Suspicious
Suspect

2364e66445ca1979af264a4bad48e152

PE Executable
MD5: 2364e66445ca1979af264a4bad48e152
Size: 802.3 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 2364e66445ca1979af264a4bad48e152
Sha1 851ce73429734f7bfae068e77515c32de23a8c8e
Sha256 e945de86856a0a84ba5655d2f379d7b6ecedfcd9d8a0bdf3ac0cb17161240521
Sha384 28973c77e47d173878624da681ffa21232ab6cb23c71ba97ba4fb1e1a74aabceb34aec43b6aaacdda0c9677c4c1344f7
Sha512 5fa9e81acb9aeef740100f78554596b9e174a0cd2cc5b17595b32680c46d44b38afaf2cacec8138d704d17ae4f1f4eaaa208901dab66af974b6b9d67fcbd890f
SSDeep 12288:WN2N7fN2jNouec0DW4fuedxRaJnCHFxIdOQ2RxkRh8iP/ZT0erQtZydyIBvguY9u:WN2r2j6dDDfBxRhbjxI5/Np/eH
TLSH 850575342EEA1029F177AF7D8AE47596EA6EB6A33707994D00B103C60723B42DDD153E
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
oNhln9lq3i
Full Name
oNhln9lq3i
EntryPoint
System.Void 74V.PEs::627()
Scope Name
oNhln9lq3i
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DB9farRJATwBRmyX
Assembly Version
6.7.3.8
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1779
Main Method
System.Void 74V.PEs::627()
Main IL Instruction Count
5
Main IL
nop <null>
ldsfld ab2.2J2 74V.PEs::792
callvirt System.Void ab2.2J2::nC6()
nop <null>
ret <null>
Module Name
oNhln9lq3i
Full Name
oNhln9lq3i
EntryPoint
System.Void 74V.PEs::627()
Scope Name
oNhln9lq3i
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DB9farRJATwBRmyX
Assembly Version
6.7.3.8
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1779
Main Method
System.Void 74V.PEs::627()
Main IL Instruction Count
5
Main IL
nop <null>
ldsfld ab2.2J2 74V.PEs::792
callvirt System.Void ab2.2J2::nC6()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙