Suspect
82197c5b9f2fc8a489b22c0ba37524e3
PE Executable
MD5: 82197c5b9f2fc8a489b22c0ba37524e3
Size: 24.3 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | 82197c5b9f2fc8a489b22c0ba37524e3 |
| Sha1 | 4504af35b08d1f0e39c42d0baf0b6dfafb692fcf |
| Sha256 | d7911e5dd2701c93eef7f8ed2b92e9269e74b14146e8c55d6801bfee3eb42eab |
| Sha384 | 0c1d512d0d67217774542498476251973f553abe9350ba0ab3471c1b6311025eedb300b2f672b14f25df02fdcd7e7399 |
| Sha512 | f7442ac31a7edb1d953dd252be3f9d6f528964379934a7b75e503e80bf73b5bcf9df3c78c4b9c855efece3c28e7a666f9b18f8658edfce066f028706f76f45db |
| SSDeep | 393216:wGCMDiCh06Sys137KWpPLAxy0uUJ8ZmGmRXLk9rlr3kEkjM88iKQpyGqrTJB:bCMDfyXysLLAxluw8ZVmRXohlDkrM8Hq |
| TLSH | 36373319367AD052DF94603BAE0FC66EC3035FBF6AA7E93D7519203813B3566842F294 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
STICH
beta
No STICH Path has been generated for this analysis yet.
2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2| Name | Value |
|---|---|
| Module Name | NudxCheat.exe |
| Full Name | NudxCheat.exe |
| EntryPoint | System.Void pkgyhwiirnuxfpuupjfgjxsfwm.pkgyhwiirnuxfpuupjfgjxsfwm::Main() |
| Scope Name | NudxCheat.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | NudxCheat |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 19 |
| Main Method | System.Void pkgyhwiirnuxfpuupjfgjxsfwm.pkgyhwiirnuxfpuupjfgjxsfwm::Main() |
| Main IL Instruction Count | 138 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | NudxCheat.exe |
| Full Name | NudxCheat.exe |
| EntryPoint | System.Void pkgyhwiirnuxfpuupjfgjxsfwm.pkgyhwiirnuxfpuupjfgjxsfwm::Main() |
| Scope Name | NudxCheat.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | NudxCheat |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 19 |
| Main Method | System.Void pkgyhwiirnuxfpuupjfgjxsfwm.pkgyhwiirnuxfpuupjfgjxsfwm::Main() |
| Main IL Instruction Count | 138 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.