Static task
static1
Behavioral task
behavioral1
Sample
7289da5a1cc6d7149e862660a7f3f48db0ef1f6f8e5de991501e72bde1192be9.exe
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
7289da5a1cc6d7149e862660a7f3f48db0ef1f6f8e5de991501e72bde1192be9.exe
Resource
win10v2004-20240508-en
General
-
Target
786b7016ffc2a7f04d0a83e3666b8ed6.bin
-
Size
622KB
-
MD5
0092df9bfa72152a189d559f15ae86e4
-
SHA1
14686e4888dd9a23d6d8e33beaaddab3587c78d4
-
SHA256
8241da7a7aa6cac379ffb4852e7240778aef09a9e0afc1326184d0527479b20d
-
SHA512
3e8117e2774a2703158cbe101a3ff546733cbf547bd614529f75341caa90b4a7e352416a268a6b12eb891b02109429cb60d097489e8e5646dc50352e9a1d5d50
-
SSDEEP
12288:h58hzelKi5DitJdwIXZXLxAE/3QHZes7r0KD6G2RDzIq:shzaKi1osIxZ/uesP0jG2BIq
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource unpack001/7289da5a1cc6d7149e862660a7f3f48db0ef1f6f8e5de991501e72bde1192be9.exe
Files
-
786b7016ffc2a7f04d0a83e3666b8ed6.bin.zip
Password: infected
-
7289da5a1cc6d7149e862660a7f3f48db0ef1f6f8e5de991501e72bde1192be9.exe.exe windows:4 windows x86 arch:x86
Password: infected
f34d5f2d4577ed6d9ceec516c1f5a744
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
Imports
mscoree
_CorExeMain
Sections
.text Size: 682KB - Virtual size: 682KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1KB - Virtual size: 1KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ