Suspect
caf5b7d0873fbac47a3dd246a9130ffe
PE Executable
MD5: caf5b7d0873fbac47a3dd246a9130ffe
Size: 750.08 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | caf5b7d0873fbac47a3dd246a9130ffe |
| Sha1 | e7653a59dce272f06f56a32c7aa92a1037941930 |
| Sha256 | 34bae751324dcb623efb9c061f097d715b1d2d93587e9b0ea59017a9e5778f6e |
| Sha384 | 05c8ed92de8c6f495786f2cc156c93a3e0962a13be63bc716fa6b0238098f8b5d42cb9dd17c5e51fa0ce4681b3821984 |
| Sha512 | 87f4c9e78f73cfa59e934562b12a3686619b7888636693fef4b990ecc2af8c444ef6c8551e1756ab6d64e71eceea99f1ed97422d8718dcd59d5b0b79c3d97f8d |
| SSDeep | 12288:dQ60VEp3/P9HauMR9LTO/DnqtkbmkvorhloGv8wFYoPsnQSaaPaTZP/sUYynki7U:dQnVaurTO/DO3kvor/kNznQ+qkfi796 |
| TLSH | FBF412A89AE8CE15D5FA03B65E62E73617B1BD6EB211C3524FF47CFB7522B160844302 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
STICH
beta
No STICH Path has been generated for this analysis yet.
3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2img
1| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | ctil.exe |
| Full Name | ctil.exe |
| EntryPoint | System.Void TermiteMound.Program::Main() |
| Scope Name | ctil.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | ctil |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 419 |
| Main Method | System.Void TermiteMound.Program::Main() |
| Main IL Instruction Count | 60 |
| Main IL | |
| Module Name | ctil.exe |
| Full Name | ctil.exe |
| EntryPoint | System.Void TermiteMound.Program::Main() |
| Scope Name | ctil.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | ctil |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 419 |
| Main Method | System.Void TermiteMound.Program::Main() |
| Main IL Instruction Count | 60 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.