Suspicious
Suspect

0b905aa2442d333f5c3bccc3724a5d7a

PE Executable
MD5: 0b905aa2442d333f5c3bccc3724a5d7a
Size: 1.05 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 0b905aa2442d333f5c3bccc3724a5d7a
Sha1 bcb6ff58f5bda59e4f119d76f7ef21f7d55e9a2e
Sha256 31a762fdce1008e635a5e6486d7bc50b4bce671c9232006216e70cd8f2a4a7fb
Sha384 8d8c71c406c36e7347017ca038ac1161ba488c869b7a08d12b29317306870d4a6ff3e455513a3e424166effcc18ed11a
Sha512 030ba780dc86e8579c214197b21fe5575a442162d85df5fb57e458c60109b146325ad73c65cb73db50e6a5b49fb7244bad03302218b72a8185d5850529108354
SSDeep 12288:lIQEdI+zxxltnn0g5zjIhSl6Cm25d3zJc0lzcV7dUxY3qUO+5jHxm+KBQ8MTFVpE:roFzp50Qzh6mDJDlrxcqUTtyQd+oR
TLSH 462501541266E902E1D68BF678B0D33432345DCFB9E2C3D29FE96FF778293816954282
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SoapBubble.Properties.Resources.resources
HI
[NBF]root.Data
RzPh
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
XEIJ.exe
Full Name
XEIJ.exe
EntryPoint
System.Void SoapBubble.Program::Main()
Scope Name
XEIJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XEIJ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
178
Main Method
System.Void SoapBubble.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SoapBubble.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SoapBubble.Properties.Resources.resources
HI
[NBF]root.Data
RzPh
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙