Suspect
376503b9592dfba219c5378a5961be33
PE Executable
MD5: 376503b9592dfba219c5378a5961be33
Size: 8.7 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very low
| MD5 | 376503b9592dfba219c5378a5961be33 |
| Sha1 | 06a472ceb395f2dd0208aaa95bcf68c35df5535b |
| Sha256 | c462396719067866b8220128287df855aecf174b5870ec48da54577e52ec7dd2 |
| Sha384 | 1f7e41cf36699cef00a3418060b13e12db71f0e5bc65cc6dd3b17bb211edcf1c3d3c75bc9764d64b086588d32fc8cdf6 |
| Sha512 | fb21dd5d8e71a3288721c338aaf834688a4c6bf6efe07262cf3307f0b735ac2edfe79ccc6021f77028e67238f0ba6d9eaca67efcd4d235ad413a944a110fc45f |
| SSDeep | 96:zOE/HkpS2AVEoL2tP9J7mZXyt1oaxOC5wFAj3W3DQjNzNt:6E/kpS2oEoCMXXIB6gn |
| TLSH | 5B02205463F9051AE2FB7F702DB647204B76FD52DA3AC76D1988001E1E61790CA72BB2 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
No STICH Path has been generated for this analysis yet.
1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
1| Name | Value |
|---|---|
| Module Name | CaseyFundingFileLinks.exe |
| Full Name | CaseyFundingFileLinks.exe |
| EntryPoint | System.Int32 Program::Main(System.String[]) |
| Scope Name | CaseyFundingFileLinks.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | CaseyFundingFileLinks |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 36 |
| Main Method | System.Int32 Program::Main(System.String[]) |
| Main IL Instruction Count | 48 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | CaseyFundingFileLinks.exe |
| Full Name | CaseyFundingFileLinks.exe |
| EntryPoint | System.Int32 Program::Main(System.String[]) |
| Scope Name | CaseyFundingFileLinks.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | CaseyFundingFileLinks |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 36 |
| Main Method | System.Int32 Program::Main(System.String[]) |
| Main IL Instruction Count | 48 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.