Static task
static1
Behavioral task
behavioral1
Sample
f3c462280fd1964d68c76ff6889bd3c766fa7140c07962dda32c0cb488188695.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
f3c462280fd1964d68c76ff6889bd3c766fa7140c07962dda32c0cb488188695.exe
Resource
win10v2004-20240508-en
General
-
Target
a4052a6663acc950f95ea27ecf872887f640b99ede1eabf6cf4fbf495623c9c9
-
Size
484KB
-
MD5
2941b1d5ed9dcdf79878bdda9409dd39
-
SHA1
675e88dc2ea5af96919406651c7da7cac2c18f70
-
SHA256
a4052a6663acc950f95ea27ecf872887f640b99ede1eabf6cf4fbf495623c9c9
-
SHA512
f77d5849d48dc16e7fdb0400ceb5b7e173fd6095e998ea8b8d278da515b197b67430724210df3c8dd0cdcfcaed10c4091760388a234deab20c480c4a8e210936
-
SSDEEP
12288:KrNyIqNSIW7+kZbmt1pgUUCNo/mgPyYiGHLRkRqDC:KxyFXAZmt15NoAYlH4Z
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource unpack001/f3c462280fd1964d68c76ff6889bd3c766fa7140c07962dda32c0cb488188695.exe
Files
-
a4052a6663acc950f95ea27ecf872887f640b99ede1eabf6cf4fbf495623c9c9.zip
Password: infected
-
f3c462280fd1964d68c76ff6889bd3c766fa7140c07962dda32c0cb488188695.exe.exe windows:4 windows x64 arch:x64
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
Sections
.text Size: 13KB - Virtual size: 12KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 2KB - Virtual size: 2KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ