Suspect
PE Executable
MD5: 1a4b49379f3da71c8d7d828535298376
Size: 1.63 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 1a4b49379f3da71c8d7d828535298376 |
| Sha1 | 7360fcfbf857c151f23ce283cba6d268fade0a1f |
| Sha256 | 2b7dbba7689d6c299e1bb956a0a7ea21b457f523c25f67a3b39c5ddef8ea2543 |
| Sha384 | 3bd8d12159781fae793266568a929872f3d882db7f4f4ea31b849e1f7f14844fbb55b2317aa038b920231e88eb608099 |
| Sha512 | c7f90ab5d200dec39092dbe9faaff132ece5261b6461fe98c88ccad3584da7682ceb8e8c4d51be72f432b4ad266bf61dde07f6764800fcc95c5e6d70acf7d791 |
| SSDeep | 49152:GUsAQJBp4etpi/B9RW04IunIX1qKfiHlzvS:GPqOaLvinIA7FDS |
| TLSH | 937522885A46EA0AC995473C0A61F7F40B784EDDE511D2076FDCBEFBB6B5E168C102C2 |
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
STICH
beta
No STICH Path has been generated for this analysis yet.
3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2img
1| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: C:\Users\Administrator\Desktop\Client\Temp\wQcYnywFLf\src\obj\Debug\Kalb.pdb |
| Module Name | Kalb.exe |
| Full Name | Kalb.exe |
| EntryPoint | System.Void SpaceFactoryTycoon.Program::Main() |
| Scope Name | Kalb.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Kalb |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 53 |
| Main Method | System.Void SpaceFactoryTycoon.Program::Main() |
| Main IL Instruction Count | 10 |
| Main IL | |