Suspicious
Suspect

2519e7b005a0bd8e444eafa32d41141c

PE Executable
MD5: 2519e7b005a0bd8e444eafa32d41141c
Size: 1.23 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 2519e7b005a0bd8e444eafa32d41141c
Sha1 8aab7cf8930de6e7796cab2447bcd0211e9f9ef5
Sha256 af8e39184404f87ea53f29454ca0211d51991129cda12387ee5ccb1a2dd83d7a
Sha384 12e44f382fefdaf907ef8b13e59628111cecdf48f8b66ab4dbfca8cb6f7a8c2159be7926c5ee4afe069b650d6853200c
Sha512 2170b9fb8ab5672ce00c9e4ac8b4dedfe1b7876beff0cd6801bccc27db8fd418c45f5d7e943cec7dad4a6f052396c86b089db37b320d8e7f379ef2c28822217e
SSDeep 24576:GvSRp50166sYqKksJhmUMkj3RAKqK38GpkIdwFYZkpx93LyR:GUpe66X9ksvnMkOhKMMkIdwr9uR
TLSH 6D45011523069E41E0E687F6B870D37472680DDF79E2C3D69FEAAFF738293805854692
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SoapBubble.Properties.Resources.resources
HI
[NBF]root.Data
YNaC
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
FzIC.exe
Full Name
FzIC.exe
EntryPoint
System.Void SoapBubble.Program::Main()
Scope Name
FzIC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
FzIC
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
178
Main Method
System.Void SoapBubble.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SoapBubble.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SoapBubble.Properties.Resources.resources
HI
[NBF]root.Data
YNaC
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙