Sample details: df6978ae5cb0eb6be63479086a90b9ff --

Hashes
MD5: df6978ae5cb0eb6be63479086a90b9ff
SHA1: 29aa397f0de514d797e142e971aebaf27b42f1b4
SHA256: f5d0c38dfb7f1163258bd655414728e2d67410a544e25414754c35c886c19c62
SSDEEP: 48:6k8fwNSnGl+/bvtRbmSrlc6nI1PctJBNZDK6jTtIknxlcXAcnLIOsauliSC75q:CnGm3x1I1PYjdeKOk7C
Details
File Type: PE32
Yara Hits
YRP/Microsoft_Visual_Studio_NET | YRP/Microsoft_Visual_C_v70_Basic_NET_additional | YRP/Microsoft_Visual_C_Basic_NET | YRP/Microsoft_Visual_Studio_NET_additional | YRP/Microsoft_Visual_C_v70_Basic_NET | YRP/NET_executable_ | YRP/NET_executable | YRP/NETDLLMicrosoft | YRP/IsPE32 | YRP/IsNET_DLL | YRP/IsDLL | YRP/IsConsole | YRP/IsBeyondImageSize | YRP/domain | YRP/IP | YRP/contentis_base64 | FlorianRoth/DragonFly_APT_Sep17_3 |
Source
http://103.68.190.250/Sources//Advance/WndRec/Player/obj/Release/TempPE/Properties.Resources.Designer.cs.dll
Strings
		!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v2.0.50727
#Strings
<Module>
Properties.Resources.Designer.cs.dll
Resources
Player.Properties
Settings
mscorlib
System
Object
System.Configuration
ApplicationSettingsBase
System.Resources
ResourceManager
resourceMan
System.Globalization
CultureInfo
resourceCulture
get_ResourceManager
get_Culture
set_Culture
System.Drawing
Bitmap
get_filter
get_forward
get_fullscreen
get_pause
get_play
get_stop
Culture
filter
forward
fullscreen
defaultInstance
get_Default
Default
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
Properties.Resources.Designer.cs
System.CodeDom.Compiler
GeneratedCodeAttribute
System.Diagnostics
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
ReferenceEquals
RuntimeTypeHandle
GetTypeFromHandle
System.Reflection
Assembly
get_Assembly
GetObject
System.ComponentModel
EditorBrowsableAttribute
EditorBrowsableState
.cctor
SettingsBase
Synchronized
3System.Resources.Tools.StronglyTypedResourceBuilder
2.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
9.0.0.0
WrapNonExceptionThrows
_CorDllMain
mscoree.dll