Sample details: 19ac9dc3c777cd11ea2788d7eace87f1

Hashes
MD5: 19ac9dc3c777cd11ea2788d7eace87f1
SHA1: 094e6adbef89c74a4bd640c248453c51700a4df8
SHA256: 1ffd368a8757739305ec7b81ca9e0d7290754ddf5e82bbfefb5602f94a9476c7
SSDEEP: 12288:jCdOy3vVrKxR5CXbNjAOxK/j2n+4YG/6c1mFFja3mXgcjfRlgsUBgai7yX1tckjV:jCdxte/80jYLT3U1jfsWaq92H6LWmHQ
Details
File Type: PE32
Yara Hits
YRP/VC8_Microsoft_Corporation | YRP/Microsoft_Visual_Cpp_8 | YRP/IsPE32 | YRP/IsWindowsGUI | YRP/HasDebugData | YRP/IsBeyondImageSize | YRP/HasRichSignature | YRP/AutoIt | YRP/domain | YRP/IP | YRP/contentis_base64 | YRP/AutoIT_compiled_script | YRP/anti_dbg | YRP/inject_thread | YRP/network_http | YRP/escalate_priv | YRP/screenshot | YRP/keylogger | YRP/win_registry | YRP/win_token | YRP/win_files_operation | YRP/CRC32_poly_Constant | YRP/CRC32_table | YRP/Str_Win32_Winsock2_Library | YRP/Str_Win32_Wininet_Library | YRP/Str_Win32_Internet_API | YRP/Str_Win32_Http_API |
Source
http://5.101.149.8/list.exe
http://5.101.149.8/list.exe