|
Hash | Hash Value |
|---|---|
| MD5 | d8db576b2e79c007df16cdd7bd296d6f
|
| Sha1 | cf271ec72564a4537bd14e69b95a82be4366e69e
|
| Sha256 | 451fe418159b0826d1b007d8bba9b8374760b9eee8a99bcad38bb62375a049e7
|
| Sha384 | c92f27d8aaf90a85cba368f4857da81f09f7cdfc9cf8a79102ec39c7749d6a99cec083db0d486528c14a94aa3107abbd
|
| Sha512 | 7f870d7ab7fee43322d63b130980103881698555e722d1e42b10e5943a16299f643a6537108bca5a4270c4429eeb68e2524264b87f596895112ed1fcbafd8fab
|
| SSDeep | 49152:YnsHyjtk2MYC5GDX1D9p2R4xJvBsvD/DX+y4onCYDoDe45EW:Ynsmtk2aKDv2R4x3svD/D+donCYU64WW
|
| TLSH | A2A5E112FAD18077C1611A34CC5B73799D3ABF111E28AA8B77F4ED0C6E3624169352EB
|
PeID
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
|
Name0 | Value |
|---|---|
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
vbaDNA - VBA Stomping & Purging Stategy detection
|
Module Name0 | ||
|---|---|---|
| ThisWorkbook | Blacklist VBA VBA Macro |
|
|
Name0 | Value | Location |
|---|---|---|
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
d8db576b2e79c007df16cdd7bd296d6f > Resources > RT_RCDATA > ID:0000 > ID:1055 > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Decompiled VBA] |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
d8db576b2e79c007df16cdd7bd296d6f > Resources > RT_RCDATA > ID:0000 > ID:1055 > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Decompiled VBA] |
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
d8db576b2e79c007df16cdd7bd296d6f > Resources > RT_RCDATA > ID:0000 > ID:1055 > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Stored VBA] |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
d8db576b2e79c007df16cdd7bd296d6f > Resources > RT_RCDATA > ID:0000 > ID:1055 > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Stored VBA] |