General
Structural Analysis
Config.0
Yara Rules28
Sync
Community
Summary by MalvaGPT
Characteristics
|
Hash | Hash Value |
|---|---|
| MD5 | 5fa4afbff3be8ae360e491bf123f6c36
|
| Sha1 | a41842ee909aeb1b06e010a03c4c7938c04d851f
|
| Sha256 | 64335811f3d65455be2cb759ce21f0fe420abb4fa12ba4732606f18cd2cd9c92
|
| Sha384 | 376885fba036408f9a26fa7121975b9e6e503a5c566d07ab71d40362e70dd80c955a8b514fa3c356202dfa84b9e8113e
|
| Sha512 | 1ac34e4e9bef8a91e09c031f254c9761366f8322c9ff44de1f71ba00de3562c607ad5d92c5f05014effe585899e96ab0eb0d49cd1f2d956399a8faf49f7fbe01
|
| SSDeep | 12288:8D4SQecwjApj2kPH0ewCAf3CeLbdFMSoy18o9UzFRQvoXR7gUjB6Vdtl9lXv/Px:hecwjAVMU0BFMS1So92FRsWHM39lHp
|
| TLSH | BEF4233CE2157A84846F3CCB5AED3EA6788FDF32921E449F05EE61AD4E208376C56D44
|
File Structure
ORDER No. 201945.exe
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
AlarmPlus.AlarmForm.resources
AlarmPlus.Properties.Resources.resources
Sweet
[NBF]root.Data
Zgmz
[NBF]root.Data
[NBF]root.Data-preview.png
AlarmPlus.SettingsForm.resources
$this.Icon
[NBF]root.IconData
AlarmPlus.StatisticsForm.resources
$this.Icon
[NBF]root.IconData
Artefacts
|
Name0 | Value |
|---|---|
| PDB Path | Uziu.pdb |
5fa4afbff3be8ae360e491bf123f6c36 (748.15 KB)
File Structure
ORDER No. 201945.exe
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
AlarmPlus.AlarmForm.resources
AlarmPlus.Properties.Resources.resources
Sweet
[NBF]root.Data
Zgmz
[NBF]root.Data
[NBF]root.Data-preview.png
AlarmPlus.SettingsForm.resources
$this.Icon
[NBF]root.IconData
AlarmPlus.StatisticsForm.resources
$this.Icon
[NBF]root.IconData
Characteristics
No malware configuration were found at this point.
Artefacts
|
Name0 | Value | Location |
|---|---|---|
| PDB Path | Uziu.pdb |
5fa4afbff3be8ae360e491bf123f6c36 > ORDER No. 201945.exe |
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.