Suspect
PE Executable
MD5: 8f90e5501e319a41a9a9649098f7c7ba
Size: 1.57 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 8f90e5501e319a41a9a9649098f7c7ba |
| Sha1 | 130493bf86c658ab8e748497603b0869a715e89f |
| Sha256 | 51974d6489023e692699475f2a5d25e986b2e1e6c191bf8f3e51100347981dfd |
| Sha384 | dd14fe47ed054a94236ab3741b1f96f58050ff16dd54a333b31c7115b756613deee20635ce4e8c203879bc3bdf4e1751 |
| Sha512 | 30a52d2f16e9713b59036b3c218fe2c0218f0692724a828089fcd1ef2167ee1303ffc8a865f1814c093f577f06d9bbae2e258d97d72eddacd4d2dcb49465f59f |
| SSDeep | 12288:e1i777crPbCJgRD1sdJ7GrUnxa1eoUztQd7kMIu6BP55+h+gAQAeey2nBlYjobPJ:e1pQ1ileoUKAQUP3+sgQ1nBlY4R |
| TLSH | 81757D5077AC8B26D7AF4AB9F4B149050B71E507A163E3AE45C8B1F92DA33829D103F7 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: ? |
| Module Name | Client.exe |
| Full Name | Client.exe |
| EntryPoint | System.Void nihbtshddobyjtwifl.B4WcQQCarVUqWanh::Main() |
| Scope Name | Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 1.7.4.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 1547 |
| Main Method | System.Void nihbtshddobyjtwifl.B4WcQQCarVUqWanh::Main() |
| Main IL Instruction Count | 11 |
| Main IL | |
| Module Name | Client.exe |
| Full Name | Client.exe |
| EntryPoint | System.Void nihbtshddobyjtwifl.B4WcQQCarVUqWanh::Main() |
| Scope Name | Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 1.7.4.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 1547 |
| Main Method | System.Void nihbtshddobyjtwifl.B4WcQQCarVUqWanh::Main() |
| Main IL Instruction Count | 11 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.