General

  • Target

    w(1).rar

  • Size

    4.4MB

  • MD5

    de4585713a9369206bbe2d63339fdce3

  • SHA1

    0e533e5e1e476b0e454b2a334b8c4475f4defa3a

  • SHA256

    2038d335e18e3621f07b054f611a8042a89dae7621248c4db5048c414fbcc19a

  • SHA512

    35ab5421b31a5b751347347bddfe8cbf30e6333736c38afa02e757f66a4918d6ccbcac0c0404aae12ac33667e0202a794c3cff99897f44075e58cc58d5dfc6bb

  • SSDEEP

    98304:BvAOO00i7P59Xzt2nevBH+IykRrZseietjLwC:BoO3jP59XztTTsoPwC

Score
7/10

Malware Config

Signatures

  • Themida packer 1 IoCs

    Detects Themida, an advanced Windows software protection system.

  • Unsigned PE 6 IoCs

    Checks for missing Authenticode signature.

Files

  • w(1).rar
    .rar
  • w/Glix.exe
    .exe windows:6 windows x64 arch:x64


    Headers

    Sections

  • w/cpr.dll
    .dll windows:6 windows x64 arch:x64

    09b3a2c15941eabf784ea161dc2e56ed


    Headers

    Imports

    Exports

    Sections

  • w/libcurl.dll
    .dll windows:6 windows x64 arch:x64

    9a4ddbe07217dde8376bb7c577388155


    Headers

    Imports

    Exports

    Sections

  • w/xxhash.dll
    .dll windows:6 windows x64 arch:x64

    fba6b233846a2ea5e6907e23b2de9a26


    Headers

    Imports

    Exports

    Sections

  • w/zlib1.dll
    .dll windows:6 windows x64 arch:x64

    d879d2294039900ef484e0f01607f882


    Headers

    Imports

    Exports

    Sections

  • w/zstd.dll
    .dll windows:6 windows x64 arch:x64

    163b42376483ef4dde972117fa0042a2


    Headers

    Imports

    Exports

    Sections