Suspicious
Suspect

5bf2f638139383e96d6e9ff3655589d8

PE Executable
MD5: 5bf2f638139383e96d6e9ff3655589d8
Size: 1.58 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 5bf2f638139383e96d6e9ff3655589d8
Sha1 ff49232eee6a016dea9d58a38a76e29fa4166fbb
Sha256 1588649aee36e1ce61a00a6288263ba398f4cef6eef974f90f152f28a7a91228
Sha384 6bab0b8d49a805e526746eac0d739ce64f5735984fc081be2b58705c08d35d1bd9fd407633f536abdb7f9b9e22036358
Sha512 9bf1aed1123f5b6053fe7a9198255ea84f06deabfe35b7e4a02c9f50e2002242fdba5ee130262183554e094cbd4957d78f73ee8340a5133dd96309599f1089b0
SSDeep 24576:LGLm5MX+PN6GiXATrDO1jVeGRt2c5SL4Z9NcwOybbauY/l3p6xlInWN6Qhnsm:vN6GiegjVeA84SL4Kby3auYt3QvCAn3
TLSH B6752364235ADD63F9AD57B22536C3B203F46DDE7411D3168BEAAEEB38417186C087C2
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PuddleSkipper.Properties.Resources.resources
BkCp
[NBF]root.Data
[NBF]root.Data-preview.png
UDP
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
NfQq.exe
Full Name
NfQq.exe
EntryPoint
System.Void PuddleSkipper.Program::Main()
Scope Name
NfQq.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
NfQq
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
286
Main Method
System.Void PuddleSkipper.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PuddleSkipper.FormSpiel::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PuddleSkipper.Properties.Resources.resources
BkCp
[NBF]root.Data
[NBF]root.Data-preview.png
UDP
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙