Suspect
PE Executable
MD5: 36358fdd96f1dc6ec7f582e860eb2b84
Size: 10.49 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | 36358fdd96f1dc6ec7f582e860eb2b84 |
| Sha1 | f2a647751fcea2ada8d454c2eef5193f8ae580d0 |
| Sha256 | d066c9129eaa023a8841cbca3cd3586e217abd3517d193fd432b4a8660cf02c4 |
| Sha384 | 49de97ed985ee645e830953ecb9d074b19ef81f1f778895ae3c3dd76f28fc272045d3f54b53069b91a034d31166348bd |
| Sha512 | bde94b2448eb29cfe39035a0bd758081f2bae4b472007ad3e19ee72c9518f41492f5cacb5a7d8998c0a6cad758d5dc507c174ef228174c9e960ba1ce2b7d6bd3 |
| SSDeep | 12288:vVvJgjTOFJfbjVtcwPggfWDl8QH75X2T+I/kqT1jOS2Uz9xqBbV:pJOTOF5tAguR822T+GkqxjO1B5 |
| TLSH | 7FB617652BE64E14E895193D827A2614D732A0F22362B7873B4AF3B14D189CDFD2C7D2 |
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
STICH
beta
No STICH Path has been generated for this analysis yet.
2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Authenticode present at 0xCC000 size 11520 bytes |
| Info | Overlay extracted: Overlay_5d44e334.bin (9638656 bytes) |
| Module Name | Client.exe |
| Full Name | Client.exe |
| EntryPoint | |
| Scope Name | Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 1243 |
| Main Method | |
| Main IL Instruction Count | 41 |
| Main IL | |