Static task
static1
Behavioral task
behavioral1
Sample
e7866278f3e0f3302b86a5d2ce20d66d3e9c3cd0512b5e58ff746aaa4e94c2d9.exe
Resource
win7-20231129-en
General
-
Target
e7866278f3e0f3302b86a5d2ce20d66d3e9c3cd0512b5e58ff746aaa4e94c2d9
-
Size
192KB
-
MD5
e42b290769cd57b224d3f48c3569f92a
-
SHA1
381d8d72cedfa6ae0e600715216f414259383f4a
-
SHA256
e7866278f3e0f3302b86a5d2ce20d66d3e9c3cd0512b5e58ff746aaa4e94c2d9
-
SHA512
b63923be00905450b364361763a2eb79264b31fb1d949bdfc2ddb4cb7b5d7a15f830e25be70b34ebc4de431796ce2e59d79a27918699176241eaadef1f0c555a
-
SSDEEP
3072:YhOmTsF93UYfwC6GIoutLmxHxae5yLpcgDE4JBuItR8pTsgnKbQFe3+37:Ycm4FmowdHoSLEaTBftapTsyFeO37
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource e7866278f3e0f3302b86a5d2ce20d66d3e9c3cd0512b5e58ff746aaa4e94c2d9
Files
-
e7866278f3e0f3302b86a5d2ce20d66d3e9c3cd0512b5e58ff746aaa4e94c2d9.exe windows:4 windows x86 arch:x86
Headers
File Characteristics
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_32BIT_MACHINE
Sections
.data Size: - Virtual size: 104KB
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 40KB - Virtual size: 44KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.data Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.reloc Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.text Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.idata Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.idata Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.text Size: 5KB - Virtual size: 8KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.rdata Size: 8KB - Virtual size: 8KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.idata Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ