Suspect
PE Executable
MD5: 315de9579fb7d98cefcd42338816b3e1
Size: 5.62 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | 315de9579fb7d98cefcd42338816b3e1 |
| Sha1 | 8cca41d5fe9717a50b7bdb361915b75655304157 |
| Sha256 | 75e978c27e6262cb702ceeb675c1daee950e477e0f5be0f7f65b834ea1b91682 |
| Sha384 | 2f75a495563f1aa670af15ab00b8d2ce95f7e341ea6ac38ba7a4056e718350b115705b1f6a9f2193c35adc02c48db03d |
| Sha512 | 9f3750a09a1a026ceac50aa752415d53f107682260dc33d7ec695a67a37ebdb5b766e0cd3a0188209aee90d29356ca60ace33396cf7e13ed8a621fd4f688a580 |
| SSDeep | 98304:YE4FFbyuKmKBUVksBHhsuMvgPQSa3v0fRT9Q37PE4rm:YZCUGsBHBMIPQSrT9Ibr |
| TLSH | 8346222221C5AE95E53F87B8843C85C193F37E0FBF11C79D79992A8CAE013866763653 |
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NETUPolyX 0.3 -> delikon
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | 8j_BbZc3yc |
| Full Name | 8j_BbZc3yc |
| EntryPoint | System.Void 8j_BbZc3yc.xQd02mNeXpy6/Knj0_b5.ai0DG5yb6fCkc::Tdj2y3PsgJ() |
| Scope Name | 8j_BbZc3yc |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | 8j_BbZc3yc |
| Assembly Version | 24.12.25.33 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.6 |
| Total Strings | 912 |
| Main Method | System.Void 8j_BbZc3yc.xQd02mNeXpy6/Knj0_b5.ai0DG5yb6fCkc::Tdj2y3PsgJ() |
| Main IL Instruction Count | 76 |
| Main IL | |
| Module Name | 8j_BbZc3yc |
| Full Name | 8j_BbZc3yc |
| EntryPoint | System.Void 8j_BbZc3yc.xQd02mNeXpy6/Knj0_b5.ai0DG5yb6fCkc::Tdj2y3PsgJ() |
| Scope Name | 8j_BbZc3yc |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | 8j_BbZc3yc |
| Assembly Version | 24.12.25.33 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.6 |
| Total Strings | 912 |
| Main Method | System.Void 8j_BbZc3yc.xQd02mNeXpy6/Knj0_b5.ai0DG5yb6fCkc::Tdj2y3PsgJ() |
| Main IL Instruction Count | 76 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.