Suspect
PE Executable
MD5: e36e7263122c4cec3910e03719872be3
Size: 101.25 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very low
| MD5 | e36e7263122c4cec3910e03719872be3 |
| Sha1 | dbd9549e1b7ff052dc667f18777f14112f16a0fb |
| Sha256 | 53d52508d4fbf502264ff4e8482ff3c988f86f4727326d09a71724b61a152e92 |
| Sha384 | 7f4c93a32f17e48c3c3c20e1fbdc850918232db718d0f7f3f3c79685ce3ed8d80700baf9f980086afa63a9966d69518f |
| Sha512 | 7cb50f9900e024d9cce8c4e131480f4939d561fa91396850d4a2413a09dea7b0397fa438ee5bbdefeccd06c4b4cd334e48edc5ab347c1165642a40993b17e917 |
| SSDeep | 1536:WAp5eznKUlIOp3YjVCguHEvQEbFqVC3woFRKpT4XP:d5eznsjsguGDFqG/ |
| TLSH | 1DA3CA387D952133C67EC1F689E50A8AEB69223F3191E9ED4CA742C418B2F156EC1D1F |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_69319637.bin (2944 bytes) |
| Module Name | 1.exe |
| Full Name | 1.exe |
| EntryPoint | System.Void MusicExpress.Program::Main() |
| Scope Name | 1.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v2.0.50727 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | 1 |
| Assembly Version | 1.28.14.52 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 1178 |
| Main Method | System.Void MusicExpress.Program::Main() |
| Main IL Instruction Count | 6 |
| Main IL | |
| Module Name | 1.exe |
| Full Name | 1.exe |
| EntryPoint | System.Void MusicExpress.Program::Main() |
| Scope Name | 1.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v2.0.50727 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | 1 |
| Assembly Version | 1.28.14.52 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 1178 |
| Main Method | System.Void MusicExpress.Program::Main() |
| Main IL Instruction Count | 6 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.