Suspicious
Suspect

2c1f1069302ba729f4b71b82c14bcd68

PE Executable
MD5: 2c1f1069302ba729f4b71b82c14bcd68
Size: 1.19 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 2c1f1069302ba729f4b71b82c14bcd68
Sha1 3dfc2d3e87f23960b1f997935d54ec9a45231453
Sha256 1d1c77589e367c5a891b2f8a1ddc2b38db9156a5a8673ca2ccda3d3dfb23a46d
Sha384 9365318c80ba0c7225d3002483c39275f3f5d8285c23da683bc74ff41c4ca151e24bf1d834b9b5cd4a5e5246c4a2217f
Sha512 0db8fad03f5b4c147d947043515fb7b837d879409ad2a8eefc36431b9b6282db5048011865b30e7f9e03229a72d27091d567ead907f1c0b0bd066a6a2197e0a9
SSDeep 12288:wUBcFqAG95adsLOrHz9dwg+lKx3KMmjTX6Us5Zmt9x23HSr4tOjyfUNOhjPEz/L4:Sg7adQODEpOKXTqUs59HqjyfUQtPyb
TLSH CA45D09C3211F89FC453CD718E64DD74AA602CAA970BD20395EB2EEFB90D5879F141E2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FrostLine.Properties.Resources.resources
TK
[NBF]root.Data
imVq
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
lcon.exe
Full Name
lcon.exe
EntryPoint
System.Void FrostLine.Program::Main()
Scope Name
lcon.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lcon
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
2
Main Method
System.Void FrostLine.Program::Main()
Main IL Instruction Count
37
Main IL
nop <null>
ldc.i4 2038522625
ldc.i4 1108181830
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.5 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0070: ret
nop <null>
newobj System.Void FrostLine.HauptForm::.ctor()
call System.Void FrostLine.Program::‭‪​‭‍‍‬‫‫‎​‬‌​‭‫‎‎‭​‌‫‪‮(System.Windows.Forms.Form)
nop <null>
ldloc.0 <null>
ldc.i4 -82930627
mul <null>
ldc.i4 1350870448
xor <null>
br.s IL_0006: ldc.i4 1108181830
ldc.i4.0 <null>
call System.Void FrostLine.Program::‮‬‏‌‎‪‌‭‮‍‎‍‮​‬‍‫‍‮‫‫​‭‍‫‍‮(System.Boolean)
ldloc.0 <null>
ldc.i4 -1727576126
mul <null>
ldc.i4 1405546677
xor <null>
br.s IL_0006: ldc.i4 1108181830
call System.Void FrostLine.Program::‏‎‏‬‪‌‮‏‫‍‭‪‍‭‫‭‌‎‍‪‌‮()
nop <null>
ldloc.0 <null>
ldc.i4 -1288735751
mul <null>
ldc.i4 2036344510
xor <null>
br.s IL_0006: ldc.i4 1108181830
ret <null>
Module Name
lcon.exe
Full Name
lcon.exe
EntryPoint
System.Void FrostLine.Program::Main()
Scope Name
lcon.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lcon
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
2
Main Method
System.Void FrostLine.Program::Main()
Main IL Instruction Count
37
Main IL
nop <null>
ldc.i4 2038522625
ldc.i4 1108181830
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.5 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0070: ret
nop <null>
newobj System.Void FrostLine.HauptForm::.ctor()
call System.Void FrostLine.Program::‭‪​‭‍‍‬‫‫‎​‬‌​‭‫‎‎‭​‌‫‪‮(System.Windows.Forms.Form)
nop <null>
ldloc.0 <null>
ldc.i4 -82930627
mul <null>
ldc.i4 1350870448
xor <null>
br.s IL_0006: ldc.i4 1108181830
ldc.i4.0 <null>
call System.Void FrostLine.Program::‮‬‏‌‎‪‌‭‮‍‎‍‮​‬‍‫‍‮‫‫​‭‍‫‍‮(System.Boolean)
ldloc.0 <null>
ldc.i4 -1727576126
mul <null>
ldc.i4 1405546677
xor <null>
br.s IL_0006: ldc.i4 1108181830
call System.Void FrostLine.Program::‏‎‏‬‪‌‮‏‫‍‭‪‍‭‫‭‌‎‍‪‌‮()
nop <null>
ldloc.0 <null>
ldc.i4 -1288735751
mul <null>
ldc.i4 2036344510
xor <null>
br.s IL_0006: ldc.i4 1108181830
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FrostLine.Properties.Resources.resources
TK
[NBF]root.Data
imVq
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙