General
Structural Analysis
Config.0
Yara Rules0
Sync
Community
Summary by MalvaGPT
Characteristics
|
Hash | Hash Value |
|---|---|
| MD5 | 8a746a06e41bdeb9d84212ef09148f6b
|
| Sha1 | 0e58a6b17fb5db002e6a5dc0a53c22b71a588a47
|
| Sha256 | d768d0d4ff47b3060822ad77a67184222c5207ace8678e033aca78ec9e6fb8c7
|
| Sha384 | fa2a6366a1a33bdd9601451b22157dc768ac63b0c487c5dd962f1e55fe261c66f4f1588c51910f82f2edf33bd2975a52
|
| Sha512 | 15951d7761bfe18f25ea9a2308c235e727c21cd19f8b5c2cbd4a24f02f7956b5256946aa16b5039d3ead2f12c3fa13dc81a21816d4199c40daa9a85bbf2c5bf2
|
| SSDeep | 6144:VZWia9ubuBsyGvMwlvaB8Mi5vz9IGePA+hq56:nquCuygMQjd5vJIBP1p
|
| TLSH | EB24022B1B2C9932D6550B3B8EE5EB3461BFF5516733D6D30B00DA9DAD232803E26752
|
PeID
Stealth PE 1.01 -> BGCorp
File Structure
8a746a06e41bdeb9d84212ef09148f6b
Overlay_05ddde94.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.PwM
.OwvyT
.MTxF
.XWRUxX
.data
.YCYo
.tKhtUt
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_DIALOG
ID:004E
ID:1033
RT_STRING
ID:00A2
ID:1033
ID:00CA
ID:1033
ID:00F3
ID:1033
ID:010B
ID:1033
ID:0146
ID:1033
ID:01F5
ID:1033
ID:02E5
ID:1033
ID:02F4
ID:1033
RT_RCDATA
ID:00A0
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
Informations
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_05ddde94.bin (18 bytes) |
8a746a06e41bdeb9d84212ef09148f6b (213.01 KB)
File Structure
8a746a06e41bdeb9d84212ef09148f6b
Overlay_05ddde94.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.PwM
.OwvyT
.MTxF
.XWRUxX
.data
.YCYo
.tKhtUt
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_DIALOG
ID:004E
ID:1033
RT_STRING
ID:00A2
ID:1033
ID:00CA
ID:1033
ID:00F3
ID:1033
ID:010B
ID:1033
ID:0146
ID:1033
ID:01F5
ID:1033
ID:02E5
ID:1033
ID:02F4
ID:1033
RT_RCDATA
ID:00A0
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.