Benign Download

a117e648b54879e001cab5a57c02ea74490f5f4a7893d6fde3d44365b8fe8cba.exe

VB6 runtime API dispatchVB6 DllFunctionCall thunk
SHA-256a117e648b54879e001cab5a57c02ea74490f5f4a7893d6fde3d44365b8fe8cba
MaleculeH(Ds)Md(Bk)

Evidence

VB6 runtime DLL string 0x238–0x268
0x2386cda5b4a100000000000000000000000l.[J............
0x2484d535642564d36302e444c4c00000000MSVBVM60.DLL....
0x25800000000000000000000000000000000................
0x268000000000000000000000000 ............
VB6 DllFunctionCall thunk 0x1048–0x10b8
0x10480604a372ee94a372fdc0a172ea62a372...r...r...r.b.r
0x1058749ba07210c4a172aec6a172f697a472t..r...r...r...r
0x1068081aa272fda094727f97a27239c3a172...r...r...r9..r
0x1078f609a3720ac3a172879ba072dc19a272...r...r...r...r
0x10889395a372859aa072df47a2728906a372...r...r.G.r...r
0x1098ba03a372560fa2721375a4725ac6a172...rV..r.u.rZ..r
0x10a84819a2722b94a37267e8a072ec3aa472H..r+..rg..r.:.r
0x10b837a2a1723a03a3723a04a3724a 7..r:..r:..rJ
.dll extension reference 0x6e4c–0x6e8c
0x6e4c214a54ea2dc8d111a3e400a0c90aea82!JT.-...........
0x6e5c433a5c57696e646f77735c537973576fC:\Windows\SysWo
0x6e6c7736345c4d535642564d36302e646c6cw64\MSVBVM60.dll
0x6e7c5c330000564252554e0000004c6e4000\3..VBRUN...Ln@.
0x6e8c0000000006000000090000005c6e4000............\n@.
PE version resource structure 0x5b75e–0x5b78e
0x5b75e01000400280100003375b00234000000....(...3u..4...
0x5b76e560053005f0056004500520053004900V.S._.V.E.R.S.I.
0x5b77e4f004e005f0049004e0046004f000000O.N._.I.N.F.O...
0x5b78e0000bd04effe000001000400020004 ...............
PE FileVersion metadata field 0x5b932–0x5ba22
0x5b932740044004a0000000000340014000100t.D.J.....4.....
0x5b942460069006c0065005600650072007300F.i.l.e.V.e.r.s.
0x5b95269006f006e000000000032002e003000i.o.n.....2...0.
0x5b96234002e003000300030003400000038004...0.0.0.4...8.
0x5b97214000100500072006f00640075006300....P.r.o.d.u.c.
0x5b9827400560065007200730069006f006e00t.V.e.r.s.i.o.n.
0x5b992000032002e00300034002e0030003000..2...0.4...0.0.
⋯5 more rows
0x5b9f26c0065006e0061006d00650000004100l.e.n.a.m.e...A.
0x5ba0274007a007200520033002e0065007800t.z.r.R.3...e.x.
0x5ba1265000000000000000000000000000000e...............
0x5ba220000000000000000 ........

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.