|
Hash | Hash Value |
|---|---|
| MD5 | fb7a0795cb78244f1bf3dca74dd54022
|
| Sha1 | 49f8fd5564751f4666f788b1792df0b903a8fef6
|
| Sha256 | 6f561ab384d65db9ee11a49b2f9d0a1e6758f9d0c6082f1e65821f6984fa2c71
|
| Sha384 | 00483ef87fbf52f00bdeaf674020b490ee8400cdbab3aa59c723a4a8b604cc5948b8991043b1a1e4c66dbe87d7aee184
|
| Sha512 | eead9403340c98fc743c6b3001c562f2ea08e7a15a0e2fdb14a0c6b86fb0b731be1ca1ba91cf86d923527a1eacff36642c1d4b7fc257df8b374f9bac38e1b931
|
| SSDeep | 196608:nLIm4FXJv9lvJiYiH7WGSGiYyXD1Jw09vcj6YWgHqJpcdGTTpgq3edU8Fd62tp3c:nsrFVvJiY670HD/9/d2dGCq3mUedD3dq
|
| TLSH | C3C63322F2D19437D1325A7DDC2BA2A45429FF103E24B94F7BE42E8C5F7968239641E3
|
PeID
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
|
Name0 | Value |
|---|---|
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
vbaDNA - VBA Stomping & Purging Stategy detection
|
Module Name0 | ||
|---|---|---|
| ThisWorkbook | Blacklist VBA VBA Macro |
|
|
Name0 | Value | Location |
|---|---|---|
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
fb7a0795cb78244f1bf3dca74dd54022 > Resources > RT_RCDATA > ID:0000 > ID:1055 > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Decompiled VBA] |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
fb7a0795cb78244f1bf3dca74dd54022 > Resources > RT_RCDATA > ID:0000 > ID:1055 > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Decompiled VBA] |
| URLs in VB Code - #1 | https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download |
fb7a0795cb78244f1bf3dca74dd54022 > Resources > RT_RCDATA > ID:0000 > ID:1055 > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Stored VBA] |
| URLs in VB Code - #2 | https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 |
fb7a0795cb78244f1bf3dca74dd54022 > Resources > RT_RCDATA > ID:0000 > ID:1055 > xl > vbaProject.bin > Root Entry > VBA > ThisWorkbook > [Stored VBA] |