Suspect
PE Executable
MD5: 11806b44f7acbe619c1c7e0a48e758d5
Size: 878.59 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 11806b44f7acbe619c1c7e0a48e758d5 |
| Sha1 | 7b70104c2cd29a5eae6db8c58972fc9f49cfe324 |
| Sha256 | 52456d908d99b33a3dfc07c2e17a4e2dff6e9488bb0f36fe2e240a3d24ba00b2 |
| Sha384 | 95e4e034b3f2da5bb30e1f943109da3b967d93133740ffedd95c4ad86a40bed9cfd77ac5daf1fd489626f749ddb443f6 |
| Sha512 | 9b0b421004281aeb880cd9a4e1605ea23b09f071c0b90120aea7e4d74ee1c4f3cec38e6a3b175c0e752b52586067b1d0f17f09145255bf8a6951d484748c2a43 |
| SSDeep | 12288:EbSn/KgsCfBQyg7oZisqtksOtgg+WLyDrQ9/7WxdtbiqCr8Ao4oBgoV+:Ebg7WyclOoWLuyWf1wloS |
| TLSH | B915CF5073F99207E1BF6BB5A4B209060B77F9529536D79E08C8A0AD0EE3791CE503B7 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: ? |
| Module Name | Client.exe |
| Full Name | Client.exe |
| EntryPoint | System.Void yogahgupfjiiflyiwohguvzpamn.TKoULIfswbgKuBEZtq0ikuEyBW::Main() |
| Scope Name | Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 1.7.4.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 1524 |
| Main Method | System.Void yogahgupfjiiflyiwohguvzpamn.TKoULIfswbgKuBEZtq0ikuEyBW::Main() |
| Main IL Instruction Count | 11 |
| Main IL | |
| Module Name | Client.exe |
| Full Name | Client.exe |
| EntryPoint | System.Void yogahgupfjiiflyiwohguvzpamn.TKoULIfswbgKuBEZtq0ikuEyBW::Main() |
| Scope Name | Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 1.7.4.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 1524 |
| Main Method | System.Void yogahgupfjiiflyiwohguvzpamn.TKoULIfswbgKuBEZtq0ikuEyBW::Main() |
| Main IL Instruction Count | 11 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.