Suspicious
Suspect

2d1e4ee926a2afd06353d3aec169d92d

PE Executable
MD5: 2d1e4ee926a2afd06353d3aec169d92d
Size: 688.64 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2d1e4ee926a2afd06353d3aec169d92d
Sha1 4df7b1836b73ca87bef6880a8201ce84ea4657a6
Sha256 f0b9b0fcc5688be094fe596b2c69681a8e37206d82e551844d7dbcb6c6118d84
Sha384 67d0ecf7365fb22cea05b348890fc21eb1d34ed8b3436be91eecf713f873023b03f10f1c1dc5da19385c230c064a7d50
Sha512 30f2af7a28d57a917bb252b9941a38cec48a2e2c12d4e634a02ce7b4cf68b83cdf80ec284996e63ba247a10adbad3f964472870d415f7a77235a3e0bc2dfd499
SSDeep 12288:Y81q04aHnAOaCyKPnppduuKjGfJedcVfvZ0r8omqlYvSdjb:vq09nRxycpEJjG9dv7gjb
TLSH 10E41255392DDC03D0BA0EF50E91C57923B99D8DA622C7D2AFCA2DEBF1E17912841363
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Module Name
famK.exe
Full Name
famK.exe
EntryPoint
System.Void SectorRepair.Program::Main()
Scope Name
famK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
famK
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
320
Main Method
System.Void SectorRepair.Program::Main()
Main IL Instruction Count
7
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.Void SectorRepair.Program::InitializeApplication()
newobj System.Void SectorRepair.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
famK.exe
Full Name
famK.exe
EntryPoint
System.Void SectorRepair.Program::Main()
Scope Name
famK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
famK
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
320
Main Method
System.Void SectorRepair.Program::Main()
Main IL Instruction Count
7
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.Void SectorRepair.Program::InitializeApplication()
newobj System.Void SectorRepair.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Embedded Resources UNKNWOWNsuspect
5huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
5huhuhuhu
2d1e4ee926a2afd06353d3aec169d92d
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
2d1e4ee926a2afd06353d3aec169d92d
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙