Suspect
PE Executable
MD5: 2e9c79df410935aae84fea6646f27a22
Size: 584.7 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 2e9c79df410935aae84fea6646f27a22 |
| Sha1 | 8488107cb4d7f0494fd1f1acf18cee393c9c71b5 |
| Sha256 | 4584961d984b24c73125b00aef61f6c49d2d6ff73faf7aa3e73d4a0d0e132ac0 |
| Sha384 | a001177767c66855c72ae8ee0c2442dcb9ea60597e5cd67f01304b56b6a56b4dcdc64180cc3c1123aa06082e8c5626a0 |
| Sha512 | f2ccc6e9fc85d95b75c53ac62cf0786c8cacac397c87a314b45d516043076603db969f8b2252caa0687a61a6357b909998315aa6649a9b849be67e089f44cc17 |
| SSDeep | 12288:VLwAW+7FmNNmzL//Hhkysl49yGqhEtK59:VLF7FUNmf/HeyKJ59 |
| TLSH | 8CC4E054FE63A402F85453B34BA2FAB5B2695D2D90C0C2B57EF4EEEB746DA011F23142 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
| Name | Value |
|---|---|
| Module Name | Irh.exe |
| Full Name | Irh.exe |
| EntryPoint | System.Void HoqueLtd.Program::Main() |
| Scope Name | Irh.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Irh |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 169 |
| Main Method | System.Void HoqueLtd.Program::Main() |
| Main IL Instruction Count | 6 |
| Main IL | |
| Module Name | Irh.exe |
| Full Name | Irh.exe |
| EntryPoint | System.Void HoqueLtd.Program::Main() |
| Scope Name | Irh.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Irh |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 169 |
| Main Method | System.Void HoqueLtd.Program::Main() |
| Main IL Instruction Count | 6 |
| Main IL | |
PDB Path
PATH
?huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential