Sample details: 63ad0e285b5fa68aa5a32dc3f04e5b7b --

Hashes
MD5: 63ad0e285b5fa68aa5a32dc3f04e5b7b
SHA1: e9e152ede515c28efd5905fc3f3500317c7b7705
SHA256: a848fa16033d9227dc16aae2e3a96b13c8f53f9c898dd316ef541ac86ec22b1d
SSDEEP: 6144:R6AXtAOfFELJlZn9ocihaFcRfp1pjO4bi+G+bHq3aZROrNu9lI7Wm:R6ZOfFkxJFc1XxVi0bKXu7nm
Details
File Type: PE32
Yara Hits
YRP/Armadillo_v171 | YRP/Microsoft_Visual_Cpp_v60 | YRP/Microsoft_Visual_Cpp_v50v60_MFC_additional | YRP/Microsoft_Visual_Cpp_50 | YRP/Microsoft_Visual_Cpp_v50v60_MFC | YRP/Armadillo_v171_additional | YRP/Armadillo_v4x | YRP/Microsoft_Visual_Cpp | YRP/IsPE32 | YRP/IsWindowsGUI | YRP/HasRichSignature | YRP/domain | YRP/contentis_base64 | YRP/DebuggerException__SetConsoleCtrl | YRP/Check_OutputDebugStringA_iat | YRP/anti_dbg | YRP/screenshot | YRP/keylogger | YRP/win_registry | YRP/win_private_profile | YRP/win_files_operation | YRP/win_hook |
Source
http://42.51.45.51:8080/win.exe