Suspicious
Suspect

6359a5acabcdabe63e38bc1c47f32690

PE Executable
MD5: 6359a5acabcdabe63e38bc1c47f32690
Size: 1.61 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 6359a5acabcdabe63e38bc1c47f32690
Sha1 546431ea87ed5d55a437b5d1732a0b110ce6ade5
Sha256 fc6a7e49e66a4878755d3ef0c95236e3443c8a2bfe10a634d03660f543c3a038
Sha384 ec11d5820a14b563bd7c4b48404ff36d100a87e454184c39a9031186e22dfc475c8bfc5f4ec9cccee758ef7ba56e1246
Sha512 2f5d6948a7132e1c15a48216927d21c7c463546544339ad2017c06519bc67ddcf54440a4fd40cd9c844da917e5cc7ee9967108f395ba6ee2c595bd61ca0ebd3f
SSDeep 49152:mwIkI+gC8wdFqu0vXJdBZGXuMH5e2pXK:mPkdrbqzvXzBIXv
TLSH 9E752399524BE603CA4913324EE1F67423B94ED96053C25B7FEC3EAFBD32B555E04282
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
sKOy.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
StockTicker.Properties.Resources.resources
Fec
[NBF]root.Data
iqlx
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
sKOy.exe
Full Name
sKOy.exe
EntryPoint
System.Void Ffn.gf2::kf5()
Scope Name
sKOy.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
sKOy
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
149
Main Method
System.Void Ffn.gf2::kf5()
Main IL Instruction Count
16
Main IL
br IL_0007: nop
nop <null>
ret <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_002C: nop
call System.Void QfZ.IfO::oTq()
br IL_001C: nop
nop <null>
newobj System.Void Ki.S5::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0005: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0012: call System.Void QfZ.IfO::oTq()
Module Name
sKOy.exe
Full Name
sKOy.exe
EntryPoint
System.Void Ffn.gf2::kf5()
Scope Name
sKOy.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
sKOy
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
149
Main Method
System.Void Ffn.gf2::kf5()
Main IL Instruction Count
16
Main IL
br IL_0007: nop
nop <null>
ret <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_002C: nop
call System.Void QfZ.IfO::oTq()
br IL_001C: nop
nop <null>
newobj System.Void Ki.S5::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0005: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0012: call System.Void QfZ.IfO::oTq()
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
sKOy.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
StockTicker.Properties.Resources.resources
Fec
[NBF]root.Data
iqlx
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙