Malicious
0f74daa5854510d25d42b69aafeff0a5
VB5/6 Executable | MD5: 0f74daa5854510d25d42b69aafeff0a5 | Size: 866.77 KB | application/x-dosexec
VB5/6 Executable
MD5: 0f74daa5854510d25d42b69aafeff0a5
Size: 866.77 KB
application/x-dosexec
Infection Chain
Summary by MalvaGPT
Characteristics
|
Hash | Hash Value |
|---|---|
| MD5 | 0f74daa5854510d25d42b69aafeff0a5
|
| Sha1 | 76426a8723ff019f213380ddfd0240ac26868218
|
| Sha256 | c0b99a4d83d20539cbcb64a75cf4195277d63ef20113a3d3d5a1affe9db263e3
|
| Sha384 | 011a7c643d013674edc3f46b34b8fffc42246e48bdf25b2170a180823d52826596bd8a6717adeb5d243c358e40255a07
|
| Sha512 | e50f98cace7f3852987eccbdc14d667cfb4a783f051e64d215793a6087a5dcce4e74f93b171616fc49728880349c90f6ebd02fb7501e2b1da4853163644f558f
|
| SSDeep | 12288:GENN+T5xYrllrU7QY6fz7hU5I5yuNHIgzSFKxWltRohBfSTso93UJeN2CMImQjr8:K5xolYQY6ff+iN57Gtene3sCMIR20x+f
|
| TLSH | 7805C01BFE04661AE49292F04431AA9BFE266D310BD1AC4F53D1BB4978B1603B4F571F
|
PeID
Microsoft Visual Basic v5.0 - v6.0
Microsoft Visual C++ v6.0 DLL
Protect Shareware V1.1 -> eCompserv CMS
File Structure
0f74daa5854510d25d42b69aafeff0a5
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.tdata
Resources
RT_ICON
ID:7531
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
VB6 Structure
VB Header
VB VBAProject Info
VB Object Table
VB VBAProject Info 2
VB Register Info
Informations
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_c5592539.bin (616918 bytes) |
0f74daa5854510d25d42b69aafeff0a5 (866.77 KB)
File Structure
0f74daa5854510d25d42b69aafeff0a5
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.tdata
Resources
RT_ICON
ID:7531
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
VB6 Structure
VB Header
VB VBAProject Info
VB Object Table
VB VBAProject Info 2
VB Register Info
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.