Suspect
PE Executable
MD5: af4e68bd96639169c051d6ed091d0a11
Size: 729.6 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | af4e68bd96639169c051d6ed091d0a11 |
| Sha1 | bde5794a1489f5ca45f72a24ec60f99e1de2209c |
| Sha256 | ab0e1d7e551816ee2e46dfd74c50906118da48af18c6f8d2d91071310cbb7dbe |
| Sha384 | 80f40cfeb4f0754902638f1376af42001d05e927bbfa54d91e43be7a7ff35a1c47a12402bb7290009c2219b319b0f230 |
| Sha512 | c47f5d4750ee60db36e5eb40b6e7abac5774d8a0507b927cb66927dc119e93c29ce29373c2567ed80a21db321131ec5c0792f9067ca31ed72477efa074d3ee87 |
| SSDeep | 12288:zaDNiDzYmtvVzZA+sisZB+XIY5ckSuw5PEemC9UebQXzXWVmrruDdsgdrAk:GDNiwQ7AfiqBHV5PEeJ9UmEaVmPuhVd |
| TLSH | DCF4236927AACE21E87D67B50632E3718B7C2D99C402D34A0FDEFDA7F00B6901D51782 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
| Name | Value |
|---|---|
| Module Name | pCCU.exe |
| Full Name | pCCU.exe |
| EntryPoint | System.Void NotepadPlus.Program::Main(System.String[]) |
| Scope Name | pCCU.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | pCCU |
| Assembly Version | 3.9.4.7 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 203 |
| Main Method | System.Void NotepadPlus.Program::Main(System.String[]) |
| Main IL Instruction Count | 52 |
| Main IL | |
| Module Name | pCCU.exe |
| Full Name | pCCU.exe |
| EntryPoint | System.Void NotepadPlus.Program::Main(System.String[]) |
| Scope Name | pCCU.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | pCCU |
| Assembly Version | 3.9.4.7 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 203 |
| Main Method | System.Void NotepadPlus.Program::Main(System.String[]) |
| Main IL Instruction Count | 52 |
| Main IL | |
PDB Path
PATH
pChuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential