Suspect
62d169abfe685543e0bdb679d7b99f7d
PE Executable
MD5: 62d169abfe685543e0bdb679d7b99f7d
Size: 63.49 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 62d169abfe685543e0bdb679d7b99f7d |
| Sha1 | d573734432a843db34e2f5f410c5b88f442d9e42 |
| Sha256 | 783e90f0956e487bd5fbb9bfdf631de82d79d533d0bbd41a8a82ba90f4b1a51d |
| Sha384 | a532d226b0948e71ce0bd682350e763c02dffa0689c74292f958bac388c978c6286149865bb926024818a7f869ede137 |
| Sha512 | e4933f54474e7668b918fc1fb2f6a799eb44792c3b19eaa1ab4a35180e689bb99a8ee2aea047b5971cd9597adb027ba9bf73f048b7da6982fc3695c62e3b0715 |
| SSDeep | 1536:TTaKHkF/s5e3saRcNT23yFZvlsQYp4WKiH/cTj:TOKHkF/s5FNNT23yFvIH/Uj |
| TLSH | CB531940E7E86216F6EE4BB6BC7315035BF0B147563AD72D0889829FCE627544A237E3 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
No STICH Path has been generated for this analysis yet.
1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
1| Name | Value |
|---|---|
| Module Name | ProcessHollowing.exe |
| Full Name | ProcessHollowing.exe |
| EntryPoint | System.Void ProcessHollowing.ProcessHollowing::Main(System.String[]) |
| Scope Name | ProcessHollowing.exe |
| Scope Type | ModuleDef |
| Kind | Console |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | ProcessHollowing |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.8 |
| Total Strings | 180 |
| Main Method | System.Void ProcessHollowing.ProcessHollowing::Main(System.String[]) |
| Main IL Instruction Count | 55 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |
| Info | |
| Module Name | ProcessHollowing.exe |
| Full Name | ProcessHollowing.exe |
| EntryPoint | System.Void ProcessHollowing.ProcessHollowing::Main(System.String[]) |
| Scope Name | ProcessHollowing.exe |
| Scope Type | ModuleDef |
| Kind | Console |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | ProcessHollowing |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.8 |
| Total Strings | 180 |
| Main Method | System.Void ProcessHollowing.ProcessHollowing::Main(System.String[]) |
| Main IL Instruction Count | 55 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.