Sample details: adbf606c607340eb78fcea057340cb2a

Hashes
MD5: adbf606c607340eb78fcea057340cb2a
SHA1: bea22d52ba2910035bd5cd135e6243768f821f0f
SHA256: e2595f9dac09ffc10fae3de53888098e208a71c0c854e157e45f7ce9e7d0311f
SSDEEP: 12288:nhxp3lZnT9bDuaI3DkcY0RHO6lJo6Y3vDpIg:nJlh9bDuaIzkX76l0/dIg
Details
File Type: PE32
Yara Hits
YRP/VC8_Microsoft_Corporation | YRP/Microsoft_Visual_Cpp_8 | YRP/IsPE32 | YRP/IsWindowsGUI | YRP/IsPacked | YRP/HasOverlay | YRP/HasDebugData | YRP/HasRichSignature | YRP/maldoc_find_kernel32_base_method_1 | YRP/domain | YRP/IP | YRP/url | YRP/contentis_base64 | YRP/anti_dbg | YRP/escalate_priv | YRP/screenshot | YRP/win_registry | YRP/win_token | YRP/win_files_operation | YRP/Big_Numbers0 | YRP/CRC32_poly_Constant | YRP/RIPEMD160_Constants | YRP/SHA1_Constants |
Source
http://107.167.10.47/fon/roz.exe