899931bae53a4e675909ca04bebd54e3
PE Executable | MD5: 899931bae53a4e675909ca04bebd54e3 | Size: 1.18 MB | application/x-msdownload
Hash | Hash Value |
---|---|
MD5 | 899931bae53a4e675909ca04bebd54e3
|
Sha1 | 61b00e55b05096b1358b046b8f4c8c4d40094d94
|
Sha256 | ce2d316eb56e9ba86761ff9a52ae454eacf62af3d12dbe3cde9a251181480f8b
|
Sha384 | c5d4c85b3eb44f259544ed29ee20aadcea4b3f1489237b59a0248594435d1e0ec2faa7e3ffa61f070cc0fe2a3553baf5
|
Sha512 | 9b2fb6db52c28ad2a468fc11b6dda463aed21cf459e560efb6a90fea7da9017e95f88d8d7fb2194b60425519561fa599f0c8d6bdad05b2943fe105f3c546143f
|
SSDeep | 24576:9nsJ39LyjbJkQFMhmC+6GD9rPAlJx8Eporf:9nsHyjtk2MYC5GD9MCEOrf
|
TLSH | 2D459E22B6D18033D1732A388D7BE3A5483EBE512D34A94F37E81E5C5F3968179253A7
|
PeID
Name0 | Value |
---|---|
PDB Path | C:\agent\_work\88\s\Win32\Release\Autologon.pdb |
URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
vbaDNA - VBA Stomping & Purging Stategy detection
Module Name0 | ||
---|---|---|
ThisWorkbook | Blacklist VBA VBA Macro |
|
Name0 | Value | Location |
---|---|---|
PDB Path | C:\agent\_work\88\s\Win32\Release\Autologon.pdb |
899931bae53a4e675909ca04bebd54e3 > Resources > RT_RCDATA > ID:0000 > ID:0 |
URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
899931bae53a4e675909ca04bebd54e3 > [Repaired @0x0011B4B8] > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Stored VBA] |
URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
899931bae53a4e675909ca04bebd54e3 > [Repaired @0x0011B4B8] > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Stored VBA] |
URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
899931bae53a4e675909ca04bebd54e3 > [Repaired @0x0011B4B8] > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Decompiled VBA] |
URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
899931bae53a4e675909ca04bebd54e3 > [Repaired @0x0011B4B8] > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Decompiled VBA] |