Suspicious
Suspect

e03944d56f67a14d11547dd3ace97b66

PE Executable
MD5: e03944d56f67a14d11547dd3ace97b66
Size: 207.87 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 e03944d56f67a14d11547dd3ace97b66
Sha1 3a812d0270035cfde87f6b28d528854e8c9387b4
Sha256 958ebd65f2915e6aeae945ea6ea90a663ea6d429e8a0c3d8be1d9ef14b3c71aa
Sha384 a28a56ba963ecd7236d0093b7d7c96cf48c071e9a00bf30e00018a2d124022effa88aec1c8bf9db2857853eaeff5f303
Sha512 bce9bcd7a93d5234362e5f29b71e8a477b23fa047c0b6fbc5cdaa8369b33681798e443634169eb2dcee097cef81826de7c2d14bb1a93899aef80d894b7cc7041
SSDeep 6144:MLV6Bta6dtJmakIM5cG9lT9E6CvvHPfI2xz:MLV6BtpmkbGrBfCvPPfIWz
TLSH 9514BF567BA88A2FE2DE8579611202128778C2E3ADC3F3DE58D420B78F567E50B071D7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
.rsrc
Resources
RT_RCDATA
ID:0001
ID:0
.Net Resources
ClientLoaderForm.resources
     ​     
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
NanoCore Client.exe
Full Name
NanoCore Client.exe
EntryPoint
System.Void ClientLoaderForm::Main()
Scope Name
NanoCore Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
NanoCore Client
Assembly Version
1.2.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
2
Main Method
System.Void ClientLoaderForm::Main()
Main IL Instruction Count
4
Main IL
call #=q_jQLaNdtSDa6ovA0VGw50w==/#=qlsj4Kl0M6SYgZMJLZ$QkSw== #=q_jQLaNdtSDa6ovA0VGw50w==::#=qqROT7DfncW7strhZvp0iRQ==()
callvirt ClientLoaderForm #=q_jQLaNdtSDa6ovA0VGw50w==/#=qlsj4Kl0M6SYgZMJLZ$QkSw==::#=qbzig1$2CwLluEJt5uPtpgqPx5y_2S$GoPgJP36N8bTE=()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
NanoCore Client.exe
Full Name
NanoCore Client.exe
EntryPoint
System.Void ClientLoaderForm::Main()
Scope Name
NanoCore Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
NanoCore Client
Assembly Version
1.2.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
2
Main Method
System.Void ClientLoaderForm::Main()
Main IL Instruction Count
4
Main IL
call #=q_jQLaNdtSDa6ovA0VGw50w==/#=qlsj4Kl0M6SYgZMJLZ$QkSw== #=q_jQLaNdtSDa6ovA0VGw50w==::#=qqROT7DfncW7strhZvp0iRQ==()
callvirt ClientLoaderForm #=q_jQLaNdtSDa6ovA0VGw50w==/#=qlsj4Kl0M6SYgZMJLZ$QkSw==::#=qbzig1$2CwLluEJt5uPtpgqPx5y_2S$GoPgJP36N8bTE=()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
.rsrc
Resources
RT_RCDATA
ID:0001
ID:0
.Net Resources
ClientLoaderForm.resources
     ​     
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙