Suspect
PE Executable
MD5: bc79f67aa2c484893be13528eb641105
Size: 837.63 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | bc79f67aa2c484893be13528eb641105 |
| Sha1 | f67bb4e49871d45cc5458c85f81751c9a04a68b0 |
| Sha256 | 2de4671af96bac2cbb7added8ee3a54239aac63a56d4bcc5ca22bfa88b30eb48 |
| Sha384 | a07d96727ba2ad37994bbe0ac709e7c07d154a36791b7c9212188eff30a584eebd52da26535f5a9db8bcee2f2c65202f |
| Sha512 | aaa5c7e798d2fce5ed9459f7422c2525f7e2ed3c814b6c938e5f0b2938d52718b1f879cd0a2febb937cf8f79b3cf6d813a197a6bb3a699228b8a5e9ea221a016 |
| SSDeep | 12288:T4dPVvAe/3DBfw8HfXpzU4VnwYkOrfXwaztpZzWt0OfzET/QWhB16s1yDJNtRE6O:T41VvhnHhzBvkOrY8zANfi/zH1mI5 |
| TLSH | 11052370836DC722D8E16BF10621D37183766E9DE421D213AFCE7CEBB656B189A84713 |
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: zkh.pdb |
| Module Name | zkh.exe |
| Full Name | zkh.exe |
| EntryPoint | System.Void WordScramble.Program::Main() |
| Scope Name | zkh.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | zkh |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 238 |
| Main Method | System.Void WordScramble.Program::Main() |
| Main IL Instruction Count | 10 |
| Main IL | |
| Module Name | zkh.exe |
| Full Name | zkh.exe |
| EntryPoint | System.Void WordScramble.Program::Main() |
| Scope Name | zkh.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | zkh |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 238 |
| Main Method | System.Void WordScramble.Program::Main() |
| Main IL Instruction Count | 10 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.