Hostile 92% Download

Worm.Win32.Viking.lu

Known worm with embedded PE

Chinese Hacktool Set - file IISPutScannesr.exeEmbedded PE binary at file offset 0x123f8 (~20478 bytes)
SHA-256ceed45457f3309a19f271ca1aaf75b3d7c74c6784f3d59ef19eaa636b80ecf52
MaleculeTh

Evidence

Chinese Hacktool Set - file IISPutScannesr.exe 0x2f3–0x493
⋯7 more rows
0x363456469746f7220312e37202020627920Editor 1.7 by
0x373796f64612026204d2e6f2e442e202d3eyoda & M.o.D. ->
0x38320636f6d652e746f2f663266202a2a2a come.to/f2f ***
0x3932a2a2a2a2a2a2a2a2a2a2a2a2a000000*************...
0x3a300000000000000000000000000000000................
⋯15 more rows
Embedded PE binary at file offset 0x123f8 (~20478 bytes) 0x123b8–0x12488
⋯3 more rows
0x123e84e00490043004f004e00000000000000N.I.C.O.N.......
0x123f84d5a4b45524e454c33322e444c4c0000MZKERNEL32.DLL..
0x124084c6f61644c6962726172794100000000LoadLibraryA....
0x1241847657450726f63416464726573730000GetProcAddress..
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.