Suspect
PE Executable
MD5: 622d610c1833e0f63a9292ad2f7668fc
Size: 914.43 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 622d610c1833e0f63a9292ad2f7668fc |
| Sha1 | 8ff2ce85f5e47637eae20e52e9dcd530e4beb08b |
| Sha256 | 98f47f9d835386aebcefd4e2c6edfb994692894a53423d3601fd108c75cbb588 |
| Sha384 | 142e9f9cebd941ae70bce1772fe35befaa20ec11f180abb19086316457ce5b1c7eaedbeb273c1e28a57b9d0aa9f5a62f |
| Sha512 | f09803e422bb25dd07cd0c8c6d05162438f1c619ef19932ed817a158c18348e5dcd313faeaabc90f630bdac84ecb27a490b7cca4ef2c23bbadbbda4eb9e8ec00 |
| SSDeep | 24576:A+Cvp9jTenfc2Z4pfM7O0F3wbRaGYhVIup:sp9jT12Z4pkJF3wbQ9VIu |
| TLSH | 3415025437A9C616E8B72BF80A21F23457B6BDDEB621D10ADFE56CEB7425B408E04703 |
PeID
Microsoft Visual C++ v6.0 DLL
STICH
beta
No STICH Path has been generated for this analysis yet.
3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2img
1| Name | Value |
|---|---|
| Module Name | ncRE.exe |
| Full Name | ncRE.exe |
| EntryPoint | System.Void PotteryKiln.Program::Main() |
| Scope Name | ncRE.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | ncRE |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 492 |
| Main Method | System.Void PotteryKiln.Program::Main() |
| Main IL Instruction Count | 10 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |