Suspect
b424246e9d67f5266b9b9113f9ca4234
PE Executable
MD5: b424246e9d67f5266b9b9113f9ca4234
Size: 2.97 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | b424246e9d67f5266b9b9113f9ca4234 |
| Sha1 | 416ff073576f79669e1e24b3df2eeaec9235953f |
| Sha256 | 42cc3afcffb3d21b60ddd95d5de6522a3f3798eb70e7033787257dcdd2226a93 |
| Sha384 | 619588934430aae88ef9dbb5e6ed724ceac13da52de014951dbcbf0e22af526f76a06939ff7742d9c3183fc826fb7c9c |
| Sha512 | 15c4ed0e624e4ea5bdf7e1fd7620058e451427f325dd7b8f6d3d9fea7c621ace4bf556586024706965a06d5f9552bfc881487097cafa1279771c6e105c134f2f |
| SSDeep | 49152:zW1tgMoAnn0dMsm9nkjNXFWWjL5rVmW1tgMoAnn0dMsm9nkjNXFWWjL5IV:igMx8Mf9GNXFHn5rfgMx8Mf9GNXFHn5I |
| TLSH | 54D523D0B6439553DF2F05B44692AA3C0BF0B8DAB113E7FA98B4465D6ACFF00254D29E |
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
STICH
beta
No STICH Path has been generated for this analysis yet.
5 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
3img
2| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | L2AncientsSetup.exe |
| Full Name | L2AncientsSetup.exe |
| EntryPoint | System.Void L2AncientsInstaller.Program::Main(System.String[]) |
| Scope Name | L2AncientsSetup.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | L2AncientsSetup |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 48 |
| Main Method | System.Void L2AncientsInstaller.Program::Main(System.String[]) |
| Main IL Instruction Count | 58 |
| Main IL | |
| Module Name | L2AncientsSetup.exe |
| Full Name | L2AncientsSetup.exe |
| EntryPoint | System.Void L2AncientsInstaller.Program::Main(System.String[]) |
| Scope Name | L2AncientsSetup.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | L2AncientsSetup |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 48 |
| Main Method | System.Void L2AncientsInstaller.Program::Main(System.String[]) |
| Main IL Instruction Count | 58 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.