Suspicious
Suspect

47ed7361739846e6a1881554030fb413

PE Executable
MD5: 47ed7361739846e6a1881554030fb413
Size: 915.46 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 47ed7361739846e6a1881554030fb413
Sha1 c2de661e090d8c8d3ae10ab5d9a91f58eee36ce8
Sha256 26f4fd7217794560c9cf8dae6f9230e35b13f0471bd4d03f3cc372e6a2fd2f40
Sha384 66eeb0ec4453c174f1cefc61982577f9ab99d8ccfd96a4544dda4ebaf499629d0f50d02b6f5918170df1318b5d02c5ac
Sha512 e7a56d0611157a8dea77bb77bc7c2dc71b19ef71679a5881ecefb2f6b325439820230e0e74465f38cb2ffd9ced3a94caa4b83cea449c25db8e8889b5927720c4
SSDeep 24576:87MAbNJYZQQ4PfN+jdwkSK6+iibnndMq:beNJYZQV48Rf+nd
TLSH EC15F11423A8E646DCEA17F40AB5E7390BB53D4EE920D30E8EE5BDEB3422F565844743
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WaterWheel.Vues.FormMoulin.resources
WaterWheel.Properties.Resources.resources
critsh
[NBF]root.Data
zAce
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
OFIz.exe
Full Name
OFIz.exe
EntryPoint
System.Void WaterWheel.Program::Main()
Scope Name
OFIz.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
OFIz
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
456
Main Method
System.Void WaterWheel.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WaterWheel.Vues.FormMoulin::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
OFIz.exe
Full Name
OFIz.exe
EntryPoint
System.Void WaterWheel.Program::Main()
Scope Name
OFIz.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
OFIz
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
456
Main Method
System.Void WaterWheel.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WaterWheel.Vues.FormMoulin::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WaterWheel.Vues.FormMoulin.resources
WaterWheel.Properties.Resources.resources
critsh
[NBF]root.Data
zAce
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙