Static task
static1
Behavioral task
behavioral1
Sample
d91fd9f5423638d94aa778e9baa4d5db6d5775995f162d0653b6b0af005d10dc.exe
Resource
win10v2004-20240226-en
Behavioral task
behavioral2
Sample
d91fd9f5423638d94aa778e9baa4d5db6d5775995f162d0653b6b0af005d10dc.exe
Resource
win11-20240508-en
General
-
Target
d91fd9f5423638d94aa778e9baa4d5db6d5775995f162d0653b6b0af005d10dc
-
Size
5.2MB
-
MD5
f81c2a703c9fec6f1454a2bd698d7777
-
SHA1
1b6557009e9a306b18c5ea38f826d08234940863
-
SHA256
d91fd9f5423638d94aa778e9baa4d5db6d5775995f162d0653b6b0af005d10dc
-
SHA512
71f7856cb53d6c11dad667f5e02371c592685a0151dff252ca943e19568a28b71f18e104d2e4427f50005dc6cf2aeaba36e5a7e9f20033a4e1f91412483a5795
-
SSDEEP
98304:C0pJQEKX0H6wM19P8KUoHJ+fKSIsTf2lEDwnKWHHbxv8G9VHCdnQx7:rJ5NI18voUffTf2lvKWHdEG9AQt
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource d91fd9f5423638d94aa778e9baa4d5db6d5775995f162d0653b6b0af005d10dc
Files
-
d91fd9f5423638d94aa778e9baa4d5db6d5775995f162d0653b6b0af005d10dc.exe windows:1 windows x86 arch:x86
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
Sections
CODE Size: 37KB - Virtual size: 36KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
DATA Size: 1024B - Virtual size: 588B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
BSS Size: - Virtual size: 3KB
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.idata Size: 2KB - Virtual size: 2KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.tls Size: - Virtual size: 8B
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rdata Size: 512B - Virtual size: 24B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: - Virtual size: 2KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.rsrc Size: 11KB - Virtual size: 11KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ