Suspect
PE Executable
MD5: 6ff3cc67b35a5caed0468ea9352506e9
Size: 772.1 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 6ff3cc67b35a5caed0468ea9352506e9 |
| Sha1 | e1de54b8f46e5c4fa38052f0cf5891e7d35549a9 |
| Sha256 | 57f5d6a0f4ba2b5db7c32af655a63a62b82e83f8bc03650f953eed6a6f0e1fa2 |
| Sha384 | ae1265290fb598681443fcc2e4512c3ed78a401c0d3e6689eaa5fb96caec445667354da7863d04e6d0f57faec4859c7d |
| Sha512 | 20142dbad5fc1bdd642ee64dee3cd9742d5c7f81a8d801f152850f64be1bf8e1bb6b2b575bc578ca4b89096cc6b9ebf19615018690e65bbe79140708cb2f66fa |
| SSDeep | 12288:Ruo+0HjJ35LZ6LxWq76MSlNl5tuinL5CiPAwq4r/QGmuQv4lRl4e:Io+qz6LoqIlNHtu0VfP1q4r/QNv4Ll |
| TLSH | 16F412687726FE52C9AD4B750A77E33413A59E5DE111C327CBEE9DEF3C20245AC08682 |
PeID
UPolyX 0.3 -> delikon
STICH
beta
No STICH Path has been generated for this analysis yet.
4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2img
2| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: C:\Users\Administrator\Desktop\Client\Temp\ILQbnbWWjl\src\obj\Debug\NvRO.pdb |
| Module Name | NvRO.exe |
| Full Name | NvRO.exe |
| EntryPoint | System.Void VirtualMachine26.Program::Main() |
| Scope Name | NvRO.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | NvRO |
| Assembly Version | 26.1.4.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 171 |
| Main Method | System.Void VirtualMachine26.Program::Main() |
| Main IL Instruction Count | 10 |
| Main IL | |