Malicious
PE Executable
MD5: 7742229ad2237e3bd199415f390f3017
Size: 2.05 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | 7742229ad2237e3bd199415f390f3017 |
| Sha1 | bb1fe6c3b4a8720fd820ccda79a2abbd7c8ec3fa |
| Sha256 | 8adfdf08e1d7883adcdf8228be4da62f9380c5ad99848be748432ecb49ff76c9 |
| Sha384 | 57b40f4a43628197030c2be0e4d3276d21b799fb9d336a459948419111388511858dae795b4750e8f8b864edd226bdc6 |
| Sha512 | 36b436207742eb2c5b809ba1b0255b32c9537e9ac35944c29447da6bc3b6c2fbd8a63fdcbda7443d158a4d1fc9558e4f2a2a615144cc0bda95a80241a2051701 |
| SSDeep | 24576:l+kn8CP2Z/ZGdeVT9rOpD9xsW/W4VXV8TxXA/Rcs3M0p3z/DFIY/jbEQfwaoi1+s:lfBXbP8dw/e0BzEAwaN1+m/QHK0 |
| TLSH | 4595BE227A44CD62D129163BC9EF415483BCAD417762DB1B7EAF339D25923A34E0E1CE |
PeID
.NET executableHQR data fileMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
| Name | Value |
|---|---|
| Module Name | Ro6BfCOSOO |
| Full Name | Ro6BfCOSOO |
| EntryPoint | System.Void bbffEuF2cpSI2a0bxMM.eVM4hFFNtyGbEGrDtyT::Xm9uZe06Kc() |
| Scope Name | Ro6BfCOSOO |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | SkpcAqFD9IEPI |
| Assembly Version | 4.9.3.7 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 69 |
| Main Method | System.Void bbffEuF2cpSI2a0bxMM.eVM4hFFNtyGbEGrDtyT::Xm9uZe06Kc() |
| Main IL Instruction Count | 29 |
| Main IL | |
| Module Name | Ro6BfCOSOO |
| Full Name | Ro6BfCOSOO |
| EntryPoint | System.Void bbffEuF2cpSI2a0bxMM.eVM4hFFNtyGbEGrDtyT::Xm9uZe06Kc() |
| Scope Name | Ro6BfCOSOO |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | SkpcAqFD9IEPI |
| Assembly Version | 4.9.3.7 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 69 |
| Main Method | System.Void bbffEuF2cpSI2a0bxMM.eVM4hFFNtyGbEGrDtyT::Xm9uZe06Kc() |
| Main IL Instruction Count | 29 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.