Suspicious
Suspect

12a289bdf1aec09a981dff99979cb8bb

PE Executable
MD5: 12a289bdf1aec09a981dff99979cb8bb
Size: 1 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 12a289bdf1aec09a981dff99979cb8bb
Sha1 b134abf59b77f0d8ddb4596cad72101ba2ed88ac
Sha256 806f226d65cd883f71504ed0cd9f7e4b0dbf837d1fdd3688c82a7a53e66c2bf0
Sha384 614414d629753a18a4b4ca6307f6960638b7bfc0c1b8b0631cde06f30a0dab3e8f12609d7115142d8c581e12a9abcdd9
Sha512 c2f4bea0315098ee4885dd98a6d0d7c552a3cd97899d6f3898f8f78c245220aa123fa15d87494f3ac4bd40d6f57923860562ac6cebb57d31e2b00cb3f8054b86
SSDeep 24576:fcXxiVYd8Grq7zkFVZDUfe1Kaa4eRrvkas3mucG5K:fcBiRGtEe4D48rvS3mj
TLSH AD25220C2659CF17CAAB1BF60D55D27123781DCE6C20DA0A1FC5AEEF3A68B650D50B93
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SaltPan.HuvudForm.resources
SaltPan.Properties.Resources.resources
IMG
[NBF]root.Data
fLoJ
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
gEXr.exe
Full Name
gEXr.exe
EntryPoint
System.Void SaltPan.Program::Main()
Scope Name
gEXr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gEXr
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
262
Main Method
System.Void SaltPan.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SaltPan.HuvudForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SaltPan.HuvudForm.resources
SaltPan.Properties.Resources.resources
IMG
[NBF]root.Data
fLoJ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙