Suspicious
Suspect

0a93a6a35f294cab7dd13a0b8a9e0cbe

PE Executable
MD5: 0a93a6a35f294cab7dd13a0b8a9e0cbe
Size: 100.35 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 0a93a6a35f294cab7dd13a0b8a9e0cbe
Sha1 7568df3124a00fccb06e94255aa567d303c5ddc2
Sha256 a18a40caaedeb504fc7cbc3eedfb25d30493b74e196fc49963599fb0ece7ff25
Sha384 574e996ad1a4d16dc79cb517f953936cd87d0167099d40f0570d15af639adb6348cb071c1c214e42c6b76aa44bfade17
Sha512 37f3d88d60bf445ffc08a8beeffca26ce6e88bc7e4ca162c6bb8b20d3766d99e4158ebc0a38b3a9bbdbb1c740c695094bceaf7143ccc597916a763b7b5852cdd
SSDeep 3072:C23EvugyrIODdaH1igdDuN5Sr5Tk9gx9TyfWZ65:b3EGnrIeiZ20r5bx92fWZ65
TLSH 5FA3D0187658817BDCBF5FFC9C7232005372E99AE639C68E2D88D98D285774059A0FB3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0002
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
logo.png
logo.png-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

img 2bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
ghLauncher.exe
Full Name
ghLauncher.exe
EntryPoint
System.Void GhLauncher.Program::Main(System.String[])
Scope Name
ghLauncher.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ghLauncher
Assembly Version
1.2.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
97
Main Method
System.Void GhLauncher.Program::Main(System.String[])
Main IL Instruction Count
42
Main IL
ldc.i4 3264
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.8 <null>
call System.Void System.Net.ServicePointManager::set_DefaultConnectionLimit(System.Int32)
ldarg.0 <null>
brfalse.s IL_004A: call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldarg.0 <null>
ldlen <null>
conv.i4 <null>
ldc.i4.2 <null>
blt.s IL_004A: call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldarg.0 <null>
ldc.i4.0 <null>
ldelem.ref <null>
ldstr /exclude
ldc.i4.5 <null>
call System.Boolean System.String::Equals(System.String,System.String,System.StringComparison)
brfalse.s IL_004A: call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldarg.0 <null>
ldc.i4.1 <null>
ldelem.ref <null>
call System.Boolean GhLauncher.MainForm::AddExclusion(System.String)
stloc.0 <null>
ldloc.0 <null>
brfalse.s IL_003D: ldloc.0
ldarg.0 <null>
ldc.i4.1 <null>
ldelem.ref <null>
call System.Void GhLauncher.MainForm::WriteMarker(System.String)
ldloc.0 <null>
brtrue.s IL_0043: ldc.i4.0
ldc.i4.1 <null>
br.s IL_0044: call System.Void System.Environment::set_ExitCode(System.Int32)
ldc.i4.0 <null>
call System.Void System.Environment::set_ExitCode(System.Int32)
ret <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void GhLauncher.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
ghLauncher.exe
Full Name
ghLauncher.exe
EntryPoint
System.Void GhLauncher.Program::Main(System.String[])
Scope Name
ghLauncher.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ghLauncher
Assembly Version
1.2.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
97
Main Method
System.Void GhLauncher.Program::Main(System.String[])
Main IL Instruction Count
42
Main IL
ldc.i4 3264
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.8 <null>
call System.Void System.Net.ServicePointManager::set_DefaultConnectionLimit(System.Int32)
ldarg.0 <null>
brfalse.s IL_004A: call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldarg.0 <null>
ldlen <null>
conv.i4 <null>
ldc.i4.2 <null>
blt.s IL_004A: call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldarg.0 <null>
ldc.i4.0 <null>
ldelem.ref <null>
ldstr /exclude
ldc.i4.5 <null>
call System.Boolean System.String::Equals(System.String,System.String,System.StringComparison)
brfalse.s IL_004A: call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldarg.0 <null>
ldc.i4.1 <null>
ldelem.ref <null>
call System.Boolean GhLauncher.MainForm::AddExclusion(System.String)
stloc.0 <null>
ldloc.0 <null>
brfalse.s IL_003D: ldloc.0
ldarg.0 <null>
ldc.i4.1 <null>
ldelem.ref <null>
call System.Void GhLauncher.MainForm::WriteMarker(System.String)
ldloc.0 <null>
brtrue.s IL_0043: ldc.i4.0
ldc.i4.1 <null>
br.s IL_0044: call System.Void System.Environment::set_ExitCode(System.Int32)
ldc.i4.0 <null>
call System.Void System.Environment::set_ExitCode(System.Int32)
ret <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void GhLauncher.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0002
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
logo.png
logo.png-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙