Suspicious
Suspect

2d5137f186bd8f99e610367e7bab3631

Share on LinkedIn
Print
PE Executable
MD5: 2d5137f186bd8f99e610367e7bab3631
Size: 1.09 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 2d5137f186bd8f99e610367e7bab3631
Sha1 aa68f095eebfae5a1122dd82c9c4e9373af1b0ec
Sha256 74eb42416b47c082fc867764b577ceac6f1bd68e192695d79a9e48a7bd3fdd69
Sha384 e0f65527e83ae8b6782d39f2881913747a40586301a0fabab1c5f24201bff49b62b4df5f40f2a008d9181a6ef907f681
Sha512 5ebe9061f4a75ba228a159f2c6e47c9b4cc6edd196717b7383f6c1677d2bfbf548e521979bb9b380a1328149c6a1119924f2b0f619f831f4d50f34f5a238c950
SSDeep 24576:0hok0jPd5hM5pSZQu3+uIXnw+5UwibTZU4AVGAe/IPfzzBsroeA9s:uok0bdnaSCu3+uqnw+5Uwib9dYGH/Qby
TLSH 533511586646EA07CA9583780EB2E3B9537D6EDDA500E3030FDDADEB7926F065C04393
PeID
.NET executableHQR data fileMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TuningForkApp.Properties.Resources.resources
NeDz
[NBF]root.Data
[NBF]root.Data-preview.png
TY
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
YENG.exe
Full Name
YENG.exe
EntryPoint
System.Void TuningForkApp.Program::Main()
Scope Name
YENG.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YENG
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
215
Main Method
System.Void TuningForkApp.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TuningForkApp.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
YENG.exe
Full Name
YENG.exe
EntryPoint
System.Void TuningForkApp.Program::Main()
Scope Name
YENG.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YENG
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
215
Main Method
System.Void TuningForkApp.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TuningForkApp.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙