Suspicious
Suspect

0c055a6c37a3bcac283e9aa8815e1e01

PE Executable
MD5: 0c055a6c37a3bcac283e9aa8815e1e01
Size: 1.03 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 0c055a6c37a3bcac283e9aa8815e1e01
Sha1 a687f253ecf2e5f82dba73c198c1dc4f436b8588
Sha256 c95048957b30f2101720abdcff23a17c52ad35241dcda2fcafab3376015ee882
Sha384 0c5d5abea46bb90fd84cc7091ca5f5017bd036bce409ad3bf3f0879162d7a42d8248774791ba37ee496ab14d47ed9f74
Sha512 f1ad492f4e786ba025ce2e7b2077c252861664012b3821f9eb678252328b93b804f27122c06bd51104e9de4d9815044b58b44b7e06fa45d0fa036320ac5f5f66
SSDeep 24576:HNj/Og3bwAg16+K+Mv8svRqBRYCpwkalXrSrKhkg3B:NPLng1JtYCWlmu33B
TLSH 372512A473E8EB09C9B487B01A71E1310775AC2EA931E3464DDABCCFB975F054AA0753
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RuneBerg.FormMain.resources
RuneBerg.Properties.Resources.resources
DR
[NBF]root.Data
GGVU
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
noVN.exe
Full Name
noVN.exe
EntryPoint
System.Void RuneBerg.Program::Main()
Scope Name
noVN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
noVN
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
503
Main Method
System.Void RuneBerg.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RuneBerg.FormMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
noVN.exe
Full Name
noVN.exe
EntryPoint
System.Void RuneBerg.Program::Main()
Scope Name
noVN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
noVN
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
503
Main Method
System.Void RuneBerg.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RuneBerg.FormMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RuneBerg.FormMain.resources
RuneBerg.Properties.Resources.resources
DR
[NBF]root.Data
GGVU
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙