Suspicious
Suspect

1a4b49379f3da71c8d7d828535298376

PE Executable
MD5: 1a4b49379f3da71c8d7d828535298376
Size: 1.63 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 1a4b49379f3da71c8d7d828535298376
Sha1 7360fcfbf857c151f23ce283cba6d268fade0a1f
Sha256 2b7dbba7689d6c299e1bb956a0a7ea21b457f523c25f67a3b39c5ddef8ea2543
Sha384 3bd8d12159781fae793266568a929872f3d882db7f4f4ea31b849e1f7f14844fbb55b2317aa038b920231e88eb608099
Sha512 c7f90ab5d200dec39092dbe9faaff132ece5261b6461fe98c88ccad3584da7682ceb8e8c4d51be72f432b4ad266bf61dde07f6764800fcc95c5e6d70acf7d791
SSDeep 49152:GUsAQJBp4etpi/B9RW04IunIX1qKfiHlzvS:GPqOaLvinIA7FDS
TLSH 937522885A46EA0AC995473C0A61F7F40B784EDDE511D2076FDCBEFBB6B5E168C102C2
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
SpaceFactoryTycoon.AA.resources
SpaceFactoryTycoon.Properties.Resources.resources
TY
[NBF]root.Data
iFZc
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\wQcYnywFLf\src\obj\Debug\Kalb.pdb
Module Name
Kalb.exe
Full Name
Kalb.exe
EntryPoint
System.Void SpaceFactoryTycoon.Program::Main()
Scope Name
Kalb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Kalb
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
53
Main Method
System.Void SpaceFactoryTycoon.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SpaceFactoryTycoon.UI.MasterControlDesk::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
SpaceFactoryTycoon.AA.resources
SpaceFactoryTycoon.Properties.Resources.resources
TY
[NBF]root.Data
iFZc
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙