main

First submission 2024-10-16 16:32:06

File details

File type: Zip archive data, at least v1.0 to extract
Mime type: application/zip
File size: 54668.98 KB (55981039 bytes)
MD5: 031435c85f77e2fca633452931a5de54
SHA1: 532ae480cd0eaa5d9dea2bbeede870dbb2ed4c6f
SHA256: 0e0e64f47d4a60714e815bb4a9370c00ffc1ca644943d3f70434533a41546136

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 4/74 VT report date: 2024-10-16 16:30:48
Malware Type 1 virus
Threat Type 3 lazagne pswtool python

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXps://codeload.github.com/steve824/caption/zip/refs/heads/main VirusTotal Report codeload.github.com VirusTotal Report 2024-10-16 16:32:06

Strings analysis - File found

Executable
[8M.sO
Autocad
v 9=.dwG
Text
Lib/idlelib/NEWS2x.txt
Library
DLLs/sqlite3.dll
vcruntime140.dll
VCRUNTIME140_1.dll
DLLs/libcrypto-1_1.dll
DLLs/tcl86t.dll
DLLs/libssl-1_1.dll
DLLs/tk86t.dll
DLLs/libffi-7.dll
python310.dll

Strings analysis - Possible IPs found 1

3.4.5.3