Suspicious
Suspect

13cd87a5fdda3b0b5b287ab04308de19

PE Executable
MD5: 13cd87a5fdda3b0b5b287ab04308de19
Size: 844.29 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 13cd87a5fdda3b0b5b287ab04308de19
Sha1 6bc04d0562f5b59f81c8f3cad97a21e3ae63414a
Sha256 f038491715d1d1b55c9227612ccf55089b771bbcadcf053dbf2fc939715dfd9f
Sha384 6e5379cd2b8e2d03df2795a30ae1c10ae2bd12d6126275f2305236c493f364cef391a084747bf870226c161ee0172da0
Sha512 07d71f8e4c84826b43fcfd5710ab8ee04b2cc94859d31060fd968e22638b3266f29db76c2f077478379596a8844289b43ec00f3434325ef59713be4c4f5ca0d6
SSDeep 12288:iSznnfoKa6Cv6Ds5WvzN08RM2MLMt9fdnco6O81rD9er7DWtxuJ8xxZjw2V9ck1w:iInnfoKa6CEWiNDRfzFAZ9W2xuJ8VpL
TLSH 580512443645DA03E89607F04DF1D37447B8AF99A801E30BCEEABCD77972B455A923A3
PeID
Armadillo v4.x
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNetworkAnalyzer.Forms.MainForm.resources
SmartNetworkAnalyzer.Properties.Resources.resources
greyder
[NBF]root.Data
lZE
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: BIq.pdb
Module Name
BIq.exe
Full Name
BIq.exe
EntryPoint
System.Void SmartNetworkAnalyzer.Program::Main()
Scope Name
BIq.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
BIq
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
243
Main Method
System.Void SmartNetworkAnalyzer.Program::Main()
Main IL Instruction Count
26
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
nop <null>
newobj System.Void SmartNetworkAnalyzer.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0040: ret
stloc.0 <null>
nop <null>
ldstr An unexpected error occurred: {0}

The application will now close.
ldloc.0 <null>
callvirt System.String System.Exception::get_Message()
call System.String System.String::Format(System.String,System.Object)
ldstr Fatal Error
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_0040: ret
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNetworkAnalyzer.Forms.MainForm.resources
SmartNetworkAnalyzer.Properties.Resources.resources
greyder
[NBF]root.Data
lZE
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙