Suspicious
Suspect

2e688af35698aadb14d24e425f5c5e8f

PE Executable
MD5: 2e688af35698aadb14d24e425f5c5e8f
Size: 1.13 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 2e688af35698aadb14d24e425f5c5e8f
Sha1 dcc8071900625e6e0df5de9ae0156c4da85b2c4b
Sha256 6decd2481cdb54b64b432e5632bfc91fddb8bcaa7d0d2289366ee1ae895025b9
Sha384 beb420d0a5f2fefdd25953cb6fd24c6f76042fc6aa9a4ba794f2f565e84ff7521e6c0e33dd12c812234f390e3a8fc4c7
Sha512 7775b32d8f20cbe161e3b55ca3784269f8a6f7215c6822a7b1977123968d189e8f977b3fd095093b5ba5448953181b41469b5336d3360ef5f8d86575f00f9e92
SSDeep 24576:CNjP/2oSdvf029IhKPHep19INYXZhJO6doZzS5/6xDQ3hG/k+6Lt:Yb/2oShJIs+p19FNdce16xDakT6t
TLSH A83501082216DE02E5F25FF04D70E3B417B91E98E921D3038EFABDDBB96678529452D3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CharcoalKiln.Properties.Resources.resources
Pro
[NBF]root.Data
TZLC
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
PDiW.exe
Full Name
PDiW.exe
EntryPoint
System.Void CharcoalKiln.Program::Main()
Scope Name
PDiW.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PDiW
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
429
Main Method
System.Void CharcoalKiln.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CharcoalKiln.UgnForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
PDiW.exe
Full Name
PDiW.exe
EntryPoint
System.Void CharcoalKiln.Program::Main()
Scope Name
PDiW.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PDiW
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
429
Main Method
System.Void CharcoalKiln.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CharcoalKiln.UgnForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CharcoalKiln.Properties.Resources.resources
Pro
[NBF]root.Data
TZLC
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙