Suspect
109c5292bbe9f481bc2e0b6981d0c1b4
PE Executable
MD5: 109c5292bbe9f481bc2e0b6981d0c1b4
Size: 207.87 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | 109c5292bbe9f481bc2e0b6981d0c1b4 |
| Sha1 | b77a5bd6d3ae0d33c80835f5bad8fa496970ad92 |
| Sha256 | d21ecef0c570555f7b5ce5e62d1852c1de48fa97f834fd48b5efb53c0a605872 |
| Sha384 | 53bc26fdfb71aedf61067130c30566da7df7404fe19b39d2c28489a62ecb79502ab98652668a4a9c2068876c799492e5 |
| Sha512 | 9caa61fe0038a81fff7725aecb8a491deffa0902ed3a2ed76c0ecaacf390f286aedd2d818dc2ca8dd3bea2a5d03228b97a0298aa8d5a7d8a2dd39df52e9f9f77 |
| SSDeep | 3072:MzEqV6B1jHa6dtJ10jgvzcgi+oG/j9iaMP2s/HIjBC/Ma/FfqL4m1FYeRBtm23A:MLV6Bta6dtJmakIM5d/BFCh1FjM23A |
| TLSH | 3C14CF167BA9492FE29E867D611202138379C2E399C3F3EE28D464B78F667E406071D7 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
No STICH Path has been generated for this analysis yet.
2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | NanoCore Client.exe |
| Full Name | NanoCore Client.exe |
| EntryPoint | System.Void ClientLoaderForm::Main() |
| Scope Name | NanoCore Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v2.0.50727 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | NanoCore Client |
| Assembly Version | 1.2.2.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 2 |
| Main Method | System.Void ClientLoaderForm::Main() |
| Main IL Instruction Count | 4 |
| Main IL | |
| Module Name | NanoCore Client.exe |
| Full Name | NanoCore Client.exe |
| EntryPoint | System.Void ClientLoaderForm::Main() |
| Scope Name | NanoCore Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v2.0.50727 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | NanoCore Client |
| Assembly Version | 1.2.2.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 2 |
| Main Method | System.Void ClientLoaderForm::Main() |
| Main IL Instruction Count | 4 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.