Suspect
b71801cb375be6f6d78fa688c81664d5
PE Executable
MD5: b71801cb375be6f6d78fa688c81664d5
Size: 1.12 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | b71801cb375be6f6d78fa688c81664d5 |
| Sha1 | 15e4b9679d5252925da739565c9053fadc011b15 |
| Sha256 | fa42af75b40265c9bc250ca078e9195ed3531fd96ffd14ece5d9fc9677a1dafa |
| Sha384 | 3ca64fe8cf416a4e76b81dac297109e03bc74908fbf6a7c5f37dd43609e400e5ff7fd729f628981717b41d3a09277b65 |
| Sha512 | 7d4c3e3429d116cef77ecb93705c190b6395c8fdcd8f6c6e37ed15d4e1662a1540789e643bf80e80f01b920e97c913b1013a5297b70098095f171bf3376b894b |
| SSDeep | 24576:iXMSvbSx4nWiPzAPzTE0OfR80XybH350qRno0G1:3kbSSWyAPzY0Si0K5lj |
| TLSH | 083501365E836B14C67D0E7CC067589C23F4CA17A226E76B3FEC11E48B66FD49A23056 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
No STICH Path has been generated for this analysis yet.
2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | Mzm5bH4nX3 |
| Full Name | Mzm5bH4nX3 |
| EntryPoint | System.Void cc2Q7Nkayb3.4esWYx3/1tzLt3PeCbd9s.Xj6_4qrGw5Dai::Xr5t2Wiqa() |
| Scope Name | Mzm5bH4nX3 |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Mzm5bH4nX3 |
| Assembly Version | 23.6.5.146 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.6 |
| Total Strings | 0 |
| Main Method | System.Void cc2Q7Nkayb3.4esWYx3/1tzLt3PeCbd9s.Xj6_4qrGw5Dai::Xr5t2Wiqa() |
| Main IL Instruction Count | 7 |
| Main IL | |
| Module Name | Mzm5bH4nX3 |
| Full Name | Mzm5bH4nX3 |
| EntryPoint | System.Void cc2Q7Nkayb3.4esWYx3/1tzLt3PeCbd9s.Xj6_4qrGw5Dai::Xr5t2Wiqa() |
| Scope Name | Mzm5bH4nX3 |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Mzm5bH4nX3 |
| Assembly Version | 23.6.5.146 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.6 |
| Total Strings | 0 |
| Main Method | System.Void cc2Q7Nkayb3.4esWYx3/1tzLt3PeCbd9s.Xj6_4qrGw5Dai::Xr5t2Wiqa() |
| Main IL Instruction Count | 7 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.