Suspicious
Suspect

42ca2b5f2b2af66dde3b74b1268448e5

Share on LinkedIn
Print
PE Executable
MD5: 42ca2b5f2b2af66dde3b74b1268448e5
Size: 40.45 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 42ca2b5f2b2af66dde3b74b1268448e5
Sha1 402b84a4247407dfb1d2aa29ef22a05bc9afa0c0
Sha256 4dadfe0d60ca295ca0a3865cccf3d47c09ffbd05f2e2d76a578e8d645ab72f6b
Sha384 c74423466ba52023ebbcfbd182fdfa5d400e8a45ded1d809909bce4bbb4ac184a065650a00fea292b7ff24b6fe4504d0
Sha512 984b2837622181d04ea363e7e9a0244f36fe7acf37a1e25f74aa77c75c895e15e5914a7a3e65765abc17656d538362524af99182dd4d23d3f89b51993910c00c
SSDeep 768:7zRsSIXKd9pdxWmE6SY/LKTo02jTtERNfnz+eJqUNbNCImy:vRsX89nxpE6pK0gfIUNbNCm
TLSH 06033904A7CD9EA3C5ED46BED0E373E103F4D4B6630EF38B9D8902A41E217D66642693
PeID
.NET SmartAssemby Obfuscator 6.0 (chars) sign ASLMicrosoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
{0487b33d-c8be-49e4-87c1-694c4b2b137a}
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
testpowershell.dll
Full Name
testpowershell.dll
Scope Name
testpowershell.dll
Scope Type
ModuleDef
Kind
Dll
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
testpowershell
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
8
Main Method
Not found or no body
An error has occurred. This application may no longer respond until reloaded. Reload 🗙