General
Structural Analysis
Config.0
Yara Rules1
Sync
Community
Summary by MalvaGPT
Characteristics
|
Hash | Hash Value |
|---|---|
| MD5 | a344196e733ebdb74f47a75d59e7fba9
|
| Sha1 | d270a43b2a4c6c2f72c9dcec05a7440d0284e0d2
|
| Sha256 | 1803fb13ce6c98a85d94c5c826d1ca362ec85b78417654f9e8c8a2b4c6dc36a9
|
| Sha384 | a7e3009a3127ad98f9b3154e1b3d894b6488b9f561fd9beaae16f63f17f4d37eafb39a11d006d0b9d7bb224d879882b4
|
| Sha512 | 01f22f13ad7bb5bd0c9574f2c571fd48e870c69da13bf88ce16904bccf2810cfba6d4d41832277ec0835bf96f9732f3de7637d1dbdecc89955e61d053832dc05
|
| SSDeep | 98304:szOLf5HYv5xZmKp1T7jTulphwgZME9zroZwcsk2Dy0t5YijgvVdml+dPnVOqPQSx:szOLR4vgcluRwgZF9foZwJkl0tfjgDn+
|
| TLSH | 8C46330602159947E8CE0D735797F138EE10B50384BA126BCA756A6FF5A17B02F3F63A
|
PeID
Microsoft Visual C++ v6.0 DLL
Nullsoft PiMP Stub -> SFX
File Structure
a344196e733ebdb74f47a75d59e7fba9.SecuriteInfo.com.Trojan.NSIS.Runner.3389.31492
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:1033-preview.png
ID:0003
ID:1033
ID:0004
ID:1033
ID:1033-preview.png
ID:0005
ID:1033
ID:0006
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
a344196e733ebdb74f47a75d59e7fba9.SecuriteInfo.com.Trojan.NSIS.Runner.3389.31492 (5.87 MB)
File Structure
a344196e733ebdb74f47a75d59e7fba9.SecuriteInfo.com.Trojan.NSIS.Runner.3389.31492
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:1033-preview.png
ID:0003
ID:1033
ID:0004
ID:1033
ID:1033-preview.png
ID:0005
ID:1033
ID:0006
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.