Benign Download

Virus.Win32.Epoe.1048

Tiny PE by file sizePE lacks signature record
SHA-2564e8d893ead3896610e909515983b6f034d46b34f1d9310aa912ed304c84d39de

Evidence

Reads PE e_lfanew offset in code 0x330–0x390
0x330898d24ffffffe8450100000bc00f8405..$....E........
0x3400100006681384d5a0f85fa0000008bd0...f.8MZ........
0x3508b403c03c266813850450f85e8000000.@<..f.8PE......
0x36081784c45504f450f84db000000ff703c.xLEPOE.......p<
⋯3 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.