Static task
static1
Behavioral task
behavioral1
Sample
68c00e3bb99dd666c421c6fd6b384ff5641ead666c44936d8e84a9075ff79819.exe
Resource
win7-20240508-en
General
-
Target
a562c59e3a4d9be348d5581d23e483db.bin
-
Size
1.8MB
-
MD5
15e2efe3b891bc41ea22aa9c030aa5e6
-
SHA1
d23b3a3179a8a84c0a93f7661d45772385be3315
-
SHA256
3ce55a749963b0ebce87b5ac9d81e5b2c92e8253db8faee50f071e9eb2a5ddb3
-
SHA512
730ae88eb0a5fa7a93601976945c88d965a94b6d0cda6407ea26870f43a783dab1277000f976b4c2963b363516dda1c3715303f997e83774dcfc1753011aa3b0
-
SSDEEP
49152:sdcKPwdlWPD9t+eGl7yBZ42y86XaF9f9hFWSdw06B:sdcKPwdlEoeHBZI8LF912Sk
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource unpack001/68c00e3bb99dd666c421c6fd6b384ff5641ead666c44936d8e84a9075ff79819.exe
Files
-
a562c59e3a4d9be348d5581d23e483db.bin.zip
Password: infected
-
68c00e3bb99dd666c421c6fd6b384ff5641ead666c44936d8e84a9075ff79819.exe.exe windows:6 windows x86 arch:x86
Password: infected
2eabe9054cad5152567f0699947a2c5b
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
Imports
kernel32
lstrcpy
Sections
Size: 183KB - Virtual size: 416KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 512B - Virtual size: 480B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.idata Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 512B - Virtual size: 2.7MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
vmjyxrbh Size: 1.6MB - Virtual size: 1.6MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
bxjwqywv Size: 1024B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.taggant Size: 8KB - Virtual size: 12KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE