6eff996b811b13f788f51602ed20ad65
PE Executable | MD5: 6eff996b811b13f788f51602ed20ad65 | Size: 2.42 MB | application/x-dosexec
|
Hash | Hash Value |
|---|---|
| MD5 | 6eff996b811b13f788f51602ed20ad65
|
| Sha1 | d47cfc3134a79553e80332cba73cebd0de4ddeae
|
| Sha256 | 6fcf0a816cc3d2ad33ddd0125cca8f189e149e106702ae25db914477940d1a27
|
| Sha384 | ec82672b7376ac7d04c226ba16a5c9b0567f2f028079f026ba72c1da8240e6adfefdc03952bee60e043f58b2f5f8b07b
|
| Sha512 | 2e30cac0c96cbd03eed428c5a9f3ff6eb2bd58c315838a0191876b4b7cdb77497b426b94575fb5b212ade42592f35404dedeb66fcc37827ee5bbfd729b9b16d0
|
| SSDeep | 49152:RnsHyjtk2MYC5GD4EOFJdQ1Bx+bIVygALO8mLe7SLq0fDGUCo/QB5KV9+ed:Rnsmtk2ajEOF36ebI5Ayr20fDSoa5KrL
|
| TLSH | E9B5F122F2D18477D1721A3C8C5BA3A5982ABF512E34794F3BE82E4C5F3D68139652D3
|
PeID
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
|
Name0 | Value |
|---|---|
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
vbaDNA - VBA Stomping & Purging Stategy detection
|
Module Name0 | ||
|---|---|---|
| ThisWorkbook | Blacklist VBA VBA Macro |
|
|
Name0 | Value | Location |
|---|---|---|
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
6eff996b811b13f788f51602ed20ad65 > [Repaired @0x00248DB0] > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Stored VBA] |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
6eff996b811b13f788f51602ed20ad65 > [Repaired @0x00248DB0] > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Stored VBA] |
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
6eff996b811b13f788f51602ed20ad65 > [Repaired @0x00248DB0] > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Decompiled VBA] |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
6eff996b811b13f788f51602ed20ad65 > [Repaired @0x00248DB0] > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Decompiled VBA] |