Benign Download

Trojan-Dropper.Win32.Microjoin.ef

Entry point in a writable RWX sectionPE lacks signature record
SHA-256c89cf9c713338e3a8ee4525fcc5328d80c37e47b19cb24f070b8c7824e139dbe

Evidence

Resource section dominates PE size 0x0–0xe0
0x04d5a00000100000002000000ffff0000MZ..............
0x1040000000000000004000000000000000@.......@.......
0x20b44ccd21000000000000000000000000.L.!............
0x3000000000000000000000000080000000................
⋯11 more rows
Writable and exe section (W^X violation) 0x1a0–0x2d0
⋯5 more rows
0x1f000000000000000000000000000000000................
0x200ec6c6c6cf1ec6cf1ec6cd5c51dfdc5cd.lll..l..l......
0x210131b6c15adc5cdcd131b6c4515c51d13..l.......lE....
0x2201b6ca58d3da5e8e5131b6ca9246e6c3c.l..=.....l.$nl<
⋯11 more rows
PE resource entropy is at least 6.6 0x7d0–0x870
0x7d0ecececececececececececececececec................
0x7e0ecececececececececececececececec................
0x7f0ecececececececececececececececec................
0x80000000000000000000000000000000200................
0x81003000000200000800e000000f0000080.... ...........
⋯6 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.