General
Structural Analysis
Config.0
Yara Rules99+
Sync
Community
Summary by MalvaGPT
Characteristics
Symbol Ofbuscation Score
Very high
|
Hash | Hash Value |
|---|---|
| MD5 | 430df771b70ab0f47cbed46a479d0c89
|
| Sha1 | 584f8c3482e8123affe0c915a71c7b5a1cf7cb14
|
| Sha256 | 23228723bd373f0a2907aa450ebaf3a218fac346c3d854ee7554b899dcc198ab
|
| Sha384 | 1742a5185d8e71285d48a96f9c056d33a12a265daa4e087fd658babd44c6c72d5fd46374a3dd277999ad1c12636331d7
|
| Sha512 | 1c251e4ab06bd2d788da1420f92a38415e373d4c2be55549cda0544da11a73dbdbf58f82018b299c78492320f9aa726d7d1840643b9c73467c1deb521db69fc5
|
| SSDeep | 98304:wilxy6/gMPcReLQJXyJL5u8jnSxey4s2h3:wiC650RNXyJLkLYbt
|
| TLSH | 9D16238C366032DEC89BD5314D661E98D6507E766F2B6213D02734AEAE3E48BCF154B3
|
File Structure
430df771b70ab0f47cbed46a479d0c89
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
hmQ3g
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | server1.exe |
| Full Name | server1.exe |
| EntryPoint | System.Void ::() |
| Scope Name | server1.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | server1 |
| Assembly Version | 2.5.9.9 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.8 |
| Total Strings | 6 |
| Main Method | System.Void ::() |
| Main IL Instruction Count | 0 |
| Main IL | |
430df771b70ab0f47cbed46a479d0c89 (4.02 MB)
File Structure
430df771b70ab0f47cbed46a479d0c89
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
hmQ3g
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.