-
Notifications
You must be signed in to change notification settings - Fork 29
Collected data
nheijmans edited this page Jul 19, 2016
·
4 revisions
Portable Executable
Office Documents
ZIP files
E-mails
Other-files
- Filename of the sample
- Filetype
- Filesize
- MD5 hash
- SHA-1 hash
- PE hash
- Fuzzy hash
- Imphash
- YARA rules that match
- PE compile time
- Imported DLL's
- PE packer information (if available)
- PE language
- Original filename (if available)
- Strings
- MD5
- SHA-1
- Filetype
- Filename
- Indicators (with olevba)
- MD5
- SHA-1
- Files in ZIP (each file will be pushed for static analysis)
- Filesize
- Filetype
- From
- To
- CC
- BCC
- Subject
- Date
- Attachments (will be pushed for static analysis as well)
- Msg_id
- attachment filenames
- URL's from the message body
- Filename
- Filetype
- Filesize
- MD5
- SHA-1
- YARA results