Suspect
PE Executable
MD5: 2fa1c8558303b87118a43f000240e817
Size: 1.82 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | 2fa1c8558303b87118a43f000240e817 |
| Sha1 | 4585a1b23eb51277056ec26926ac316788c23b45 |
| Sha256 | 9cbffe3435e4218fbfebedbbc72a2e587098bdd9eb4a4b3014a38d1d9869817b |
| Sha384 | 21d96b256b5bd85e136e74248f04cff4e49588b21c0652bb04d9e4cbe2021a78b21d4f103d0fde75b260ac3143583499 |
| Sha512 | 0dcb29c6f8440171b0b25a92bde017f5fc7235d3dc32ed76d7c008595ff9d73b27e4292754fedf1163d1e4f6826453cf219e474a6d9f911b0f61c850d8adc61d |
| SSDeep | 24576:laYY1OiddVoCLrMfwTo3//eu9BrV7qIt5ERqWLmboBhRyH:dY1OKvrMeov/VVmICF4H |
| TLSH | A585011453E49A18F9BF9B38983955A753F1FCC7EA76DB0D664870EE0D21B81CA90323 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | 8Wdiqq |
| Full Name | 8Wdiqq |
| EntryPoint | System.Void 8Wdiqq.im1A2qWw/6ciGE.Dr4a5wiEyH8o::Fdc6k8mWDie40() |
| Scope Name | 8Wdiqq |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | 8Wdiqq |
| Assembly Version | 20.18.48.267 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.6 |
| Total Strings | 1150 |
| Main Method | System.Void 8Wdiqq.im1A2qWw/6ciGE.Dr4a5wiEyH8o::Fdc6k8mWDie40() |
| Main IL Instruction Count | 87 |
| Main IL | |
| Module Name | 8Wdiqq |
| Full Name | 8Wdiqq |
| EntryPoint | System.Void 8Wdiqq.im1A2qWw/6ciGE.Dr4a5wiEyH8o::Fdc6k8mWDie40() |
| Scope Name | 8Wdiqq |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | 8Wdiqq |
| Assembly Version | 20.18.48.267 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.6 |
| Total Strings | 1150 |
| Main Method | System.Void 8Wdiqq.im1A2qWw/6ciGE.Dr4a5wiEyH8o::Fdc6k8mWDie40() |
| Main IL Instruction Count | 87 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.