Suspicious
Suspect

215f3abf5f180560d7ef95581a1c07dc

PE Executable
MD5: 215f3abf5f180560d7ef95581a1c07dc
Size: 852.48 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 215f3abf5f180560d7ef95581a1c07dc
Sha1 dd4c7e8512fc4447544d36ecdff856fa53548e06
Sha256 b897296b26ad15c42b2194eb6c75fd5a2b91aede9e7b9606acb1ae2bbe3e269c
Sha384 c8d708bc6e895e21bb2ecab33d52e54442495a6fa24cfeb2de540d66903cb99f769355f320b8448d4a05f0583c745349
Sha512 d67ccf8adae719dabb0b9211ca83dc89e1109a656f6bfdf01e51b19c82ebf1e199f799a5e596d7a5ad10d9d239093f001e109102ea21060d16c7e61a255c56b1
SSDeep 24576:E5aYShxBknkWYJ91ItTwNj+4OyiQRnnf:RzhxBIkRO8jLf
TLSH 310512142252CA03D4F51BF5ACA1E7B04BB86ECAE801D3078EF9BDE77C367944A45366
PeID
Armadillo v4.x
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNetworkAnalyzer.Forms.MainForm.resources
SmartNetworkAnalyzer.Properties.Resources.resources
VPz
[NBF]root.Data
[NBF]root.Data-preview.png
greyder
[NBF]root.Data
Name Value
Module Name
iPr.exe
Full Name
iPr.exe
EntryPoint
System.Void SmartNetworkAnalyzer.Program::Main()
Scope Name
iPr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
iPr
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
243
Main Method
System.Void SmartNetworkAnalyzer.Program::Main()
Main IL Instruction Count
26
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
nop <null>
newobj System.Void SmartNetworkAnalyzer.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0040: ret
stloc.0 <null>
nop <null>
ldstr An unexpected error occurred: {0}

The application will now close.
ldloc.0 <null>
callvirt System.String System.Exception::get_Message()
call System.String System.String::Format(System.String,System.Object)
ldstr Fatal Error
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_0040: ret
ret <null>
PDB Path PATH
iPhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNetworkAnalyzer.Forms.MainForm.resources
SmartNetworkAnalyzer.Properties.Resources.resources
VPz
[NBF]root.Data
[NBF]root.Data-preview.png
greyder
[NBF]root.Data
No malware configuration was found at this point.
PDB Path PATH
iPhuhuhuhu
215f3abf5f180560d7ef95581a1c07dc
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙