Suspect
PE Executable
MD5: 2d1e4ee926a2afd06353d3aec169d92d
Size: 688.64 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 2d1e4ee926a2afd06353d3aec169d92d |
| Sha1 | 4df7b1836b73ca87bef6880a8201ce84ea4657a6 |
| Sha256 | f0b9b0fcc5688be094fe596b2c69681a8e37206d82e551844d7dbcb6c6118d84 |
| Sha384 | 67d0ecf7365fb22cea05b348890fc21eb1d34ed8b3436be91eecf713f873023b03f10f1c1dc5da19385c230c064a7d50 |
| Sha512 | 30f2af7a28d57a917bb252b9941a38cec48a2e2c12d4e634a02ce7b4cf68b83cdf80ec284996e63ba247a10adbad3f964472870d415f7a77235a3e0bc2dfd499 |
| SSDeep | 12288:Y81q04aHnAOaCyKPnppduuKjGfJedcVfvZ0r8omqlYvSdjb:vq09nRxycpEJjG9dv7gjb |
| TLSH | 10E41255392DDC03D0BA0EF50E91C57923B99D8DA622C7D2AFCA2DEBF1E17912841363 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
| Name | Value |
|---|---|
| Module Name | famK.exe |
| Full Name | famK.exe |
| EntryPoint | System.Void SectorRepair.Program::Main() |
| Scope Name | famK.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | famK |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 320 |
| Main Method | System.Void SectorRepair.Program::Main() |
| Main IL Instruction Count | 7 |
| Main IL | |
| Module Name | famK.exe |
| Full Name | famK.exe |
| EntryPoint | System.Void SectorRepair.Program::Main() |
| Scope Name | famK.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | famK |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 320 |
| Main Method | System.Void SectorRepair.Program::Main() |
| Main IL Instruction Count | 7 |
| Main IL | |
Embedded Resources
UNKNWOWNsuspect
5huhuhuhu
Suspicious Type Names (1-2 chars)
UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential