October 2018
Beginner to intermediate
436 pages
9h 36m
English
The following table concerns the file elements we found.
The original file is a UPX-packed Win32 executable file.
| Filename | whatami.exe |
| File size | 28,672 bytes |
| MD5 | F4723E35D83B10AD72EC32D2ECC61091 |
| SHA-1 | 4A1E8A976F1515CE3F7F86F814B1235B7D18A231 |
| File type | Win32 PE file – packed with UPX v3.0 |
The UPX unpacked version gives us this new information about the file:
| Filename | whatami.exe |
| File size | 73,728 bytes |
| MD5 | 18F86337C492E834B1771CC57FB2175D |
| SHA-1 | C8601593E7DC27D97EFC29CBFF90612A265A248E |
| File type | Win32 PE file – compiled by Microsoft Visual C++ 8 |
The program maps an unknown PE file using process hollowing. This PE file contains the following information:
| File size | 53,248 bytes |
| MD5 | DD073CBC4BE74CF1BD0379BA468AE950 ... |
Read now
Unlock full access