Suspicious
Suspect

529425a9f2f8c7f6868fade6c5a219ab

PE Executable
MD5: 529425a9f2f8c7f6868fade6c5a219ab
Size: 5.65 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 529425a9f2f8c7f6868fade6c5a219ab
Sha1 a7b401ac4a412c301633b5df840248555a0773e5
Sha256 6693905d48210f94fd4ebc2e08686739f6978e94c78b45db8f4cd24d591aaca0
Sha384 ba4adee612f48b73f3b8320fe341ebc24a9649c3a984ecca1463e307ed641f7db9e1953e415c482abf254792e3ffa2f5
Sha512 c179d6f9775a0250b444e671c807ea67f249fabb432e665f6c6937ae5a491aa5faa5e96b646a6d7b767fb34c18142b4f43ced8b915228c32bbb4d5a16735f5a5
SSDeep 98304:Chva0Bk2vwvsE1njvpy1tvzkABVEVMmPL/IEvgncAv0ULLv4V3vSdCNSSFVOWVjv:Chva0Bk2vwvsE1njvpy1tvzkuVEVMmPF
TLSH 8146DB03BA449B05C97C353A82FB2D2D63A1F6CB1771991FDF017A671CD62A69CCC24A
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_e520f675.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
TyfoonWinControls.FrmBOExplorer.resources
TyfoonWinShape1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
imageList.ImageStream
[NBF]root.Data
TyfoonWinControls.FrmBrokenRulesExplorer.resources
TyfoonWinShape1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
TyfoonWinControls.FrmGridConfig.resources
TyfoonWinShape1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
TyfoonWinControls.FrmSearchItem.resources
$this.Icon
[NBF]root.IconData
TyfoonWinShape1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
TyfoonWinControls.FrmTyfoon.resources
TyfoonWinControls.TyfoonWinSearchTextbox.resources
buttSearch.Image
TyfoonWinControls.dll.licenses
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Module Name
TyfoonWinControls.dll
Full Name
TyfoonWinControls.dll
Scope Name
TyfoonWinControls.dll
Scope Type
ModuleDef
Kind
Dll
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TyfoonWinControls
Assembly Version
2017.0.0.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x560A00 size 11136 bytes
Total Strings
0
Main Method
Not found or no body
Module Name
TyfoonWinControls.dll
Full Name
TyfoonWinControls.dll
Scope Name
TyfoonWinControls.dll
Scope Type
ModuleDef
Kind
Dll
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TyfoonWinControls
Assembly Version
2017.0.0.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
0
Main Method
Not found or no body
[Authenticode]_e520f675.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
TyfoonWinControls.FrmBOExplorer.resources
TyfoonWinShape1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
imageList.ImageStream
[NBF]root.Data
TyfoonWinControls.FrmBrokenRulesExplorer.resources
TyfoonWinShape1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
TyfoonWinControls.FrmGridConfig.resources
TyfoonWinShape1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
TyfoonWinControls.FrmSearchItem.resources
$this.Icon
[NBF]root.IconData
TyfoonWinShape1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
TyfoonWinControls.FrmTyfoon.resources
TyfoonWinControls.TyfoonWinSearchTextbox.resources
buttSearch.Image
TyfoonWinControls.dll.licenses
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙