Sample details: d9b5b26f0423230e99768092f17919a3 --

Hashes
MD5: d9b5b26f0423230e99768092f17919a3
SHA1: fa1c20914e200d696e19135cb8388ea012ba953b
SHA256: 19690e5b862042d9011dbdd92504f5012c08d51efca36828a5e9bdfe27d88842
SSDEEP: 192:coYvRdqq9jGvEQbT8wLgqqkWDgxHWcG4l5GeeIb/s:DU4wjQ38dxkiP4Oeb
Details
File Type: PE32
Yara Hits
YRP/Visual_Cpp_2005_DLL_Microsoft | YRP/Visual_Cpp_2003_DLL_Microsoft | YRP/IsPE32 | YRP/IsDLL | YRP/IsWindowsGUI | YRP/IsBeyondImageSize | YRP/HasRichSignature | YRP/domain | YRP/contentis_base64 | FlorianRoth/DragonFly_APT_Sep17_3 |
Parent Files
ac22586c7643432adf8ccdf388e8ba66
Source
Strings
		!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
UVWjFj
L$4_^][3
URPQQh|
v	N+D$
UQPXY]Y[
    (%d bytes hidden)
\x%02x
```hhh
xppwpp
KERNEL32.dll
TbPutBuff
TbMalloc
tibe-2.dll
Parameter_UString_getValue
Params_findParameter
trch-1.dll
strncpy
_snprintf
memset
isprint
strncat
sprintf
memcpy
fwrite
msvcrt.dll
malloc
_XcptFilter
_initterm
_amsg_exit
_adjust_fdiv
RtlUnwind
InterlockedExchange
InterlockedCompareExchange
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
esco-0.dll
HexDumpShort
HexStr
ReadSizedBufferFromFile
ReadSizedBufferFromParameter
TbUniStrToSizedBuffer
WriteSizedBufferToFile
isAscii
REG_NONE
REG_SZ
REG_EXPAND_SZ
REG_BINARY
REG_DWORD
REG_DWORD_LITTLE_ENDIAN
REG_DWORD_BIG_ENDIAN
REG_LINK
REG_MULTI_SZ
REG_RESOURCE_LIST
REG_FULL_RESOURCE_DESCRIPTOR
REG_QWORD
REG_QWORD_LITTLE_ENDIAN
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
  <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
    <security>
      <requestedPrivileges>
        <requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
      </requestedPrivileges>
    </security>
  </trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
40k0v0
1#1B1G1O1~1
22282@2I2V2[2b2
6(707H7
7#9+909L9T9^9i9
:!:8:>:R:X:e:u:
<%=P=V=\=b=h=n=u=|=
> >+>4>
0#0C0P0\0d0l0x0
2 2<2@2