Suspect
PE Executable
MD5: ea48a32e9ccb90462b6bb8db618cbb69
Size: 279.55 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
High
| MD5 | ea48a32e9ccb90462b6bb8db618cbb69 |
| Sha1 | 9ee9b483b28e3a978c2330f081edf3a8f63172b5 |
| Sha256 | ac929f42a3157efcd9a4446d590188f129a22fcacd39496557f6a36e86e7a4e5 |
| Sha384 | 0bf8601681dd5d2eecb0f666c35907421934eadaf711c87eae65e12c5cfbce58011fa1801b54a00f7c6fc87742796f01 |
| Sha512 | 062abd8f1341d89a0bfa279beebfc9d2710a4404c4a9b0bcc693cfff8aa81cbfb1be284686c9f8ad6282b0c666e2b92b7fc579271f2a6fff5ad9c860e45d7370 |
| SSDeep | 6144:TvSy/0RRIyTh01lNMMmsAMP3tAZpFPyJN:n/4IX6uUFaL |
| TLSH | 3E54CF796FDCE606CFDC07BAA5B6006095F1A591B503E3BFA42C7BB13902BD0691825F |
STICH
beta
No STICH Path has been generated for this analysis yet.
1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
1| Name | Value |
|---|---|
| Module Name | PrinterNotifyPotato.exe |
| Full Name | PrinterNotifyPotato.exe |
| EntryPoint | System.Void Zcg.Exploits.Local.PrinterNotifyPotato::Main(System.String[]) |
| Scope Name | PrinterNotifyPotato.exe |
| Scope Type | ModuleDef |
| Kind | Console |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | PrinterNotifyPotato |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 12 |
| Main Method | System.Void Zcg.Exploits.Local.PrinterNotifyPotato::Main(System.String[]) |
| Main IL Instruction Count | 0 |
| Main IL | — |
| Info | PE Detect: PeReader OK (file layout) |