General
Structural Analysis
Config.0
Yara Rules0
Sync
Community
Summary by MalvaGPT
Characteristics
|
Hash | Hash Value |
|---|---|
| MD5 | dd7b3bc409695c0caac1a2f589fa4108
|
| Sha1 | c74f976492e7b7474ab3537f63f98f13b182b83c
|
| Sha256 | 3c1a2fa98aaf7394ba262ef8d47c4ac1355c8c2224bfd961e130a48a1b7d8708
|
| Sha384 | 4144c04b61db404172657f98b801abbd83ff181411abd19febe0993c05355353ec8aff68722fdfb19d0b0ed37e0e5fca
|
| Sha512 | ab06da10bf6f771fb8af1dcc1f12baab5f12916549a7bb064562656b82083083164304ff7885dd9be6338860a4268fc681c65525368cc3540b4927139424cce4
|
| SSDeep | 6144:iIRkVICSS3prHaXhwBYZZhdRYpFilCGZ6ZcZMMneXUpm2AbLEsx6i0w3d7y6m:eImNaGBG3Ye6ZcmiPAbL3oi3d6
|
| TLSH | 1A84F12A77EC14AAD97653748CB30A206731F8645B22DBDF0250813C5F66FD4AE34F9A
|
PeID
Microsoft Visual C++ v6.0 DLL
Microsoft v12.00 64bit C++ DLL - sign ASL ( 64 bit )
File Structure
dd7b3bc409695c0caac1a2f589fa4108
[Authenticode]_5cda2906.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.didat
.guids
.rsrc
.reloc
Resources
MUI
ID:0001
ID:1033
WEVT_TEMPLATE
ID:0001
ID:1033
RT_ICON
ID:0001
ID:1033
RT_RCDATA
ID:00C8
ID:1033
ID:0202
ID:1033
ID:0203
ID:1033
ID:0204
ID:1033
ID:0207
ID:1033
ID:020A
ID:1033
ID:020B
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1033
RT_VERSION
ID:0001
ID:1033
Informations
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Authenticode present at 0x21800 size 11160 bytes |
| Info | PDB Path: winmm.pdb |
dd7b3bc409695c0caac1a2f589fa4108 (405.5 KB)
File Structure
dd7b3bc409695c0caac1a2f589fa4108
[Authenticode]_5cda2906.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.didat
.guids
.rsrc
.reloc
Resources
MUI
ID:0001
ID:1033
WEVT_TEMPLATE
ID:0001
ID:1033
RT_ICON
ID:0001
ID:1033
RT_RCDATA
ID:00C8
ID:1033
ID:0202
ID:1033
ID:0203
ID:1033
ID:0204
ID:1033
ID:0207
ID:1033
ID:020A
ID:1033
ID:020B
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1033
RT_VERSION
ID:0001
ID:1033
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.