Suspicious
Suspect

1c7f26661343a771c692dee9c2233830

PE Executable
MD5: 1c7f26661343a771c692dee9c2233830
Size: 813.57 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 1c7f26661343a771c692dee9c2233830
Sha1 c80369f63f57eae5b7574c445093b2f5b1c90c5e
Sha256 3a69743c2e6248b3cfd9ed4b1f24d411aba3a5dc7cd2b787e23e0a77094bfc19
Sha384 f206069a069f25a9fc6aca5bf14324a692b610432b2b8c8b7f3ce3aa6ac7e0c91e470e3918892f76fa75a219c020c8bd
Sha512 7d5435344307b575f5df669e6f13f5166b3a9024d75b8291982771d420208edcdc9ba61c34e3422f26dac068371c57992ac4dc805ec5b836a09d4dbd507b98f3
SSDeep 12288:6/PNVllXILuLmaV+u+Xy8IiEhmnGlNmtvbAzEiFFifXzOT:C/l0uFPAy8IiEYENmtvbdfXiT
TLSH 3D05E0C03B65B716DDB41A359978EEB543B92D69B024F6E61EC93B8B396D7008D08F02
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SandglassArchitect.FormAlchimie.resources
SandglassArchitect.Properties.Resources.resources
DT
[NBF]root.Data
tkqh
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
ZToK.exe
Full Name
ZToK.exe
EntryPoint
System.Void SandglassArchitect.Program::Main()
Scope Name
ZToK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ZToK
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
502
Main Method
System.Void SandglassArchitect.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SandglassArchitect.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
ZToK.exe
Full Name
ZToK.exe
EntryPoint
System.Void SandglassArchitect.Program::Main()
Scope Name
ZToK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ZToK
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
502
Main Method
System.Void SandglassArchitect.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SandglassArchitect.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SandglassArchitect.FormAlchimie.resources
SandglassArchitect.Properties.Resources.resources
DT
[NBF]root.Data
tkqh
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙