Sample details: c4cc1bbb798228b291fa8596dc913e86 --

Hashes
MD5: c4cc1bbb798228b291fa8596dc913e86
SHA1: 1c5565b1c2bfb1778d190c2abd6296a343d2e4e8
SHA256: b8a6ca3852e3837af2ec23495cc8fc0d6a7f85fd80f234a4590499e55146c8d7
SSDEEP: 24576:Xu83ilfGFuByo/WHLTkpcWJ2+KRz1qsg+Y:pihGBrTkY
Details
File Type: PE32
Yara Hits
YRP/Microsoft_Visual_Studio_NET | YRP/Microsoft_Visual_C_v70_Basic_NET_additional | YRP/Microsoft_Visual_C_Basic_NET | YRP/Microsoft_Visual_Studio_NET_additional | YRP/Microsoft_Visual_C_v70_Basic_NET | YRP/NET_executable_ | YRP/NET_executable | YRP/NETexecutableMicrosoft | YRP/IsPE32 | YRP/IsNET_EXE | YRP/IsWindowsGUI | YRP/domain | YRP/IP | YRP/contentis_base64 |
Source
http://bpcgovyoyo.com/serv/frv2.exe
http://bpcgovyoyo.com/serv/frv2.exe
Strings
		!This program cannot be run in DOS mode.
`.rsrc
@.reloc
r^(	po(
r{1	po(
ro8	po(
r6:	po(
r >	po(
rK@	po(
riG	po(
rhL	po(
r.]	po(
rzd	po(
rLh	po(
r3j	po(
r8l	po(
rsn	po(
rbp	po(
rBt	po(
rj|	po(
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^
Oj.Ab1
-d,l	2
+ d/Y|
z<.I<n
h[poV{n
g^XpaIS
(i\v3zZ
1d2k5p
)0,</2
0U@=HMPCTx
b6@>5"
s0$l=={
_Zu%{v
6iR`Jd
Ra<zBH
h\>!(RZ
8(%1jO
ceyyrgy3	U
0ZaFP.
72 C:q-=$
Dj852r+
@>|O@"3
qsUG1?d
9(YZE!
x3u~0Q
J4.B~4
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^
esfV'Sr
U]q)6#
e?=*gd
=kU*/}
'8^'~Z
UQ`'MX\
!gH^Uw
OJO4_?
,iOX9e
6y,Ieo
*8-r	Q
+-99SC
\5WT9a*
~+XyoM
F/>+g)/
M,k-4!
dr8l$~
f)SY in
s^E$(V3.od
pjN{S(
&fp?>~
H{U-E">
FqLiGl
G;ngh_F{
>H |\0
e<@c\/
V0UEcZ
^jcRj2
rN5WJ-
p3_UNH
eBXwh?
]F1mfjM
vd}Jzj
9	Y OKj<
Dy,65X
vR1'gRS
c|a}k8
Ve|1	W
,f93^#
C)rD=M{[
z?Q&r`
}cLG~c
zlduMo
D%=lq=x!w3&
5vkiG\
02K<n'
dJKt21
nR;H:R
b5{sLv
oD	^*:V
Q~<d36H
~.X;-\
~<cD71
^"Kx%Dy&f/d
$O]j.R
[a]Nuf
WS2(\E-2O
DBQ/I.
Grf@S^
'4Sofp&
!D0Og'
,v!-2^
>#4OM0
:E4dXD\
>Q/f?OG
q!$st<
{2WH4E
cE0^Y]}j
&VOLBQ
Pe&[oK
(MQ"kT
}D2l{?
_!(A4Zb~
A:I$+=k
tCCfRx
T&&mM+
Sl'zZt
LtjOU&
9r^$MD
	L:16>
"K)[BwJ
<PdI] K
E1"f1$O
}In1kN
"Q%GHl=
aU9{:_Gh1$
eM\pX[
j:gqQ:
\)$->p
-G2a8q
?CDW27
|'Kt=[[P
=1?AG?^
O@Y&;F
"<I~o.
\&Hy&{$
$>	4I/=
D64wZbnn
30E3)&
wLH7\q@
q qI44b}
3JX0l/
~}"n^M
M_vzAs+CWb6
|_l8}ka	i<vw
gE\(qI
AX]=\=
$gVFK+
T3#=Fp
Z<VQfYr
]6N'yC4
fjyD{J
"Y&l$L_
5n/	HJyp
E^e,[-
Wr )D[
`T[HVe\
1i& #`
}[`C/xd
kt\<N	
4wmV?|
e5yoB/
ZK{aSwO
/IjE4K	l
p`!<6z`
@N^?\r=9
#8ieD'
("F&=cdR
ryK>*O
bB6r$Q
}@JWra
_aNIl'0uq
Nr-\(r
8\6<_V
u:U=J:
uIZ!!M
{5kC}`
A?vLt7
n^=okhk(
DR)Vz	
g2;D3;
r4-!f&f
FVX8MH
*]z+m]
WA+ceg
%KC>:C
+uojdt
4G'h. 
^A^8Bt
6%?@y>)
/>Z~{H
U0t^?"
(o_F_h
5%Rx2n
OW~7Wh
i|OTqZ
."RPPi
l	Ez9ig
l1DL?s
i<Gf?%I^[
G$~Xp%
'6g-ph
]-#U1`
q2K-Fjd
*oL6"ZO1
e+h=73WJrDw
	d|_6B
e&Kzci3
$d_;c#'0#X
\	q	u	ve
qRL6C."
=IJ&D"
u{=B;h
Pu;U+No
&RMfMeQ
65l>sp,
Yg2VUm
em_ids@_
tau4XU
rCjLtS
6#&*Y{
NZ3'&z
Jy>:tY
W-v R^%gs
$K6_XW
X:2.:%
liin W
V-@r\Bs
m':3Y^
!PfuN~f
w\K&Cq
*r4x|-f
_I;#~kh"y#
zUz#T+
O&$8wedm
X+;_yT
v?YZq[
iS|Rk6
F.$}u4P	
X<4luE
q:eyRCu:
$Zi#?][
h h6Ne
={s&h?
8zy\kY
Z<31[i
SHL{4yA-
kN{hfY
&#*op"{5
UUqk4k[8
6kou%)
nIvU,<
o%BbM'
H.:|K>/
z1?*y[M1
zJTcty
SUFEsdCguR
z+On[!
'm/HY2 
8=I-f$
kHL	zv
0iI@JPwt7
uB zJhw0
*8Sn0`
P$dq7)
0e	L)@
Z3%e,t
24C4v`
)i`wij
6'Rb&O
lXdo"IBj
MU3!x\7
2W@x!D
zzQ3 2tqU_
v	=\'j
-$;6)y
"URB&N
q8cN[N"
Il#gX,t
Sfxo\]p
I^wM;7q
2*kH.m
OJ4,`P
I@.|Qo
~1Dy[%
r/pI^}
!CWThy7
=p(HoBc
afj78!
H&(Y(e*[A
L}ufWH
7gU2\ 3
5kZ~C!
0lz-9I
:Bppk4
pA.\vQC
je>>c'
bJm \>
Rq[59M
]eBb#-
,`Re>8
Fc[4Rq
/:N+p+
z,H`ts
\*s%o~
X7b0{%
l`L^X2.
qZOm#0
&9]CM^q
yX\N?'S 
	r@>{h1q-
xa_w"~
h=!gzB
6fVCSi
7g]IP2
G_g1{\&`
rVO>Ft
d!v%P<pWN
)$qzLX
;eI!)3
HGGh{o
7Rn{[!
q6>k,P
Y]"ecV
<y0+Yj_6H
"{T1=<
mmU^WC
6Zqk`J*	z
v2.0.50727
#Strings
<Module>
mscorlib
Microsoft.VisualBasic
MyApplication
MyComputer
MyProject
MyWebServices
ThreadSafeObjectProvider`1
Microsoft.VisualBasic.ApplicationServices
ApplicationBase
Microsoft.VisualBasic.Devices
Computer
System
Object
.cctor
get_Computer
m_ComputerObjectProvider
get_Application
m_AppObjectProvider
get_User
m_UserObjectProvider
get_WebServices
m_MyWebServicesObjectProvider
Application
WebServices
Equals
GetHashCode
GetType
ToString
Create__Instance__
instance
Dispose__Instance__
get_GetInstance
m_ThreadStaticValue
GetInstance
System.ComponentModel
EditorBrowsableAttribute
EditorBrowsableState
System.CodeDom.Compiler
GeneratedCodeAttribute
System.Diagnostics
DebuggerHiddenAttribute
Microsoft.VisualBasic.CompilerServices
StandardModuleAttribute
HideModuleNameAttribute
System.ComponentModel.Design
HelpKeywordAttribute
System.Runtime.CompilerServices
RuntimeHelpers
GetObjectValue
RuntimeTypeHandle
GetTypeFromHandle
Activator
CreateInstance
MyGroupCollectionAttribute
System.Runtime.InteropServices
ComVisibleAttribute
ThreadStaticAttribute
CompilerGeneratedAttribute
NewLateBinding
LateGet
Operators
MultiplyObject
SubtractObject
Conversions
ToInteger
ToByte
LateIndexGet
LateIndexSet
System.Collections.Generic
List`1
System.Text
Encoding
get_Default
GetString
String
Concat
Boolean
ChangeType
ModObject
STAThreadAttribute
ZD.Resources.resources
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
System.Reflection
AssemblyFileVersionAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
AssemblyCompanyAttribute
AssemblyDescriptionAttribute
AssemblyTitleAttribute
frv2.exe
MyTemplate
8.0.0.0
My.WebServices
My.Application
My.Computer
My.User
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
WrapNonExceptionThrows
	11.11.6.7
(c) Diebold Incorporated
Diebold Incorporated starter
Diebold Incorporated Company
Diebold Incorporated Launcher
Diebold Incorporated
_CorExeMain
mscoree.dll
dIDATx