Suspect
a864d29d857a24c79cff0537da15efe3
PE Executable
MD5: a864d29d857a24c79cff0537da15efe3
Size: 59.9 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | a864d29d857a24c79cff0537da15efe3 |
| Sha1 | 45265dcebbed21201339b37211ed7d5f91e8239a |
| Sha256 | 13add98d1fb45bc64b2bcc839920447cbe09cb0d71a3d56aeb28cb5d3162327e |
| Sha384 | 88d263aef6c1c0c7acb168cbf3ac16fd5f6a4a3e127410fd3bb32c81bfa4c452d177c126e6e60e1f8acab09af444e363 |
| Sha512 | 617c0184da8e44033f33f3b602a72de136667f6e2fe839129b0c0459f2a607dfdf934bdb64116362ac92e3371e55f163dac67facef2b2841015571a8b6af1b9e |
| SSDeep | 768:MTT1+0m1PyFGEsVGXYVfz3XuOjiJcqVWQn4E3zUrtRij+wc9LBl:K40m1eReezCqB4eyy8D |
| TLSH | 8B43DA8C765076DFC85BC876CAA81C68EA60747B831BD243A46316ED9E0D99BCF150F3 |
PeID
Microsoft Visual C# / Basic .NET
STICH
beta
No STICH Path has been generated for this analysis yet.
1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
1| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: GHOSTED.pdb |
| Module Name | GHOSTED.dll |
| Full Name | GHOSTED.dll |
| Scope Name | GHOSTED.dll |
| Scope Type | ModuleDef |
| Kind | Dll |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | GHOSTED |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5.1 |
| Total Strings | 0 |
| Main Method | Not found or no body |
| Module Name | GHOSTED.dll |
| Full Name | GHOSTED.dll |
| Scope Name | GHOSTED.dll |
| Scope Type | ModuleDef |
| Kind | Dll |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | GHOSTED |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5.1 |
| Total Strings | 0 |
| Main Method | Not found or no body |
No malware configuration was found at this point.
You must be signed in to view YARA rules.