General
Structural Analysis
Config.0
Yara Rules0
Sync
Community
Summary by MalvaGPT
Characteristics
|
Hash | Hash Value |
|---|---|
| MD5 | 206cf4271bdbc0dc4f78f6b317ed0df6
|
| Sha1 | 7d5101fe6fc3f8b7364ea6a3249ea101f72adef3
|
| Sha256 | 113b43743498db3c8e12b6ba34b7d12069fb8763968178b7e79f256916bb0317
|
| Sha384 | fe3ada825f144cf7878dc693d6592be64ff912b17a2934ba751df53feed9090a4e1d7510697a8cdd9dcf1e3960e982d9
|
| Sha512 | 8388a9a5c7c07e97081db5ae37df47017734647fab5009893a21a6bd005fe8ae1f2df191d80621884bcc5f317b998fce61ffc514aa0c3844764fbe2d32f5c02c
|
| SSDeep | 49152:odZEy2B6vflQf6X8uZQoy3vR6QVQy5Z+bm4M/HMFvfGW0/7Z7Ib3jxw5bd:MHvfGfZvZj1/N/z/owJd
|
| TLSH | 23F58DD2A3A600E8E9B7F23C85568517E7F2B81753709BCF15A44A761F236D12B3E702
|
PeID
Microsoft Visual C++ 8.0 (DLL)
Microsoft Visual C++ v6.0 DLL
Pe123 v2006.4.4-4.12
Private EXE Protector V2.30-V2.3X -> SetiSoft Team
File Structure
206cf4271bdbc0dc4f78f6b317ed0df6
[Authenticode]_6ebc936c.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.gfids
.rsrc
.reloc
Resources
AFX_DIALOG_LAYOUT
ID:0067
ID:1033
RT_BITMAP
ID:006C
ID:0
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
RT_DIALOG
ID:0067
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0071
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Informations
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Authenticode present at 0x347C00 size 42680 bytes |
| Info | PDB Path: C:\MeshAgent\MeshAgent\Release\MeshService64.pdb |
206cf4271bdbc0dc4f78f6b317ed0df6 (3.48 MB)
File Structure
206cf4271bdbc0dc4f78f6b317ed0df6
[Authenticode]_6ebc936c.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.gfids
.rsrc
.reloc
Resources
AFX_DIALOG_LAYOUT
ID:0067
ID:1033
RT_BITMAP
ID:006C
ID:0
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
RT_DIALOG
ID:0067
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0071
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.