Suspect
PE Executable
MD5: 61d9d64fe0ceaf33116f130f35879ceb
Size: 1.28 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 61d9d64fe0ceaf33116f130f35879ceb |
| Sha1 | ec74018a2cf7375efb9b29e6a44fa51bd0c94053 |
| Sha256 | f103df0af6684dd4e14e698172bc510552053197b2aa2daa075679682ddaaf6d |
| Sha384 | 64267a665e5809ec0e8d60dd836f201f35026bfb7e0cc5ad7b4f03239b206dcbd944a33a9e6f0cd46713b59ed1b37264 |
| Sha512 | cc2bf207c5bef36e65f982f73006c83afd9af900bac42678b3890a13df3cd8b1f94c3de67b3fc3c5bad051628225aacf34065866886dac2ac5457e6824f4f6c7 |
| SSDeep | 24576:M+bvFWUuB7XJ4SCkdB0QdA6K7at5y2438ZxkT7Jukf:M+btab3TrKWsuITtFf |
| TLSH | A8451214266AD917C49207B408B1E3B45768AE98BD34C3139FFEFDEBB83621538543A7 |
STICH
beta
No STICH Path has been generated for this analysis yet.
3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2img
1| Name | Value |
|---|---|
| Module Name | EDyE.exe |
| Full Name | EDyE.exe |
| EntryPoint | System.Void DoveCote.Program::Main() |
| Scope Name | EDyE.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | EDyE |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 56 |
| Main Method | System.Void DoveCote.Program::Main() |
| Main IL Instruction Count | 10 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |