Suspicious
Suspect

27139922a7ac56aa3e54591cbf8e21bd

Share on LinkedIn
Print
PE Executable
MD5: 27139922a7ac56aa3e54591cbf8e21bd
Size: 1.07 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 27139922a7ac56aa3e54591cbf8e21bd
Sha1 9426e24435e9ebd360362d15c408df8cb2ea21db
Sha256 565110ae685e0248e3ed684c859ccd1cc092c3ad1aa6a05fbfbefb10af46583b
Sha384 fddf3786636320f49fb66c747bade5ae78061f57c1ccfeaadf884a44fba67e3c07cce23598072f3af6d7bd2e1915eedb
Sha512 5c36d0f78adbbcbc277d4534feb707d4d63ea79d19ffec892a26459af6dc462fdf231e18d57ec824bca32031749fb04cfb63e9c0060a5eec4188245edeb8c5f4
SSDeep 24576:xulhFab5Rz8uXXrdrc4pir95BTFH4enH0d04Q0dewv:xulubpir9zTFH4enUdXTd
TLSH 0C354B1137ED6AE9F07F6F35D2E56255D77AE3722606DB8B1E00C24A1D13B42CE4283A
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
.Net Resources
BrightIdeasSoftware.Properties.Resources.resources
ClearFiltering
[NBF]root.Data
[NBF]root.Data-preview.png
ColumnFilterIndicator
[NBF]root.Data
[NBF]root.Data-preview.png
Filtering
[NBF]root.Data
[NBF]root.Data-preview.png
SortAscending
[NBF]root.Data
[NBF]root.Data-preview.png
SortDescending
[NBF]root.Data
[NBF]root.Data-preview.png
BrightIdeasSoftware.ColumnSelectionForm.resources
ILRepack.List
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\mikez\AppData\Local\Temp\LX_T5E5YyrS_XBY\ILRepack-13832-554975\LX_T5E5YyrS_XBY.pdb
Module Name
LX_T5E5YyrS_XBY
Full Name
LX_T5E5YyrS_XBY
EntryPoint
System.Void SIL.Harmony.Program::<Main>(System.String[])
Scope Name
LX_T5E5YyrS_XBY
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LX_T5E5YyrS_XBY
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
535
Main Method
System.Void SIL.Harmony.Program::<Main>(System.String[])
Main IL Instruction Count
7
Main IL
ldarg.0 <null>
call System.Threading.Tasks.Task SIL.Harmony.Program::Main(System.String[])
callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter()
stloc.0 <null>
ldloca.s V_0
call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult()
ret <null>
Module Name
LX_T5E5YyrS_XBY
Full Name
LX_T5E5YyrS_XBY
EntryPoint
System.Void SIL.Harmony.Program::<Main>(System.String[])
Scope Name
LX_T5E5YyrS_XBY
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LX_T5E5YyrS_XBY
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
535
Main Method
System.Void SIL.Harmony.Program::<Main>(System.String[])
Main IL Instruction Count
7
Main IL
ldarg.0 <null>
call System.Threading.Tasks.Task SIL.Harmony.Program::Main(System.String[])
callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter()
stloc.0 <null>
ldloca.s V_0
call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult()
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙