Suspicious
Suspect

5fc5efdc9381ff79e596c22508e6ecfb

Share on LinkedIn
Print
PE Executable
MD5: 5fc5efdc9381ff79e596c22508e6ecfb
Size: 847.87 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 5fc5efdc9381ff79e596c22508e6ecfb
Sha1 9ecf0e9bcca1f0c60b2b43140e6b932b45d5f973
Sha256 61539d1e98768dcb4843cb39e0c40625c015d8a2fce217beffe369349b6b8f1d
Sha384 79cf7f909315c66d4957515ff603562607483faa30b67bc11133829575ecfb88efa8c2581fc5371dac02578fa2f660b4
Sha512 2df981259bd8c10304ed75d627483d17421f411f6e5b5d7a5a293412927fc4f1c3212de71e528aa26bd79fac563fad42d70360513f0bb0e3233a57d5aee06a1f
SSDeep 12288:cQdHMdqwcMlt+Th8QTXX9eOzfHavAa7IwdbyTNjWHNll8VUZhJsRd6kj1vMRi:XMA6tj8X9eObAA+9yBjWvOKZQRIs2
TLSH 3B050211275ACA46E8A50BB809B1D3B507A54E8EFA11C35BCEFCBDDB347A7523D04782
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Day4_Task1.RowExhaustedSignal.resources
$this.Icon
[NBF]root.IconData
notifyIcon1.TrayLocation
pageSetupDialog1.TrayLocation
printDialog1.TrayLocation
printDocument1.TrayLocation
printPreviewDialog1.Icon
[NBF]root.IconData
printPreviewDialog1.TrayLocation
Day4_Task1.Form2.resources
Day4_Task1.Properties.Resources.resources
critsh
[NBF]root.Data
vaSB
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
fFGk.exe
Full Name
fFGk.exe
EntryPoint
System.Void Day4_Task1.Program::Main()
Scope Name
fFGk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
fFGk
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\GfsibwNROH\src\obj\Debug\fFGk.pdb
Target Framework
.NETFramework,Version=v4.8
Total Strings
229
Main Method
System.Void Day4_Task1.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Day4_Task1.Form2::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙