Suspect
PE Executable
MD5: f6249b14a0b8485d665b402fdb076a98
Size: 252.42 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | f6249b14a0b8485d665b402fdb076a98 |
| Sha1 | edd2d35b1d05e2db6869f2227e914723b5b4e7e0 |
| Sha256 | e6d567df857135bc75f5f260efc36de7ff65753a0194f87ceb4bf8ef4e4ca672 |
| Sha384 | 8bded0725215960e2d3209d023874238d06a209f270f8839533320854525c9b9c254d3fc8ff976a61cd3523c1fc2eb11 |
| Sha512 | 29028c44fabc9e9622e58a2ea331bc34096a4310aaf947a28030d26589b84ff4d5eefa12d58c8c4490b5c7376fef2abed9a4851471bba461e336e360ab11407e |
| SSDeep | 3072:DcDTxU7ZsUFLX1OSBsZHvfDMPcNJGdSutY2Oz50ARISFirKoXsA+fKpK:DVfcKGHYPUZmm+rKoOyp |
| TLSH | 3234289477FC1214F2BF8F79A87454504AB7F427A926D70E1CDA61DC2A32B90EA14B33 |
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
STICH
beta
No STICH Path has been generated for this analysis yet.
1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
1| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | Stealerv37.exe |
| Full Name | Stealerv37.exe |
| EntryPoint | System.Void CvMega.Program::<Main>(System.String[]) |
| Scope Name | Stealerv37.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Stealerv37 |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.6.2 |
| Total Strings | 2473 |
| Main Method | System.Void CvMega.Program::<Main>(System.String[]) |
| Main IL Instruction Count | 7 |
| Main IL | |