Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Sample ccae2400a50a3f2435d7ef1b11e7497c
- Dumped e82872c4039945e9bf1b41ae2e3f12fb
- Dropper c32354ee13930113072fdba163dc8ca4
- Images: http://imgur.com/a/5xf6l
- (Older sample a489e781db78472dedd657be21aca604)
- pescanner run of ccae2400a50a3f2435d7ef1b11e7497c // original sample //
- ################################################################################
- Record 0
- ################################################################################
- Meta-data
- ================================================================================
- File: Locker.exe_
- Size: 140800 bytes
- Type: PE32 executable for MS Windows (GUI) Intel 80386 32-bit Mono/.Net assembly
- MD5: ccae2400a50a3f2435d7ef1b11e7497c
- SHA1: 0f86c35697d16b2516601e9472264b87259672f2
- ssdeep: 3072:Ey/XPVXCM33kUBfH6rrUi4x0aW8W9MdwmTZ/yArUi:V/MAUUBOrUiUW9UNrUi
- Date: 0x5404BD0B [Mon Sep 1 18:38:03 2014 UTC]
- EP: 0x41f86e .text 0/3
- CRC: Claimed: 0x2dace, Actual: 0x2dace
- Resource entries
- ================================================================================
- Name RVA Size Lang Sublang Type
- --------------------------------------------------------------------------------
- RT_ICON 0x203d0 0x4136 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
- RT_GROUP_ICON 0x24508 0x14 LANG_NEUTRAL SUBLANG_NEUTRAL MS Windows icon resource - 1 icon
- RT_VERSION 0x20130 0x2a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
- RT_MANIFEST 0x24520 0x1ea LANG_NEUTRAL SUBLANG_NEUTRAL XML document text
- Sections
- ================================================================================
- Name VirtAddr VirtSize RawSize Entropy
- --------------------------------------------------------------------------------
- .text 0x2000 0x1d874 0x1da00 7.525804 [SUSPICIOUS]
- .rsrc 0x20000 0x4710 0x4800 7.806567 [SUSPICIOUS]
- .reloc 0x26000 0xc 0x200 0.101910 [SUSPICIOUS]
- Version info
- ================================================================================
- Translation: 0x0000 0x04b0
- LegalCopyright: Copyright \xa9 2014
- Assembly Version: 1.0.0.0
- InternalName: Locker.exe
- FileVersion: 1.0.0.0
- ProductName: Locker
- ProductVersion: 1.0.0.0
- FileDescription: Locker
- OriginalFilename: Locker.exe
- Packer: Microsoft Visual C# / Basic .NET
- PeStudio output: http://i.imgur.com/UseuueX.jpg
- Samples available at http://kernelmode.info/forum/viewtopic.php?f=16&t=3466
- ======================================================= EOF
- @bartblaze
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement