General
Structural Analysis
Config.0
Yara Rules18
Sync
Community
Summary by MalvaGPT
Characteristics
Symbol Ofbuscation Score
Low
|
Hash | Hash Value |
|---|---|
| MD5 | 70e5c9b8827d3808a6a5088ef582fe96
|
| Sha1 | 31b8768646f57c47608895855ca0e99395bb102c
|
| Sha256 | ba0ffac6927dbc9ea581538291d9eed369277957573ded03d212a99053dbdd1d
|
| Sha384 | 810842058d70a3b57a8568bf17d8e2aed53e1af9ba0bccc9407e50f36e80e369ae483ec0cf6e58fd6a21480fc8937f6d
|
| Sha512 | ba055b4a43bcc6330357866081b47272c8dbad1094a56a56858037c8247e1fc14d1166083910a3f6978cdaf32836fcb1e1f9a83ee8951664cc985de0efcd35b0
|
| SSDeep | 384:yP4lTO7H/jKnE4fldFkCWR9VZwVq/x3WqVQNhL:yP4lq7unEjC+9rlVYV
|
| TLSH | 8E72290833E84254E1FF4B7D99B2021849B6F96A6839EF4D1CCD616E1DE37849A10FB3
|
PeID
Microsoft Visual C++ DLL
Microsoft Visual C++ v6.0
File Structure
70e5c9b8827d3808a6a5088ef582fe96
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | agent_mem_x64.exe |
| Full Name | agent_mem_x64.exe |
| EntryPoint | System.Void FleetAgent.Program::Main(System.String[]) |
| Scope Name | agent_mem_x64.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | agent_mem_x64 |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 151 |
| Main Method | System.Void FleetAgent.Program::Main(System.String[]) |
| Main IL Instruction Count | 2 |
| Main IL | call System.Void FleetAgent.Program::Execute() ret <null> |
70e5c9b8827d3808a6a5088ef582fe96 (16.38 KB)
File Structure
70e5c9b8827d3808a6a5088ef582fe96
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.