Suspect
PE Executable
MD5: 12a289bdf1aec09a981dff99979cb8bb
Size: 1 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 12a289bdf1aec09a981dff99979cb8bb |
| Sha1 | b134abf59b77f0d8ddb4596cad72101ba2ed88ac |
| Sha256 | 806f226d65cd883f71504ed0cd9f7e4b0dbf837d1fdd3688c82a7a53e66c2bf0 |
| Sha384 | 614414d629753a18a4b4ca6307f6960638b7bfc0c1b8b0631cde06f30a0dab3e8f12609d7115142d8c581e12a9abcdd9 |
| Sha512 | c2f4bea0315098ee4885dd98a6d0d7c552a3cd97899d6f3898f8f78c245220aa123fa15d87494f3ac4bd40d6f57923860562ac6cebb57d31e2b00cb3f8054b86 |
| SSDeep | 24576:fcXxiVYd8Grq7zkFVZDUfe1Kaa4eRrvkas3mucG5K:fcBiRGtEe4D48rvS3mj |
| TLSH | AD25220C2659CF17CAAB1BF60D55D27123781DCE6C20DA0A1FC5AEEF3A68B650D50B93 |
STICH
beta
No STICH Path has been generated for this analysis yet.
3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2img
1| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | gEXr.exe |
| Full Name | gEXr.exe |
| EntryPoint | System.Void SaltPan.Program::Main() |
| Scope Name | gEXr.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | gEXr |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 262 |
| Main Method | System.Void SaltPan.Program::Main() |
| Main IL Instruction Count | 10 |
| Main IL | |