Suspect
PE Executable
MD5: 6c84a65b99d100d4ff79c1ce03701e01
Size: 221.18 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very low
| MD5 | 6c84a65b99d100d4ff79c1ce03701e01 |
| Sha1 | acff9ca1829bb5ddf7b9e83cc4428c72edbb45c9 |
| Sha256 | 36cfd82cf3348bb91506fd5783e7edf12b470cb5928140655fa4c76be46f210f |
| Sha384 | 7f8cc7d9c8e9d284c88b2de2665b9b01ef784bcd1f36695471fd9f0d8904c1046e8bb62e77057ea2e70143dbc9236749 |
| Sha512 | 033bbd5ee33ba507b4fbd2d175347903c572c6d6a768098fb87f96e7d93aa235c2fff0e2e428df8d4f61483334377436377fb62f01e19cf36abbcfd7e7cd77cb |
| SSDeep | 3072:7l6R/7oWpna6lada9a2nzXTAzH4dBz+A6bOnJAn+UiVrrYFkH:Gal0dBz+A6bOnJAn+Drm |
| TLSH | 8424E0222DEB209DB3A39BB65FC8F8FF486AF9B3550E30F531510B4687229858D51B35 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | Coger_crypted.exe |
| Full Name | Coger_crypted.exe |
| EntryPoint | System.Void ObfuscatedStub.Runner::Main() |
| Scope Name | Coger_crypted.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Coger_crypted |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 15 |
| Main Method | System.Void ObfuscatedStub.Runner::Main() |
| Main IL Instruction Count | 76 |
| Main IL | |
| Module Name | Coger_crypted.exe |
| Full Name | Coger_crypted.exe |
| EntryPoint | System.Void ObfuscatedStub.Runner::Main() |
| Scope Name | Coger_crypted.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Coger_crypted |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 15 |
| Main Method | System.Void ObfuscatedStub.Runner::Main() |
| Main IL Instruction Count | 76 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.