Suspicious
Suspect

52141a7468dbfbc858f72d2ce947d6b3

PE Executable
MD5: 52141a7468dbfbc858f72d2ce947d6b3
Size: 49.15 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 52141a7468dbfbc858f72d2ce947d6b3
Sha1 5b5c1b64b8d00704dabbdf7d453029b00fe61072
Sha256 ea5bf6fd34986ea7ce7e9f9207742a2dad04700f23e25d2e3a861315503f8a2a
Sha384 a4349724309031cf7e9e732104c23587560825645d53131abacc962d4e09ff56fa93f02d0bf54f6cca0d75d6d8354278
Sha512 114e23b7c431a0baaeaf4bcf9cfdb2f1aec3c98e10f9c030768eeabc0d35660fe5a668b82cfd444ea9c0b9f91bce2a14082ac9ad75afca47a1c2439de0b6da65
SSDeep 768:FwkMajwRh6UmzvwiDw8EMlpd01dQzQbCMV4x5K+jHYi:OL6UmUFopkUQbqx5KMHN
TLSH DA23710B62ED6DA1D47D47767B3383C1C3B8DE024A03DA1E0DD560A5AA7E3837901BE6
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0-preview.png
ID:0007
ID:0
ID:0008
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
stb.Resources.resources
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
stub.exe
Full Name
stub.exe
EntryPoint
System.Void stb.Ih::main()
Scope Name
stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
stub
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
297
Main Method
System.Void stb.Ih::main()
Main IL Instruction Count
8
Main IL
nop <null>
newobj System.Void stb.Ih::.ctor()
stloc.0 <null>
ldloc.0 <null>
callvirt System.Void stb.Ih::Ncn()
nop <null>
nop <null>
ret <null>
Module Name
stub.exe
Full Name
stub.exe
EntryPoint
System.Void stb.Ih::main()
Scope Name
stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
stub
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
297
Main Method
System.Void stb.Ih::main()
Main IL Instruction Count
8
Main IL
nop <null>
newobj System.Void stb.Ih::.ctor()
stloc.0 <null>
ldloc.0 <null>
callvirt System.Void stb.Ih::Ncn()
nop <null>
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0-preview.png
ID:0007
ID:0
ID:0008
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
stb.Resources.resources
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙