Hostile 92% Download

Trojan.Win32.VB.edp

Packed trojan masquerading as IE detect

Unsigned PE writable entry with multiple RWX sectionsInflated reloc with writable entry and high code entropy
SHA-25663b3043257752c02f9f4f181465d6db6b8e9adade32d64e5cffbd6eb828b3a7c

Evidence

PE directories in mismatched sections 0x0–0x120
0x04d5a90000300000004000000ffff0000MZ..............
0x10b8000000000000004000000000000000........@.......
0x2000000000000000000000000000000000................
0x30000000000000000000000000c8000000................
⋯15 more rows
Writable .text section 0x380–0x630
⋯7 more rows
0x3f000000000000000000000000000000000................
0x400d8dc0000879c00003d2b000002000400........=+......
0x410006ffdffdb39cbdbb0752c4cf1f04c6f.o...9...u,L..Lo
0x4207d1914e044738675c3aa574e52346967}...Ds.u..WNR4ig
0x43010fb985ea0ba3c041fd88bee47c98a52...^..<.....G..R
⋯32 more rows
PECompact SEH exception trick 0x100d–0x10fd
⋯3 more rows
0x103de3192ede1de7469859f235b870fa0011......F.Y.5.p...
0x104d5064ff35000000006489250000000033Pd.5....d.%....3
0x105dc089085045436f6d7061637432002f42...PECompact2./B
0x106d2fd62a834e645a7c621956c159357fb2/.*.NdZ|b.V.Y5..
0x107d7c9ae6a8eff1562ff3161ca7d715e7b5|.....V/........
0x108da6ef3b0b36edf141f5e150d3e15740e9..;.6..A..P..W@.
⋯7 more rows
PE version metadata includes CompanyName 0x38d2–0x3a22
⋯7 more rows
0x39426f006e0065006e007400000000004c00o.n.e.n.t.....L.
0x39522c00010043006f006d00700061006e00,...C.o.m.p.a.n.
0x396279004e0061006d006500000000004d00y.N.a.m.e.....M.
0x39726900630072006f0073006f0066007400i.c.r.o.s.o.f.t.
0x3982200043006f00720070006f0072006100 .C.o.r.p.o.r.a.
0x3992740069006f006e000000600038000100t.i.o.n...`.8...
0x39a2460069006c0065004400650073006300F.i.l.e.D.e.s.c.
0x39b2720069007000740069006f006e000000r.i.p.t.i.o.n...
⋯7 more rows
PE version metadata includes FileVersion 0x3b26–0x3c76
⋯3 more rows
0x3b56740065006d0000000000380018000100t.e.m.....8.....
0x3b66460069006c0065005600650072007300F.i.l.e.V.e.r.s.
0x3b7669006f006e000000000036002e003200i.o.n.....6...2.
0x3b863800300030002e0031003100300036008.0.0...1.1.0.6.
0x3b9600003c0018000100500072006f006400..<.....P.r.o.d.
0x3ba675006300740056006500720073006900u.c.t.V.e.r.s.i.
0x3bb66f006e00000036002e00320038003000o.n...6...2.8.0.
0x3bc630002e003100310030003600000034000...1.1.0.6...4.
0x3bd61200010049006e007400650072006e00....I.n.t.e.r.n.
0x3be661006c004e0061006d00650000004900a.l.N.a.m.e...I.
⋯9 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.