Suspicious
Suspect

201c3977a10f73542515e22b07dad335

PE Executable
MD5: 201c3977a10f73542515e22b07dad335
Size: 1.15 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 201c3977a10f73542515e22b07dad335
Sha1 701fd7cbf22c14077bdd70883dd2eafbdd0074b3
Sha256 94acc5bde1e48ce426bc61ea90a8780cf2be98795aaba7d946d5fe9d43b3203d
Sha384 e21acae59a9fe9fac1e8ee59ed5aed7973bdd9aab4259f7b43d032ff92232bab1c51c3117712d0f668f21051931d23f8
Sha512 876a9d1686bd8513f72e8e9c00b95a453473e672db390535dc190c27acb1c160f1397912483e45d38aa5e878bf1344f6aeca9b68c540dc3f2786e83f3e240c2c
SSDeep 24576:g8S22IQTi0dSJIo/n/jR2aVE46ssWn5tKfjxQ/6R:gnTi0dSJjn/jE8J5LKbey
TLSH 7435DF00621BDA33C9163B71D9B3E2F406A45E44E821C23F5AE97EB77F76F751885282
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
.Net Resources
bV.l2.resources
WWo.fWH.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
AvalancheSlope.Properties.Resources.resources
OtQE
[NBF]root.Data
Kare
[NBF]root.Data
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Module Name
kGtz.exe
Full Name
kGtz.exe
EntryPoint
System.Void rA.lx::fF()
Scope Name
kGtz.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kGtz
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
323
Main Method
System.Void rA.lx::fF()
Main IL Instruction Count
20
Main IL
br IL_0031: nop
ldloc.s V_0
newobj System.Void bV.l2::.ctor(k1.f4)
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0016: nop
nop <null>
ret <null>
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_003C: call System.Void mMY.zM1::AJm()
nop <null>
newobj System.Void k1.f4::.ctor()
stloc.s V_0
br IL_0005: ldloc.s V_0
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0018: nop
call System.Void mMY.zM1::AJm()
br IL_0024: nop
Info
PE Detect: PeReader OK (file layout)
Module Name
kGtz.exe
Full Name
kGtz.exe
EntryPoint
System.Void rA.lx::fF()
Scope Name
kGtz.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kGtz
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
323
Main Method
System.Void rA.lx::fF()
Main IL Instruction Count
20
Main IL
br IL_0031: nop
ldloc.s V_0
newobj System.Void bV.l2::.ctor(k1.f4)
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0016: nop
nop <null>
ret <null>
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_003C: call System.Void mMY.zM1::AJm()
nop <null>
newobj System.Void k1.f4::.ctor()
stloc.s V_0
br IL_0005: ldloc.s V_0
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0018: nop
call System.Void mMY.zM1::AJm()
br IL_0024: nop
.Net Resources
bV.l2.resources
WWo.fWH.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
AvalancheSlope.Properties.Resources.resources
OtQE
[NBF]root.Data
Kare
[NBF]root.Data
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙