Suspect
PE Executable
MD5: e687156548e1918f924bbe03c9751ffe
Size: 792.58 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | e687156548e1918f924bbe03c9751ffe |
| Sha1 | 5af16e1a715e910e647ee682325b3eae173b3310 |
| Sha256 | a5a6f09dbfef79a19d216620a173e636ad05e97f28a90bd4a08f12cc0254d24b |
| Sha384 | 0bbce3e83d1c244ae79d8f119c032cd0a669e87e4d4e8bbe4938064a5afaac5aa46c9ea53005e55803fb36793857fe6d |
| Sha512 | 60cd4d16afef9de7aba8b5713de7782c43b4777bb7aff0fd9e42e21c8787d438d209dee8b3d986f2fe9ac85452989de328deef4e61961bbc21da46513643fd61 |
| SSDeep | 12288:Lgnd3mq8lB00fIhzf6YC4zgQohWwzT3kuEfhvEnI+X0Wxezvw5vlfSIAD85BM+TN:Imt706Ih9C4z8XTyfh8IdWxezvp1D8 |
| TLSH | 3AF4D09C3250B49FC857C93689A4EC74AA607CAB9717C20790D71EAFBA4D957CF102B3 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | PhnQ.exe |
| Full Name | PhnQ.exe |
| EntryPoint | System.Void ModularCalculator.Program::Main() |
| Scope Name | PhnQ.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | PhnQ |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 175 |
| Main Method | System.Void ModularCalculator.Program::Main() |
| Main IL Instruction Count | 37 |
| Main IL | |
| Module Name | PhnQ.exe |
| Full Name | PhnQ.exe |
| EntryPoint | System.Void ModularCalculator.Program::Main() |
| Scope Name | PhnQ.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | PhnQ |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 175 |
| Main Method | System.Void ModularCalculator.Program::Main() |
| Main IL Instruction Count | 37 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.