cef4eb76c55cec6a28aad1ce08dbf61c
PE Executable | MD5: cef4eb76c55cec6a28aad1ce08dbf61c | Size: 4.45 MB | application/x-dosexec
|
Hash | Hash Value |
|---|---|
| MD5 | cef4eb76c55cec6a28aad1ce08dbf61c
|
| Sha1 | acf710f210e01a9162fd69b668205c898892d948
|
| Sha256 | 11dee89c0ea7cb7142d3edd87bf1888f3d559ab6752f0762b123e60bbb0cdac9
|
| Sha384 | 9b0462ebceddddf839a1e9ddba43e227d67a2f6f6b5adb52ccc5b13b786f1aa234070dab48dc7a8b6842be3ffa9893bb
|
| Sha512 | 86bf59596c9546ac1f9b34f7e1e4b96349fd8fa15872e511ade025547cdeb23c8b0625241781ccd87118ee063ed8d68b32a7158f892248c21bfcc8c91a6006c0
|
| SSDeep | 98304:ensmtk2aPskDP1dOcd6cy2LkZkkd0sAon:gLYOMy2LkZ71
|
| TLSH | D7269D292B924262C3513738CC76A6A425796F131F18D4766EB42D4D7D3228EFC13EBE
|
PeID
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
|
Name0 | Value |
|---|---|
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
vbaDNA - VBA Stomping & Purging Stategy detection
|
Module Name0 | ||
|---|---|---|
| ThisWorkbook | Blacklist VBA VBA Macro |
|
|
Name0 | Value | Location |
|---|---|---|
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
cef4eb76c55cec6a28aad1ce08dbf61c > [Repaired @0x00438A48] > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Stored VBA] |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
cef4eb76c55cec6a28aad1ce08dbf61c > [Repaired @0x00438A48] > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Stored VBA] |
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
cef4eb76c55cec6a28aad1ce08dbf61c > [Repaired @0x00438A48] > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Decompiled VBA] |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
cef4eb76c55cec6a28aad1ce08dbf61c > [Repaired @0x00438A48] > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Decompiled VBA] |