Suspicious
Suspect

PE Executable
MD5: 397b043a23c671c37a243fabd9c5d195
Size: 802.3 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 397b043a23c671c37a243fabd9c5d195
Sha1 c30ecdd93d46f9e1cd73548ccdb0028be77b47c4
Sha256 01cf3732fc2dda453bc38f2e3ee9d92d75e15c4559625bd1ffd209516128bf41
Sha384 6a67362e5545e23bcdbcc3e84b2d5183805e8584d0baa7714048c161143c446af0822660afd629232d428d93947216c7
Sha512 59436538f3c6dd273ca7c1348404e7c4c1d009984897621cf249390319e1a6ba5c1ecce1160eb3f587310149625cb62d414693b999c0e15166897b58ee3b0943
SSDeep 12288:WN2N7fN2jNouec0DW4fuedxRaJnCHFxIdOQ2RxkRh8iP/ZT0erQtZydyIBvguY9P:WN2r2j6dDDfBxRhbjxI5/Np/eH
TLSH 410575342EEA1029F177AF7D8AE47596EA6EB6A33707994D00B103C60723B42DDD153E
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
oNhln9lq3i
Full Name
oNhln9lq3i
EntryPoint
System.Void 74V.PEs::627()
Scope Name
oNhln9lq3i
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DB9farRJATwBRmyX
Assembly Version
6.7.3.8
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1779
Main Method
System.Void 74V.PEs::627()
Main IL Instruction Count
5
Main IL
nop <null>
ldsfld ab2.2J2 74V.PEs::792
callvirt System.Void ab2.2J2::nC6()
nop <null>
ret <null>
Module Name
oNhln9lq3i
Full Name
oNhln9lq3i
EntryPoint
System.Void 74V.PEs::627()
Scope Name
oNhln9lq3i
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DB9farRJATwBRmyX
Assembly Version
6.7.3.8
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1779
Main Method
System.Void 74V.PEs::627()
Main IL Instruction Count
5
Main IL
nop <null>
ldsfld ab2.2J2 74V.PEs::792
callvirt System.Void ab2.2J2::nC6()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙