Suspicious
Suspect

2d5137f186bd8f99e610367e7bab3631

PE Executable
MD5: 2d5137f186bd8f99e610367e7bab3631
Size: 1.09 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 2d5137f186bd8f99e610367e7bab3631
Sha1 aa68f095eebfae5a1122dd82c9c4e9373af1b0ec
Sha256 74eb42416b47c082fc867764b577ceac6f1bd68e192695d79a9e48a7bd3fdd69
Sha384 e0f65527e83ae8b6782d39f2881913747a40586301a0fabab1c5f24201bff49b62b4df5f40f2a008d9181a6ef907f681
Sha512 5ebe9061f4a75ba228a159f2c6e47c9b4cc6edd196717b7383f6c1677d2bfbf548e521979bb9b380a1328149c6a1119924f2b0f619f831f4d50f34f5a238c950
SSDeep 24576:0hok0jPd5hM5pSZQu3+uIXnw+5UwibTZU4AVGAe/IPfzzBsroeA9s:uok0bdnaSCu3+uqnw+5Uwib9dYGH/Qby
TLSH 533511586646EA07CA9583780EB2E3B9537D6EDDA500E3030FDDADEB7926F065C04393
PeID
.NET executableHQR data fileMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TuningForkApp.Properties.Resources.resources
NeDz
[NBF]root.Data
[NBF]root.Data-preview.png
TY
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
YENG.exe
Full Name
YENG.exe
EntryPoint
System.Void TuningForkApp.Program::Main()
Scope Name
YENG.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YENG
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
215
Main Method
System.Void TuningForkApp.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TuningForkApp.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
YENG.exe
Full Name
YENG.exe
EntryPoint
System.Void TuningForkApp.Program::Main()
Scope Name
YENG.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YENG
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
215
Main Method
System.Void TuningForkApp.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TuningForkApp.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TuningForkApp.Properties.Resources.resources
NeDz
[NBF]root.Data
[NBF]root.Data-preview.png
TY
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙