapFree
VirtualProtect
HeapCreate
GetSystemInfo
VirtualAlloc
VirtualFree
GetCurrentThreadId
CompareStringOrdinal
VirtualQuery
GetProcAddress
CreateThread
LoadLibraryW
FreeEnvironmentStringsW
GetLastError
GetPrivateProfileStringW
CreateFileW
WaitForSingleObject
FindClose
GetCurrentProcess
SetLastError
GetFileSizeEx
FindFirstFileW
GetModuleHandleW
DisableThreadLibraryCalls
GetModuleHandleExW
ExitProcess
LoadLibraryExW
FreeLibrary
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
EncodePointer
InterlockedFlushSList
RaiseException
RtlPcToFileHeader
RtlUnwindEx
InitializeSListHead
GetStartupInfoW
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
CreateEventW
WaitForSingleObjectEx
ResetEvent
SetEvent
InitializeCriticalSectionAndSpinCount
FreeLibraryAndExitThread
GetModuleFileNameW
InitializeSRWLock
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
TryEnterCriticalSection
DeleteCriticalSection
QueryPerformanceCounter
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
GetSystemTimeAsFileTime
user32
ReleaseDC
SystemParametersInfoW
SystemParametersInfoForDpi
GetDesktopWindow
GetClassNameW
MonitorFromWindow
GetDC
EndPaint
BeginPaint
InvalidateRect
GetParent
MessageBoxW
GetSysColorBrush
DrawTextW
IsZoomed
GetSystemMetricsForDpi
SetWindowLongW
SetLayeredWindowAttributes
DrawTextExW
WindowFromDC
OffsetRect
SendMessageW
CreateWindowExW
FillRect
EnumChildWindows
GetDpiForWindow
DestroyWindow
GetWindowRect
GetWindowLongW
GetKeyState
gdi32
SetTextAlign
GetBkColor
SaveDC
SelectObject
GetBkMode
CreateCompatibleDC
PatBlt
GetTextCharacterExtra
GetStockObject
GetTextAlign
SetBkMode
GetObjectW
GetTextColor
SetBkColor
RestoreDC
GetCurrentObject
ExtTextOutW
SetTextCharacterExtra
IntersectClipRect
GetDeviceCaps
advapi32
RegCreateKeyExW
RegOpenKeyExW
RegCloseKey
RegDeleteKeyW
LookupPrivilegeValueW
AdjustTokenPrivileges
RegQueryValueExW
RegSetValueExW
OpenProcessToken
RegGetValueW
ole32
CoCreateInstance
gdiplus
GdipSetSmoothingMode
GdipDeletePath
GdipSetClipPath
GdipClosePathFigures
GdipDeleteBrush
GdipResetClip
GdipCreatePath
GdipCreateSolidFill
GdipFillPath
GdipSetSolidFillColor
GdipCreateFromHDC
GdipFillRectangleI
GdipAddPathArc
GdipDeleteGraphics
GdipAddPathLine
GdiplusStartup
GdiplusShutdown
uxtheme
DrawThemeTextEx
BeginBufferedPaint
EndBufferedPaint
DrawThemeText
DrawThemeBackground
GetThemeColor
ord47
dwmapi
DwmFlush
DwmEnableBlurBehindWindow
DwmGetWindowAttribute
DwmExtendFrameIntoClientArea
DwmSetWindowAttribute
comctl32
ord410
ord413
Exports
Exports
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer
Sections
.text Size: 131KB - Virtual size: 130KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rdata Size: 62KB - Virtual size: 62KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.data Size: 6KB - Virtual size: 11KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.pdata Size: 8KB - Virtual size: 8KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
_RDATA Size: 512B - Virtual size: 348B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.rsrc Size: 1KB - Virtual size: 1KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 2KB - Virtual size: 2KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
ExplorerBlurMica/Release/config.ini
-
ExplorerBlurMica/Release/register.cmd
-
ExplorerBlurMica/Release/uninstall.cmd