Suspect
051efd15a1c7d57e40e72e073898f0c4
PE Executable
MD5: 051efd15a1c7d57e40e72e073898f0c4
Size: 556.03 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | 051efd15a1c7d57e40e72e073898f0c4 |
| Sha1 | adae76131545cff4348f11066fea2eedef145cb9 |
| Sha256 | 7146aa6b97153b033def7ea490d8a5f24c1f0140855db29311b9e81ba132cb2b |
| Sha384 | 1d5452645ff72bb6dad0d3ebc03267e40bc588e4ec194852f3179b8f7a37f1c73ca4e394a93ce07784a76cdfea6aeb8d |
| Sha512 | d2badc85972e719b02cb39e15c01baf5405609a2f36f3db6fefe8f1b46b16aa670b00ba68bf1d435ce4680b4cc2b44611c5ea5cbcbd379b38e7129a478f9b2b6 |
| SSDeep | 12288:JLV6BtpmkjMNl+Xzca9ymmOxGbo5YJAJg1pnjP1oEA/2Dq:xApfolSzpmIGU54119jWtp |
| TLSH | A9C4025A73E94A2FE2DE8A7AA0221502937CC1E398D3F3EE15C855B78F257E006471D7 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
No STICH Path has been generated for this analysis yet.
2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | NanoCore Client.exe |
| Full Name | NanoCore Client.exe |
| EntryPoint | System.Void ClientLoaderForm::Main() |
| Scope Name | NanoCore Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v2.0.50727 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | NanoCore Client |
| Assembly Version | 1.2.2.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 2 |
| Main Method | System.Void ClientLoaderForm::Main() |
| Main IL Instruction Count | 4 |
| Main IL | |
| Module Name | NanoCore Client.exe |
| Full Name | NanoCore Client.exe |
| EntryPoint | System.Void ClientLoaderForm::Main() |
| Scope Name | NanoCore Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v2.0.50727 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | NanoCore Client |
| Assembly Version | 1.2.2.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 2 |
| Main Method | System.Void ClientLoaderForm::Main() |
| Main IL Instruction Count | 4 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.