Malicious
cbe251dd8587553dec38bd393cf49847
PE Executable
MD5: cbe251dd8587553dec38bd393cf49847
Size: 780.29 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | cbe251dd8587553dec38bd393cf49847 |
| Sha1 | ac4a86978788a7a03eeb6aa0b582e3962685befb |
| Sha256 | c8336e84c4a44b42ffc0f6cb57cf573b42cb46fa4ef9e553a9bb398dccee0ca2 |
| Sha384 | 92efffd7dcc5bb7168c626d6dcb58ea4c42a081c91993beef0bd8b8c43747f423a28905c7fdce074095c6e213930a965 |
| Sha512 | 05bc99be13cc3c7fb2f6a57b30e0e39861417319fe6c4f325b78f11c6bc06795506594660212ac66e0f050daec5888e2507c36c6b1387d8faa5917f9265b6344 |
| SSDeep | 12288:9GIbvq9pmhFGL1ct0t/8/8uFQ8BLs5rI5AIoy8o0RA:+pSGL1cM8/x6S02 |
| TLSH | F7F4BF1F72528E12D2C85637C1C75A04A3E4D6823637DB0E768827965E0B3EBDE4B397 |
PeID
.NET executableHQR data fileMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | Rqrukdqwhk.exe |
| Full Name | Rqrukdqwhk.exe |
| EntryPoint | System.Void RGW197QaiVNkvV4kbl.aGbEW4JmlhE8KCg11b::KkPKP4Cwi() |
| Scope Name | Rqrukdqwhk.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Rqrukdqwhk |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 41 |
| Main Method | System.Void RGW197QaiVNkvV4kbl.aGbEW4JmlhE8KCg11b::KkPKP4Cwi() |
| Main IL Instruction Count | 62 |
| Main IL | |
| Module Name | Rqrukdqwhk.exe |
| Full Name | Rqrukdqwhk.exe |
| EntryPoint | System.Void RGW197QaiVNkvV4kbl.aGbEW4JmlhE8KCg11b::KkPKP4Cwi() |
| Scope Name | Rqrukdqwhk.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Rqrukdqwhk |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 41 |
| Main Method | System.Void RGW197QaiVNkvV4kbl.aGbEW4JmlhE8KCg11b::KkPKP4Cwi() |
| Main IL Instruction Count | 62 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.