Suspicious
Suspect

21da12e496e8393fce26cd13e2361969

PE Executable
MD5: 21da12e496e8393fce26cd13e2361969
Size: 1.09 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 21da12e496e8393fce26cd13e2361969
Sha1 9998328d5217220703d1bf1c38e75ee420473865
Sha256 21ed13c8d7ec99df0c224171fc7d1d3f2bd08ff17c567564589c2ba769214735
Sha384 05fa4885bde72a05d433410f225302a3ec42298107814b66b5d3821e2ad81cfc8c042720487f93e891275bda62522d31
Sha512 0302ffd6fe7ce0a778d4f701b3cedcce144d3c1615ef3c71098fb6abbc0941ff4c4b106823084104f5fbe24556dbecd377543b260262fdf1c5cd4c004843c769
SSDeep 12288:gehmBQVkd34QmFwBrBg8y2EpVHqHK80S7RBbyLbi4GNb7WkAQAu9wby9ZR5LqS5O:gRBQeCwBrzy2EG/9tSGB3W6wbyn3qaO
TLSH AA35E05422599BD2C9E537F74672E238C7B62D8EA425F21B4ED4BFD7F932B00C842252
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GlassFurnace.FormFourneau.resources
GlassFurnace.Properties.Resources.resources
GM
[NBF]root.Data
ooRU
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Suki.exe
Full Name
Suki.exe
EntryPoint
System.Void GlassFurnace.Program::Main()
Scope Name
Suki.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Suki
Assembly Version
1.3.1.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
331
Main Method
System.Void GlassFurnace.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void GlassFurnace.FormFourneau::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GlassFurnace.FormFourneau.resources
GlassFurnace.Properties.Resources.resources
GM
[NBF]root.Data
ooRU
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙