Suspect
7102ad31aefa964c627a1d2d2cd5db79
PE Executable
MD5: 7102ad31aefa964c627a1d2d2cd5db79
Size: 1.05 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 7102ad31aefa964c627a1d2d2cd5db79 |
| Sha1 | 14be46147b431e56345a64f1d43b44ef0cb064f6 |
| Sha256 | a6604cb175b8b162e4657114ab071ce8e1e04f79e6615201f01f4d16f985cead |
| Sha384 | 94a0320a0610cccd2b9d847813d9a5e8bc73a5da291b590796f000f86947890599ddbe162a4dae6dabcc9a5e05268d23 |
| Sha512 | 3635d1f1d3a14834ce0ee8fbd23c72ac19aefd3a018aa45a3ca2fc243def68d65958f24429937f21475a6825a5d88cef8699d86bc959efa935e9eab63c3632d6 |
| SSDeep | 24576:fYj/Og3PVFoQ/HB+Bc0q/+y9WIN3Dv0A4EZg4IOlwVt:yPfVSQ/h+BcQI9v0A4EZAOlwr |
| TLSH | 332512C5B7E9EB16E6B447F00AB0E13147786C2AA031D30A5DEAFCDBBA75B151810793 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
No STICH Path has been generated for this analysis yet.
3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2img
1| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | FNep.exe |
| Full Name | FNep.exe |
| EntryPoint | System.Void RuneBerg.Program::Main() |
| Scope Name | FNep.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | FNep |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 503 |
| Main Method | System.Void RuneBerg.Program::Main() |
| Main IL Instruction Count | 10 |
| Main IL | |
| Module Name | FNep.exe |
| Full Name | FNep.exe |
| EntryPoint | System.Void RuneBerg.Program::Main() |
| Scope Name | FNep.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | FNep |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 503 |
| Main Method | System.Void RuneBerg.Program::Main() |
| Main IL Instruction Count | 10 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.