taskhostw.exe
First submission 2024-10-16 23:06:03
File details
File type: | PE32 executable (GUI) Intel 80386, for MS Windows |
Mime type: | application/x-dosexec |
File size: | 935.51 KB (957965 bytes) |
Compile time: | 2010-03-07 17:08:39 |
MD5: | daaa8ac3995fb610eda2e52a639d191f |
SHA1: | 2a26a631b79878c461248d5c03a33fb312aedb05 |
SHA256: | e82aa9f8f95f53d306db35e28e6fdd4dd16eba7d7437971f929d3cf5470267b7 |
Import Hash : | aaaa8913c89c8aa4a5d93f06853894da |
Sections 4 | .text .rdata .data .rsrc |
Directories 2 | import resource |
File features detected
Signed
XOR
OSINT Enrichments
Virus Total: | 35/77 VT report date: 2024-10-16 19:26:24 |
Malware Type 1 | trojan |
Threat Type 3 | autoit cottonmouth snakekeylogger |
URLs, FQDN and IP indicators 1
PE Sections 0 suspicious
Name | VAddress | VSize | Size | SHA1 | MD5 | Suspicious |
---|---|---|---|---|---|---|
.text | 0x1000 | 0x80017 | 524800 | 2313df023bb305e4aac83f1d250066be138dba7a | 6c20c6bf686768b6f134f5bd508171bc | |
.rdata | 0x82000 | 0xd95c | 55808 | 98dac5ef8e9c23a80b31f1a09e01a56a882ca283 | f979966509a93083729d23cdfd2a6f2d | |
.data | 0x90000 | 0x1a518 | 26624 | 9286d86740e16cc5e1190d8435f272bfab8a2f90 | e5d77411f751d28c6eee48a743606795 | |
.rsrc | 0xab000 | 0x9298 | 37888 | a484de0e400909d276cd544fce4341f65566b415 | f6be76de0ef2c68f397158bf01bdef3e |
PE Resources 7
Name | Language | Sublanguage | Offset | Size | Data |
---|---|---|---|---|---|
RT_ICON | LANG_ENGLISH | SUBLANG_ENGLISH_UK | 0xb16c0 | 1128 | |
RT_MENU | LANG_ENGLISH | SUBLANG_ENGLISH_UK | 0xb1b28 | 80 | |
RT_DIALOG | LANG_ENGLISH | SUBLANG_ENGLISH_UK | 0xb1b78 | 252 | |
RT_STRING | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0xb3c60 | 344 | |
RT_GROUP_ICON | LANG_ENGLISH | SUBLANG_ENGLISH_UK | 0xb3e70 | 20 | |
RT_VERSION | LANG_ENGLISH | SUBLANG_ENGLISH_UK | 0xb3e88 | 412 | |
RT_MANIFEST | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0xb4028 | 620 |
Meta infos 4
CompiledScript: | AutoIt v3 Script: 3, 3, 6, 0 |
Translation: | 0x0809 0x04b0 |
FileVersion: | 3, 3, 6, 0 |
FileDescription: |
Packers detected 2
Microsoft Visual C++ 8 |
VC8 -> Microsoft Corporation |
Anti debug functions 11
FindWindowExW |
FindWindowW |
GetLastError |
GetWindowThreadProcessId |
IsDebuggerPresent |
OutputDebugStringW |
Process32FirstW |
Process32NextW |
RaiseException |
TerminateProcess |
UnhandledExceptionFilter |
Anti debug functions 1
VMCheck.dll |
Strings analysis - File found
Library |
mscoree.dll |
KERNEL32.dll |
ADVAPI32.dll |
OLEAUT32.dll |
VERSION.dll |
WSOCK32.dll |
SHELL32.dll |
UxTheme.dll |
ICMP.DLL |
PSAPI.DLL |
COMCTL32.dll |
ole32.dll |
WININET.dll |
USER32.dll |
USERENV.dll |
WINMM.dll |
GDI32.dll |
MPR.dll |
COMDLG32.dll |
Strings analysis - Possible IPs found 1
255.255.255.255 |
Import functions
Name | Latest seen | MD5 |
---|---|---|
taskhostw.exe | 2024-10-06 21:37:03 | d515411b9a3c0d9fb13b9c6a928a7fd0 |
taskhostw.exe | 2024-10-07 06:33:04 | 822a424b469a4aec464f209d49dd072f |
taskhostw.exe | 2024-10-07 16:57:05 | 58ff14d476f2bbaab31b12587c09559e |
nggeejan22.exe | 2024-10-09 15:26:02 | 40a93e64a968a16b5139e7a5e4836353 |
ngown.exe | 2024-10-09 15:28:02 | 1ea3b00d00461c1ee3c576e21dcda173 |
GSAutoClicker.exe?ex=670c8e24&is=670b3ca4&hm=51be56320789350c63b80ba15ac4b60b6b739c1094dae83636c4b1e5bb776c07& | 2024-10-13 19:43:01 | 6862f65be14fd3ce88086ec79777db6e |
taskhostsw.exe | 2024-10-14 21:13:03 | b072f78321c660283d46e104ae677220 |
taskhostw.exe | 2024-10-15 10:34:03 | 3e2f27edd3deacd8f08f6ed1133b2040 |
taskhostws.exe | 2024-10-17 16:48:04 | b47e4f366b08fe509c2a8f9ee7251f51 |