Suspect
PE Executable
MD5: debc5451a1cba0528327f95daa19982f
Size: 3.61 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | debc5451a1cba0528327f95daa19982f |
| Sha1 | e35f0b7f50b156887bdc6522cf895806390db9a3 |
| Sha256 | 9d5a8515ee389bc2aeb83bfb6a0cea9a2bb4ef4b5dbff60b93ad6d4184f43a11 |
| Sha384 | 81ece9e7e9215cefe4bbafdc2fe48b382b1b7755f4c346ba95ae946ac2e83ea62b4f75be4f8a98320fbd11422da0128a |
| Sha512 | 4d744519eac63e50366770799ea34d3f8cdfc0aa77f48a1d5da518f0908405a1d4457d5ca18250d9b92df1bd5aff80f302c9fd8f64f51bea1e2186b19ac2844e |
| SSDeep | 49152:NGZUkVVB9Z7AMSVWpzROPBCx8RRveYkqM3fC41p2VEn:AVVN7AXWhROpCx8XGrqMvz1pmS |
| TLSH | 6DF5F181A5C57994C5A63330F536460B33BAFE57E931C48D0C9EB8A1F3B728A5E870D6 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
| Name | Value |
|---|---|
| Module Name | done |
| Full Name | done |
| EntryPoint | System.Void Pm4w.e6X8::t0K2() |
| Scope Name | done |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | done |
| Assembly Version | 2.7.11.4 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.6 |
| Total Strings | 1329 |
| Main Method | System.Void Pm4w.e6X8::t0K2() |
| Main IL Instruction Count | 99 |
| Main IL | |
| Module Name | done |
| Full Name | done |
| EntryPoint | System.Void Pm4w.e6X8::t0K2() |
| Scope Name | done |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | done |
| Assembly Version | 2.7.11.4 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.6 |
| Total Strings | 1329 |
| Main Method | System.Void Pm4w.e6X8::t0K2() |
| Main IL Instruction Count | 99 |
| Main IL | |
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #4
URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #5
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #6
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #7
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #8
URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #9
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #10
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #11
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #12
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #13
URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #14
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhu
debc5451a1cba0528327f95daa19982f
URLs in VB Code - #2
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
debc5451a1cba0528327f95daa19982f
URLs in VB Code - #3
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
debc5451a1cba0528327f95daa19982f
URLs in VB Code - #4
URIsuspect
http:/huhuhuhuhuhuhu
debc5451a1cba0528327f95daa19982f
URLs in VB Code - #5
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
debc5451a1cba0528327f95daa19982f
URLs in VB Code - #6
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
debc5451a1cba0528327f95daa19982f
URLs in VB Code - #7
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
debc5451a1cba0528327f95daa19982f
URLs in VB Code - #8
URIsuspect
http:/huhuhuhuhuhuhu
debc5451a1cba0528327f95daa19982f
URLs in VB Code - #9
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
debc5451a1cba0528327f95daa19982f
URLs in VB Code - #10
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
debc5451a1cba0528327f95daa19982f
URLs in VB Code - #11
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
debc5451a1cba0528327f95daa19982f
URLs in VB Code - #12
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
debc5451a1cba0528327f95daa19982f
URLs in VB Code - #13
URIsuspect
http:/huhuhuhuhuhuhu
debc5451a1cba0528327f95daa19982f
URLs in VB Code - #14
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
debc5451a1cba0528327f95daa19982f
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.