Static task
static1
Behavioral task
behavioral1
Sample
002b58bda7d2d65ed215233729a43962f78f21afe901b29aa63c9fc33380f4f9.exe
Resource
win10v2004-20240226-en
Behavioral task
behavioral2
Sample
002b58bda7d2d65ed215233729a43962f78f21afe901b29aa63c9fc33380f4f9.exe
Resource
win11-20240508-en
General
-
Target
002b58bda7d2d65ed215233729a43962f78f21afe901b29aa63c9fc33380f4f9
-
Size
5.0MB
-
MD5
85d908a0d7969961e553fe6bab6e455e
-
SHA1
7b8d7182c6246f9878d23e9bcdfb272ebdad99dd
-
SHA256
002b58bda7d2d65ed215233729a43962f78f21afe901b29aa63c9fc33380f4f9
-
SHA512
22722d9cc8a20f0c040a02b20e943fb5bd6f22cf5a6fcc9a0cefa90e3a4cce9aadd9f3b3220598d4ac42d8bb309e80ef3fc7f681e2c9218b676ad1cfd01a0543
-
SSDEEP
98304:Cy1doHo7rsovSH7Y9PUo5lO8Miik9vQ7wN6O0/DHwiAdJPnrOluC7UQE07QhQx7:X1doIMovSH7Y9PlOavvstynrO8C7nE0t
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 002b58bda7d2d65ed215233729a43962f78f21afe901b29aa63c9fc33380f4f9
Files
-
002b58bda7d2d65ed215233729a43962f78f21afe901b29aa63c9fc33380f4f9.exe windows:1 windows x86 arch:x86
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
Sections
CODE Size: 37KB - Virtual size: 36KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
DATA Size: 1024B - Virtual size: 588B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
BSS Size: - Virtual size: 3KB
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.idata Size: 2KB - Virtual size: 2KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.tls Size: - Virtual size: 8B
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rdata Size: 512B - Virtual size: 24B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: - Virtual size: 2KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.rsrc Size: 11KB - Virtual size: 11KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ