Suspect
b679a2beed0436eec3009d85882e57eb
PE Executable
MD5: b679a2beed0436eec3009d85882e57eb
Size: 1.13 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | b679a2beed0436eec3009d85882e57eb |
| Sha1 | 44ec8792f73c32880fca4997687734c671a052cb |
| Sha256 | a767946d8b54dfd0059012f87afeb9113d112b01e32db8359cadf60233b5bdd6 |
| Sha384 | fd8b88322a21ae9e0821ab3ca2171d8df535b2a18dcf6df7814c2b5500f54e11e94b269168672d585ac8f7f7952e1421 |
| Sha512 | 24ca9eef7e04bebc79f66ac637f558699539e27574882190e781d2b64288bd3e91bdf13a18b6c4267b4d6a6ed7af3f75ac6f4f661fc0818f7194d6e01d175428 |
| SSDeep | 24576:iwjR6pFsR2DQyIEuaIoSjSuTp1gaQ+x+QGjxRhTz:ptimR2kyRuGSuG13Q+GjxTTz |
| TLSH | 33350295332ACC46C5A35F711E70E3B442BD8D88A505F7338EFABCABB8793866D11191 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
No STICH Path has been generated for this analysis yet.
4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2img
2| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: C:\Users\Administrator\Desktop\Client\Temp\aduXgvQNhD\src\obj\Debug\wUGI.pdb |
| Module Name | wUGI.exe |
| Full Name | wUGI.exe |
| EntryPoint | System.Void FleetManager.Program::Main() |
| Scope Name | wUGI.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | wUGI |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 129 |
| Main Method | System.Void FleetManager.Program::Main() |
| Main IL Instruction Count | 6 |
| Main IL | |
| Module Name | wUGI.exe |
| Full Name | wUGI.exe |
| EntryPoint | System.Void FleetManager.Program::Main() |
| Scope Name | wUGI.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | wUGI |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 129 |
| Main Method | System.Void FleetManager.Program::Main() |
| Main IL Instruction Count | 6 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.