Suspect
PE Executable
MD5: dcb49b129c43fea9da4300155aa733a3
Size: 566.27 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | dcb49b129c43fea9da4300155aa733a3 |
| Sha1 | 26cf6a86a8f57087f7e83b483c7acd3be527255a |
| Sha256 | 4d5c94ee188d2b20cc91fa680b6a81a59a61ac93fc7e822dcd58be0310fd7768 |
| Sha384 | d48c1cbc2d6eaae3c4e45e1f9dd00ac544210af0bc71cadeed097bcfd64ddd9faa83474d0126f859b540b7392d8eed17 |
| Sha512 | 75af8a9219b4b3125292dc3a9868bdadb51b28b639b8ec003fb7ebec3eab68e1bafeffad4477771739434417588757670ae4fccb7a2738a4156fbe581a1e5f12 |
| SSDeep | 12288:CLV6BtpmkrLD9efoaLgdywHIKfwQK6waJLj1kQs:gApfrLJef/0fI6wKLS9 |
| TLSH | 52C40255B7A84E2EE6DF45BAA12511528379C1E39DC3F7DE2CC464B79B227E006072C3 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
| Name | Value |
|---|---|
| Module Name | NanoCore Client.exe |
| Full Name | NanoCore Client.exe |
| EntryPoint | System.Void ClientLoaderForm::Main() |
| Scope Name | NanoCore Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v2.0.50727 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | NanoCore Client |
| Assembly Version | 1.2.2.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 2 |
| Main Method | System.Void ClientLoaderForm::Main() |
| Main IL Instruction Count | 4 |
| Main IL | |
| Module Name | NanoCore Client.exe |
| Full Name | NanoCore Client.exe |
| EntryPoint | System.Void ClientLoaderForm::Main() |
| Scope Name | NanoCore Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v2.0.50727 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | NanoCore Client |
| Assembly Version | 1.2.2.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 2 |
| Main Method | System.Void ClientLoaderForm::Main() |
| Main IL Instruction Count | 4 |
| Main IL | |
Embedded Resources
UNKNWOWNsuspect
2huhuhuhu
Suspicious Type Names (1-2 chars)
UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential