Suspicious
Suspect

PE Executable
MD5: 25b32c1cf2dfa18426d5836631f7ae80
Size: 802.3 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 25b32c1cf2dfa18426d5836631f7ae80
Sha1 6bc971abefbd5bf5b5b8c2b542a0c6b511a16121
Sha256 2d460e887cab8b04d177abcde12caaf3fc92da243a8774b04a46ae77fa0f2891
Sha384 06c730f23691f200fe163eb68e834e2979fda2770d5e2accdf91e4848957498cc382bcfdcd84e7972493b2267653fc86
Sha512 3ce300b80e53f3e8568ee8f6e6a9b86be1d4b9b3419f88e40aa2bace337338e7fdb95d76326b2b8702cbe0626bc814c8497cdd12be607ddc2ebb40f6e9ce7f73
SSDeep 12288:mN2N7fN2jNouec0DW4fuedxRaJnCHFxIdOQ2RxkRh8iP/ZT0erQtZydyIBvguY9P:mN2r2j6dDDfBxRhbjxI5/Np/eH
TLSH C40575342EEA1029F177AF7D8AE47596EA6EB6A33707994D00B103C60723B42DDD153E
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
oNhln9lq3i
Full Name
oNhln9lq3i
EntryPoint
System.Void 74V.PEs::627()
Scope Name
oNhln9lq3i
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DB9farRJATwBRmyX
Assembly Version
6.7.3.8
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1779
Main Method
System.Void 74V.PEs::627()
Main IL Instruction Count
5
Main IL
nop <null>
ldsfld ab2.2J2 74V.PEs::792
callvirt System.Void ab2.2J2::nC6()
nop <null>
ret <null>
Module Name
oNhln9lq3i
Full Name
oNhln9lq3i
EntryPoint
System.Void 74V.PEs::627()
Scope Name
oNhln9lq3i
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DB9farRJATwBRmyX
Assembly Version
6.7.3.8
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1779
Main Method
System.Void 74V.PEs::627()
Main IL Instruction Count
5
Main IL
nop <null>
ldsfld ab2.2J2 74V.PEs::792
callvirt System.Void ab2.2J2::nC6()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙