Hostile 100% pe-machine-learning-dataset Download

25070

Packed, embedded PE, downloads files

Unsigned elevated loader validates an embedded PE and downloads a payloadEntry point in a writable RWX section
SHA-25652ac77272d3a2f19de2bcdff86ff2be4d5c173c07b22aff4837735a77de2e224

Evidence

Inline PE header walk sequence 0x1f2f–0x20af
⋯7 more rows
0x1f9f832600ff151c5040006681384d5a7514.&[email protected].
0x1faf8b483c85c9740d03c18a481a880e8a40.H<..t....H....@
0x1fbf1b8846015ec3558becb82c120000e85e..F.^.U...,....^
⋯15 more rows
Dynamic library loading via LoadLibraryA 0x4fcc–0x511c
⋯3 more rows
0x4ffc00000000445500005a55000070550000....DU..ZU..pU..
0x500c7e55000090550000a655000044580000~U...U...U..DX..
0x501ce2550000f6550000085600001a560000.U...U...V...V..
0x502c2856000036560000425600004c560000(V..6V..BV..LV..
0x503c585600006c560000805600009c560000XV..lV...V...V..
0x504cb6560000d0560000e6560000fe560000.V...V...V...V..
0x505c185700002a5700003a57000048570000.W..*W..:W..HW..
0x506c6257000072570000805700008e570000bW..rW...W...W..
0x507c9c570000a8570000b4570000c0570000.W...W...W...W..
0x508cd6570000e6570000f657000008580000.W...W...W...X..
0x509c1a580000265800003658000056580000.X..&X..6X..VX..
0x50ac00000000ca55000000000000ffffffff.....U..........
⋯7 more rows
Writable and exe section (W^X violation) 0x9fa0–0xa0e0
⋯5 more rows
0x9ff0494e47585850414444494e4750414444INGXXPADDINGPADD
0xa000558bec81ec880000008365ec008365b0U.........e...e.
0xa010008365e0008365f0008365fc00c745c4..e...e...e...E.
0xa020433a5c34c745c837383433c745cc6663C:\4.E.7843.E.fc
0xa030632ec745d065786500e8000000005805c..E.exe......X.
0xa0409b0200008945e864a1300000008945d8.....E.d.0....E.
0xa0508b45e8c70083c404e98b45d88b400c8b.E........E..@..
0xa060401c8b008945e48b45e48b40088945f4@[email protected].
0xa0708b45f48b403c8b4df48b55f403540178.E..@<.M..U..T.x
⋯7 more rows
Embedded PE binary at file offset 0xa2e1 (~15647 bytes) 0xa24c–0xa40c
⋯3 more rows
0xa27c78fffffff40100007d3d8b857cffffffx.......}=..|...
0xa28c81384d5a900075206a008d45f8506800.8MZ..u j..E.Ph.
0xa29c3c0000ffb57cffffffff75c0ff55e0c7<....|....u..U..
0xa2ac458001000000eb0f8b857cffffff4089E.........|...@.
0xa2bc857cffffffebaaff75c0ff55f0837d80.|......u..U..}.
0xa2cc0175096a058d45c450ff55fcc9c3cc3f.u.j..E.P.U....?
0xa2dc84cc3f84474d5a900003000000040000..?.GMZ.........
0xa2ec00ffff0000b800000000000000400000.............@..
0xa2fc00000000000000000000000000000000................
0xa30c00000000000000000000000000000000................
0xa31c00e80000000e1fba0e00b409cd21b801.............!..
⋯15 more rows
URLDownloadToFile named, not imported 0xdd4c–0xde9c
⋯3 more rows
0xdd7c646c6c0073686c776170692e646c6c00dll.shlwapi.dll.
0xdd8c75726c6d6f6e2e646c6c007573657233urlmon.dll.user3
0xdd9c322e646c6c007368656c6c33322e646c2.dll.shell32.dl
⋯3 more rows
0xdddc594150415849405a0000005061746846[email protected]
0xddec696c654578697374734100000055524cileExistsA...URL
0xddfc446f776e6c6f6164546f46696c654100DownloadToFileA.
0xde0c000077737072696e7466410000005368..wsprintfA...Sh
0xde1c656c6c45786563757465410000000000ellExecuteA.....
0xde2c00000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.