Suspicious
Suspect

11d800c0e492f8ee8090a873f5838561

PE Executable
MD5: 11d800c0e492f8ee8090a873f5838561
Size: 1.04 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 11d800c0e492f8ee8090a873f5838561
Sha1 d0be646573decf151d3aa1985cb67c20a7f1c8e2
Sha256 bad86d2aabc76beaa78036bec4f2ecd8f2c8649f75ee7d85aabe487cdd343853
Sha384 1a10fc6148f31fde0cc0b7b2ceb046ddef830423b56159c8777164a8a5423b149b866fc42b0f4cf8bf57e78981fb1c06
Sha512 2120dff51a7498fbe93d8eb3c7d5fbc2698942e61f86545c73d34842d958ee22330811517178f91b25cd295ca264754a380d1b7fbcdfd59a37c27869ef134557
SSDeep 24576:RW+CIliNyA4fxuAKUhkeIe+59V6LNMKHTKW7JwAZjaA:E6iXIhrITvV6ZTzKW7JtB
TLSH B02523D66398D631C495077949B7F37153B4CDEEB233E66ACFD9BDEB7A222000806261
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GalacticEmpire4X.MainDashboard.resources
$this.Icon
[NBF]root.IconData
MR5
[NBF]root.Data
GalacticEmpire4X.ColonyManagerDesk.resources
GalacticEmpire4X.Properties.Resources.resources
aumf
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: bLJh.pdb
Module Name
bLJh.exe
Full Name
bLJh.exe
EntryPoint
System.Void GalacticEmpire4X.Program::Main()
Scope Name
bLJh.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
bLJh
Assembly Version
4.2.6.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
69
Main Method
System.Void GalacticEmpire4X.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void GalacticEmpire4X.MainDashboard::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GalacticEmpire4X.MainDashboard.resources
$this.Icon
[NBF]root.IconData
MR5
[NBF]root.Data
GalacticEmpire4X.ColonyManagerDesk.resources
GalacticEmpire4X.Properties.Resources.resources
aumf
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙