Suspicious
Suspect

2680dd7239138d434e72e4e260792c00

PE Executable
MD5: 2680dd7239138d434e72e4e260792c00
Size: 904.19 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 2680dd7239138d434e72e4e260792c00
Sha1 c71449356ad109f44abde01e77b72815de9feacf
Sha256 f1ca533620933da6d4e119a4bc7b44e233617007cd4ee0239591d0fd0946e718
Sha384 1decbf888681fcd34078799dab7b84ceb489d2d928ce11d4dde9d03ba6c718031f7566e1b2786d29393d5c4676b39bbf
Sha512 a0159a9915286e1c1a481d7473287c746b4a81469833ea9c5626e76db8804206cd0142a0c9746c5357a42e8a1bc792fd9ea6bae52f0b4f7b2833bf03e08d85f7
SSDeep 24576:a7p509c/miuypOzP7NgL6j5nOU9Uwi0Icjbm8p:SpEByUzPB46FnOIUwicjD
TLSH 1715F1542252EA41E0D6C7F3B860E33132B90DDF39E2D3929FE56FF738593856994242
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SunriseTimer.Properties.Resources.resources
HI
[NBF]root.Data
HiHv
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
lPgy.exe
Full Name
lPgy.exe
EntryPoint
System.Void SunriseTimer.Program::Main()
Scope Name
lPgy.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lPgy
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
229
Main Method
System.Void SunriseTimer.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SunriseTimer.frmClock::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SunriseTimer.Properties.Resources.resources
HI
[NBF]root.Data
HiHv
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙