Suspect
PE Executable
MD5: 87a21e85fb19a1d20f067fa7cc153c33
Size: 811.53 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 87a21e85fb19a1d20f067fa7cc153c33 |
| Sha1 | 6bda57239fc597cb4d0b55446023e5f2d33b3ce2 |
| Sha256 | a72143b5769c74747fa3e9d4e6ecca69f9df376b4d8623fbfaf6cb1629bb8bd5 |
| Sha384 | 07f48f115c3a12570e5217e06b7854136d01d642cee5858a7f29730df52fa382d33e2553e30a7152782faa452a50b1de |
| Sha512 | 0ebbc95f07fde47f90d666e3c4082d1167db10139cedcf648f92fad6830522ca03ac4c7187757a608c12acf70bcf70b8e8eaadcac8963b260b60cd1b6e229602 |
| SSDeep | 24576:mQi52OuusSLkxDK5mGRBpLQlSp2IgYmEyUOk0M3Qy:Bo2yszVGvpLbGMydk0Mh |
| TLSH | 220501A0A1C1D531C9501FF4C970D3B68E7AAF89A4F1C213EAF9BCDBB5797412888253 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
| Name | Value |
|---|---|
| Module Name | pmCF.exe |
| Full Name | pmCF.exe |
| EntryPoint | System.Void NetworkMonitor.Program::Main() |
| Scope Name | pmCF.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | pmCF |
| Assembly Version | 7.8.6.7 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 113 |
| Main Method | System.Void NetworkMonitor.Program::Main() |
| Main IL Instruction Count | 10 |
| Main IL | |
| Module Name | pmCF.exe |
| Full Name | pmCF.exe |
| EntryPoint | System.Void NetworkMonitor.Program::Main() |
| Scope Name | pmCF.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | pmCF |
| Assembly Version | 7.8.6.7 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 113 |
| Main Method | System.Void NetworkMonitor.Program::Main() |
| Main IL Instruction Count | 10 |
| Main IL | |
PDB Path
PATH
pmhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential