Suspect
PE Executable
MD5: 201c3977a10f73542515e22b07dad335
Size: 1.15 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
High
| MD5 | 201c3977a10f73542515e22b07dad335 |
| Sha1 | 701fd7cbf22c14077bdd70883dd2eafbdd0074b3 |
| Sha256 | 94acc5bde1e48ce426bc61ea90a8780cf2be98795aaba7d946d5fe9d43b3203d |
| Sha384 | e21acae59a9fe9fac1e8ee59ed5aed7973bdd9aab4259f7b43d032ff92232bab1c51c3117712d0f668f21051931d23f8 |
| Sha512 | 876a9d1686bd8513f72e8e9c00b95a453473e672db390535dc190c27acb1c160f1397912483e45d38aa5e878bf1344f6aeca9b68c540dc3f2786e83f3e240c2c |
| SSDeep | 24576:g8S22IQTi0dSJIo/n/jR2aVE46ssWn5tKfjxQ/6R:gnTi0dSJjn/jE8J5LKbey |
| TLSH | 7435DF00621BDA33C9163B71D9B3E2F406A45E44E821C23F5AE97EB77F76F751885282 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
No STICH Path has been generated for this analysis yet.
2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2| Name | Value |
|---|---|
| Module Name | kGtz.exe |
| Full Name | kGtz.exe |
| EntryPoint | System.Void rA.lx::fF() |
| Scope Name | kGtz.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | kGtz |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 323 |
| Main Method | System.Void rA.lx::fF() |
| Main IL Instruction Count | 20 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | kGtz.exe |
| Full Name | kGtz.exe |
| EntryPoint | System.Void rA.lx::fF() |
| Scope Name | kGtz.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | kGtz |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 323 |
| Main Method | System.Void rA.lx::fF() |
| Main IL Instruction Count | 20 |
| Main IL | |