Static task
static1
Behavioral task
behavioral1
Sample
30b0558f61fa81460d68330a85678ff074c6a2c677de752ee08613278a44e09b.exe
Resource
win10v2004-20240508-en
General
-
Target
30b0558f61fa81460d68330a85678ff074c6a2c677de752ee08613278a44e09b
-
Size
1.9MB
-
MD5
c5a2b473dd3eb8b285c5812cf84d6029
-
SHA1
f8316c64920b219f062b59631f9fd53dfedd15ae
-
SHA256
30b0558f61fa81460d68330a85678ff074c6a2c677de752ee08613278a44e09b
-
SHA512
4c5cf64c08f120618cf513fdc1c7bad78c2be0a768b29abf6953913fe86b0627b04b5bec6c5042958ed73d468b464ec4f764e1fe04fcbad7e57863577c201fb8
-
SSDEEP
49152:UuIbSNDTWDjrvcedxto4uzAUHi5AIc9FS:UVSRMrIzzAUi7s
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 30b0558f61fa81460d68330a85678ff074c6a2c677de752ee08613278a44e09b
Files
-
30b0558f61fa81460d68330a85678ff074c6a2c677de752ee08613278a44e09b.exe windows:6 windows x86 arch:x86
2eabe9054cad5152567f0699947a2c5b
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
Imports
kernel32
lstrcpy
Sections
Size: 183KB - Virtual size: 416KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 512B - Virtual size: 480B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.idata Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 512B - Virtual size: 2.7MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
zmlukjfy Size: 1.7MB - Virtual size: 1.7MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
exayxkiu Size: 1024B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.taggant Size: 8KB - Virtual size: 12KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE