Suspicious
Suspect

2f747ee39f63980282f3cbf307e7c598

PE Executable
MD5: 2f747ee39f63980282f3cbf307e7c598
Size: 2.7 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 2f747ee39f63980282f3cbf307e7c598
Sha1 ae765964d427ac11e03d2095f87e0ff95cc6faba
Sha256 d607bfcbe22d2dd7d7a40172c2c5e1680d5d1132c8cab4b2ce51b57ca84fe997
Sha384 dd287faecbed37ac454e9b1137291db11474753b4908df382e666c63b103c4b6308b842cec8459353eb07eb1ba0ce0a4
Sha512 2d59f1ff3ca9f26da59c5fb93601cba303c93fb2c2f93bdbfa2a33b8929c4bda26bcca288cc6d13ea807719288ab3c94dea737f9958712ec0bbe5039ffa786c0
SSDeep 24576:nG2E3pEGxXjePOMWVPtavH0vL6lQd+keNENq+0vmLax:GJ3PXIzvwEOq+ZW
TLSH 4CC52D342EEA102AB173FF7D8AE47596DA5FBBA33707585D10A1038A0723A42DDD153E
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
WT6c4w9OXhoblS
Full Name
WT6c4w9OXhoblS
EntryPoint
System.Void 74V.PEs::627()
Scope Name
WT6c4w9OXhoblS
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Fcftq4EZsgBUluB
Assembly Version
0.0.8.3
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1779
Main Method
System.Void 74V.PEs::627()
Main IL Instruction Count
5
Main IL
nop <null>
ldsfld ab2.2J2 74V.PEs::792
callvirt System.Void ab2.2J2::nC6()
nop <null>
ret <null>
Module Name
WT6c4w9OXhoblS
Full Name
WT6c4w9OXhoblS
EntryPoint
System.Void 74V.PEs::627()
Scope Name
WT6c4w9OXhoblS
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Fcftq4EZsgBUluB
Assembly Version
0.0.8.3
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1779
Main Method
System.Void 74V.PEs::627()
Main IL Instruction Count
5
Main IL
nop <null>
ldsfld ab2.2J2 74V.PEs::792
callvirt System.Void ab2.2J2::nC6()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙