Suspicious
Suspect

f9245195efcc99981f609520dbd16d07

PE Executable
MD5: f9245195efcc99981f609520dbd16d07
Size: 3.58 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 f9245195efcc99981f609520dbd16d07
Sha1 66bdb2a46282ee680445034e0f99a01ab1f977de
Sha256 63ebc5bb3a36ac820fddc9ccdd48a19bf8fc4b08fa4b5044bdf1027dbdce42e8
Sha384 1a1adc7948670f3b7a0f756da4654bf40a2f2879f900d4e5f2dd9889ce92aa7375fb398cb542e8f0d6066fa692070941
Sha512 7cd96bb7838e83c48de024d56994a4ea26b01ba6d2158a93a7640440d5d006839b81ab37619ab9c4902f04cde015a2c5f837fb71f06633810227d21e2a194e05
SSDeep 24:etGSU8mmzUe6J39GgFKdgKkjhtkZfemQEhWI+ycuZhNOakS2PNnq:6GjpEfS/jsJem61ulOa3Kq
TLSH 1F71CB1693E84A2BE4BA4B38EEB303162BE4FC50CE73576F49C4121A6C612601932FB0
PeID
Microsoft Visual C# / Basic .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
ndfn24us.dll
Full Name
ndfn24us.dll
Scope Name
ndfn24us.dll
Scope Type
ModuleDef
Kind
Dll
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ndfn24us
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
0
Main Method
Not found or no body
Module Name
ndfn24us.dll
Full Name
ndfn24us.dll
Scope Name
ndfn24us.dll
Scope Type
ModuleDef
Kind
Dll
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ndfn24us
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
0
Main Method
Not found or no body
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙