Suspect
PE Executable
MD5: 21a851b499504026c3311b6133c74e6b
Size: 689.66 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | 21a851b499504026c3311b6133c74e6b |
| Sha1 | 147d09e580a93084868263ceb4c34e76b3ea3b9a |
| Sha256 | d884d75821203a8a1dd656f7caa2980ef3d2ef873b7968f4472fefc291d1caab |
| Sha384 | 231a671329364bb84275a8629f1ae4e19de75eca3a973ec0eae5f5e6947e9ace6bc4b375653c37b64acb78c120649f68 |
| Sha512 | e026452188a04636a49af27002db7628e2d2dc096e15e6540f534de1ea8d7b7caa7a92671f84e6140ac07c322a85818545bcc03eb2d4e636a004391606a6dc61 |
| SSDeep | 12288:yeQOUXCcFVrTIDUuNw8ycDT4y3MaXKSLQT+qM+Eo3dQcd3ZHqtNR+2As3l36P+So:yhOWhGUuN7L318SqM+WW3ZHqti2As3 |
| TLSH | A7E4BF9C3254B59FC463CA728D64DE74AA207CAA9717C20391E31DAFB90D687DE142F3 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | gyDE.exe |
| Full Name | gyDE.exe |
| EntryPoint | System.Void ClipboardAnalyzer.Program::Main() |
| Scope Name | gyDE.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | gyDE |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 367 |
| Main Method | System.Void ClipboardAnalyzer.Program::Main() |
| Main IL Instruction Count | 37 |
| Main IL | |
| Module Name | gyDE.exe |
| Full Name | gyDE.exe |
| EntryPoint | System.Void ClipboardAnalyzer.Program::Main() |
| Scope Name | gyDE.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | gyDE |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 367 |
| Main Method | System.Void ClipboardAnalyzer.Program::Main() |
| Main IL Instruction Count | 37 |
| Main IL | |