Suspect
b01d08ccf140cfe2d95a2920637e397f
PE Executable
MD5: b01d08ccf140cfe2d95a2920637e397f
Size: 1.16 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | b01d08ccf140cfe2d95a2920637e397f |
| Sha1 | 672b03b6705eed39ac4110a11166105683f468ce |
| Sha256 | e05eeb1ac0c6722a64e69f2fad8dba483cfdfe97a60f2bd123c4fb33715c419f |
| Sha384 | ba508b6e0193c6ca50ce540cf4f38adf12cb1ec226535dfc4871a1b63356853edcb7e6d1a1415876767a9dd52a59e662 |
| Sha512 | 072bea936ec9b83fe8941cb1939aa323c32820266c45d4be5370b02fa63b97f081ad1f7fde3ff9d5be222415bb292c7eb490908b71a69d9c358bc8191e45ee9c |
| SSDeep | 12288:tV1ljfZ4ZpG50omh69bwPb6HplP5fvHJQR8Pv6PxH8c/fg2Q6VSBD8p8XNPXyuFQ:TQh2bwAFvHCRYvy9A2Q6ktCuF |
| TLSH | 6935DF1926E69154E0BBD7349BB94A1447F0BA17CA32D32FA14715FDCF6238A25233B3 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | xCw6Ez1q2 |
| Full Name | xCw6Ez1q2 |
| EntryPoint | System.Void xCw6Ez1q2.xn0FqQw::Bc6jnDa15wgYr() |
| Scope Name | xCw6Ez1q2 |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | xCw6Ez1q2 |
| Assembly Version | 7.18.26.274 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.6 |
| Total Strings | 1005 |
| Main Method | System.Void xCw6Ez1q2.xn0FqQw::Bc6jnDa15wgYr() |
| Main IL Instruction Count | 106 |
| Main IL | |
| Module Name | xCw6Ez1q2 |
| Full Name | xCw6Ez1q2 |
| EntryPoint | System.Void xCw6Ez1q2.xn0FqQw::Bc6jnDa15wgYr() |
| Scope Name | xCw6Ez1q2 |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | xCw6Ez1q2 |
| Assembly Version | 7.18.26.274 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.6 |
| Total Strings | 1005 |
| Main Method | System.Void xCw6Ez1q2.xn0FqQw::Bc6jnDa15wgYr() |
| Main IL Instruction Count | 106 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.