Suspicious
Suspect

PE Executable
MD5: 2e5ef0e1f7add246d7f98ccdfe8047b9
Size: 683.52 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 2e5ef0e1f7add246d7f98ccdfe8047b9
Sha1 941c0ab9588794c92ec30e4886928d8fdc8c14b6
Sha256 74ca5aad35d138c31e8cc8bf3a0d3389ab321fac99483f475fa434a6ffd8a6a4
Sha384 9a4138c0f7ecda25d69e706785d78389411b12f6c02715ea24bccc9f82e559f174f436518e30dfefb83d3ce580479351
Sha512 c07d2856562076a3d0f21fd86e8dd2e28c3c83c4aedfc694a069547d386919bde7f98281660a26d9cd9c44daf8e98842bfe934b1c762b9cfd760dda0a0804968
SSDeep 12288:u5WuVoZmFykzfxAtve56nsFGVuam3r/zzoqbKCXPJc+1UK6EqYTqWxVbMiNgvmjg:GHVoZmFykbGC/Fcn0bKgPV1BqKxVb6r
TLSH 8BE412A1AA69EA12C4A64BF10B70C7B3173AAECCD421C30BE9DEECC7B90535535553C2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PuhonRM.Properties.Resources.resources
PLje
vgx
PuhonRM.AddItem.resources
PuhonRM.ItemView.resources
btnAdd.Image
Name Value
Module Name
ALcY.exe
Full Name
ALcY.exe
EntryPoint
System.Void PuhonRM.Program::Main()
Scope Name
ALcY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ALcY
Assembly Version
1.6.2010.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
107
Main Method
System.Void PuhonRM.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PuhonRM.ItemView::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
ALcY.exe
Full Name
ALcY.exe
EntryPoint
System.Void PuhonRM.Program::Main()
Scope Name
ALcY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ALcY
Assembly Version
1.6.2010.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
107
Main Method
System.Void PuhonRM.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PuhonRM.ItemView::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
6huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PuhonRM.Properties.Resources.resources
PLje
vgx
PuhonRM.AddItem.resources
PuhonRM.ItemView.resources
btnAdd.Image
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
6huhuhuhu
2e5ef0e1f7add246d7f98ccdfe8047b9
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
2e5ef0e1f7add246d7f98ccdfe8047b9
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙