Suspicious
Suspect

385fcdf7cd2882b5b756f474b432bcb3

PE Executable
MD5: 385fcdf7cd2882b5b756f474b432bcb3
Size: 943.62 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 385fcdf7cd2882b5b756f474b432bcb3
Sha1 7f97ef5f761cc49f91c421d3d193501edbe183ab
Sha256 633cc0eaef33e5697b24e6b25242c9669bec7c01684f2dbddb181e049bf8e800
Sha384 fab01d91fc829c48bcce4f0baad14ee9341826ba813471352f28b6a34ee6e8d3f631c88f55feb7dbdfdab6b463fd8f74
Sha512 91f589f86376702b1fca5fe0287f92ec2c5107114f9538ae026f5cdcc21029924b4f7e0df907980aaa6e323eb42f5ab339b5c754e94840c8fd090aa01905ba45
SSDeep 12288:qGsVnDt//LyTzj7PgARnYBwmabXd5wWdTVDX7MWnrtDWVliPXW5SOuO8GBVByrc0:m/GHjTgAuwJJ5wkLQkRfW5SOuuCL
TLSH E215DE782248CA37C86E1AB0C95BD3F8DA671F99E910DF07AAD5FDCBB136B404517602
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Icehouse.FormRaportti.resources
$this.Icon
[NBF]root.IconData
Icehouse.Properties.Resources.resources
JrKm
[NBF]root.Data
[NBF]root.Data-preview.png
WTT
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Module Name
GPxk.exe
Full Name
GPxk.exe
EntryPoint
System.Void Icehouse.Program::Main()
Scope Name
GPxk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
GPxk
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Info
PE Detect: PeReader OK (file layout)
Total Strings
489
Main Method
System.Void Icehouse.Program::Main()
Main IL Instruction Count
11
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
ldsfld System.Data.DataSet Icehouse.Program::JaaHuoneDataSet
newobj System.Void Icehouse.FormJaaHuone::.ctor(System.Data.DataSet)
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Icehouse.FormRaportti.resources
$this.Icon
[NBF]root.IconData
Icehouse.Properties.Resources.resources
JrKm
[NBF]root.Data
[NBF]root.Data-preview.png
WTT
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙