Suspect
PE Executable
MD5: 42ca2b5f2b2af66dde3b74b1268448e5
Size: 40.45 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 42ca2b5f2b2af66dde3b74b1268448e5 |
| Sha1 | 402b84a4247407dfb1d2aa29ef22a05bc9afa0c0 |
| Sha256 | 4dadfe0d60ca295ca0a3865cccf3d47c09ffbd05f2e2d76a578e8d645ab72f6b |
| Sha384 | c74423466ba52023ebbcfbd182fdfa5d400e8a45ded1d809909bce4bbb4ac184a065650a00fea292b7ff24b6fe4504d0 |
| Sha512 | 984b2837622181d04ea363e7e9a0244f36fe7acf37a1e25f74aa77c75c895e15e5914a7a3e65765abc17656d538362524af99182dd4d23d3f89b51993910c00c |
| SSDeep | 768:7zRsSIXKd9pdxWmE6SY/LKTo02jTtERNfnz+eJqUNbNCImy:vRsX89nxpE6pK0gfIUNbNCm |
| TLSH | 06033904A7CD9EA3C5ED46BED0E373E103F4D4B6630EF38B9D8902A41E217D66642693 |
PeID
.NET SmartAssemby Obfuscator 6.0 (chars) sign ASLMicrosoft Visual C++ DLLMicrosoft Visual C++ v6.0
STICH
beta
No STICH Path has been generated for this analysis yet.
2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | testpowershell.dll |
| Full Name | testpowershell.dll |
| Scope Name | testpowershell.dll |
| Scope Type | ModuleDef |
| Kind | Dll |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | testpowershell |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.6 |
| Total Strings | 8 |
| Main Method | Not found or no body |