Suspicious
Suspect

229d2c8e2d68ee55f336d5393e2f4721

Share on LinkedIn
Print
PE Executable
MD5: 229d2c8e2d68ee55f336d5393e2f4721
Size: 867.33 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 229d2c8e2d68ee55f336d5393e2f4721
Sha1 d3ca69da866842d3dc0bd2854906e90fcd1c55f5
Sha256 0384e80d3e541b243f0bd66f0ca4e346a15574039c30e25060bf0c0a7f0e5e4e
Sha384 ece163505bd0811b0ecc1204349c9fd6a213813de7083c6840744de9b3cd31ee7abb095a728adc381d48157955a82d63
Sha512 f88e3ac69f91c642cb1c22593e936f2b9f5e0ad06af680a9a00eed3ab5cd7d85b9990765c8da89e5eea47e99d588d00e8da42fb6873ecade764be79096293367
SSDeep 24576:OQR+ioCfTGU/9xJLrM0AEBe7E1+v29DioPhD2MzX:OQRa6GU/l/A+ePcPbzX
TLSH 9505F118231AE905D8464F784D72E7F45B655EC8BA50D3038EFEBEFFB875A096C05282
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
.Net Resources
RetroDSP.About.resources
RetroDSP.SynthMainForm.resources
$this.Icon
[NBF]root.IconData
Sed
[NBF]root.Data
RetroDSP.OscilloscopeForm.resources
RetroDSP.Properties.Resources.resources
bEYn
[NBF]root.Data
[NBF]root.Data-preview.png
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Module Name
FeZY.exe
Full Name
FeZY.exe
EntryPoint
System.Void RetroDSP.Program::Main()
Scope Name
FeZY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
FeZY
Assembly Version
0.2.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
89
Main Method
System.Void RetroDSP.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RetroDSP.SynthMainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\PaLfNepqAL\src\obj\Debug\FeZY.pdb
Module Name
FeZY.exe
Full Name
FeZY.exe
EntryPoint
System.Void RetroDSP.Program::Main()
Scope Name
FeZY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
FeZY
Assembly Version
0.2.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
89
Main Method
System.Void RetroDSP.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RetroDSP.SynthMainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙