Suspect
PE Executable
MD5: 1f8f1a5de4f7ca72c5f02eb84ff22917
Size: 5.08 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 1f8f1a5de4f7ca72c5f02eb84ff22917 |
| Sha1 | 03194c385186d3c30598c5f0ead51b4e1638cdd7 |
| Sha256 | 7a3ea1f8ddff3751f6148c6f7da2aa702ad053ba7c7a182b9a94faf2b3b44a43 |
| Sha384 | 3f2bd5ab219f4cc006778714489843793362d8000fb45dc33845b616f3a75a19cfdc940f17f1a81335537729afeea306 |
| Sha512 | b2dd328b1a1803a62910c0f3d96845437a0331a3de14eb139d0808c0ffbbdf3212124372b19cf72d5adb74581e14f2f6378c4cd273e38325af826f43203ea6c0 |
| SSDeep | 98304:0Kxh1pmniRvew+9r+4G1nHI2uGhRvnE/wHIvO97N:b7pmvwKq4G1o2u+RfCwHKQ7N |
| TLSH | 723633558BF5263AF8BAD03DEDEA045D9F257C40E72FC94E0E405872A92ED04E4D9BC2 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | |
| Module Name | DownloaderApp.exe |
| Full Name | DownloaderApp.exe |
| EntryPoint | System.Void A.B::Main(System.String[]) |
| Scope Name | DownloaderApp.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | DownloaderApp |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 29 |
| Main Method | System.Void A.B::Main(System.String[]) |
| Main IL Instruction Count | 146 |
| Main IL | |
| Module Name | DownloaderApp.exe |
| Full Name | DownloaderApp.exe |
| EntryPoint | System.Void A.B::Main(System.String[]) |
| Scope Name | DownloaderApp.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | DownloaderApp |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 29 |
| Main Method | System.Void A.B::Main(System.String[]) |
| Main IL Instruction Count | 146 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.