|
Hash | Hash Value |
|---|---|
| MD5 | d03734457a171c4998e4e7645297ebbf
|
| Sha1 | 2fc30c2da50cce256fca4fe3c22944c586db8de0
|
| Sha256 | 1b20bb50d5eb548b9de8905a860fe218da7b49e78ae87c0fee159686ba3e48a6
|
| Sha384 | 3eeba8450306c91d9b0287f84b5089ba771898ea90020cdbd1f413ad885e05801aabf1d2142e972c57d629344bb76e77
|
| Sha512 | 4ef92b20ca2a488d0d578831bd8890df09b6a8f35b09639a772d3a3ee194e77cef2a55df004ab8c340de6fb0b81d1dfe4e43c703644aad1137a749079042166c
|
| SSDeep | 49152:7nsHyjtk2MYC5GDgWwgkLCDIZHsUdi2oi9rx9A+5h+v4loPB7n3:7nsmtk2aBWwgIZH1dRoKrjAaTEB73
|
| TLSH | 0DB5F132F2D18437D1331A3C9D6BA3A4483ABE512E38794E7BE93E4C5E396812D552D3
|
PeID
|
Name0 | Value |
|---|---|
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
vbaDNA - VBA Stomping & Purging Stategy detection
|
Module Name0 | ||
|---|---|---|
| ThisWorkbook | Blacklist VBA VBA Macro |
|
|
Name0 | Value | Location |
|---|---|---|
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
d03734457a171c4998e4e7645297ebbf > [Repaired @0x00229FB8] > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Stored VBA] |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
d03734457a171c4998e4e7645297ebbf > [Repaired @0x00229FB8] > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Stored VBA] |
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
d03734457a171c4998e4e7645297ebbf > [Repaired @0x00229FB8] > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Decompiled VBA] |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
d03734457a171c4998e4e7645297ebbf > [Repaired @0x00229FB8] > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Decompiled VBA] |