Suspicious
Suspect

3301bc88533633d7acacea4a76be89d7

PE Executable
MD5: 3301bc88533633d7acacea4a76be89d7
Size: 78.85 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 3301bc88533633d7acacea4a76be89d7
Sha1 634164cd59311c588cd59f80063572394445dc90
Sha256 b87a9cfde8da07e2c8d391911ba9350ecf8c8b020e934aa8d63ecc5d732021e9
Sha384 9505be46693ccb94f3bd6030832a7c9d29f7be024a879268b7320568350f541bde53370028b24f983b194a11aabb4953
Sha512 64ef9a7aed8eb60870c4ba9d5c551f323783492a0244279806ab827dac8e25bb0d39ae04a202c2e31521f9522831f3123afd6d3ece59084fce87e8bab6782058
SSDeep 1536:jBeTJymCfU5v1F6SSWOBm1qSngWK9HMr0B0Ki:jB/mhN6pjsr0B0Ki
TLSH 9D73839D766072EFC857C472DEA81CA4EA6075BB831F8203D45716ADEA4D89BCF140F2
PeID
HQR data file
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
Lff n
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Module Name
xbnxnvvf.exe
Full Name
xbnxnvvf.exe
EntryPoint
System.Void ‬‌‪‏​​‌‌‏‬‭‏‮‏‍‪‏‫‮‮‍​‮::​‬‪‫‏‫‎​‏‍​​‮​‍‍​‭‪‌‍‎‮()
Scope Name
xbnxnvvf.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xbnxnvvf
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.1
Total Strings
4
Main Method
System.Void ‬‌‪‏​​‌‌‏‬‭‏‮‏‍‪‏‫‮‮‍​‮::​‬‪‫‏‫‎​‏‍​​‮​‍‍​‭‪‌‍‎‮()
Main IL Instruction Count
0
Main IL
PDB Path PATH
xbnxhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
Lff n
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
PDB Path PATH
xbnxhuhuhuhu
3301bc88533633d7acacea4a76be89d7
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙