Suspicious
Suspect

6cb55456e3e5c099a85a7314076bb741

PE Executable
MD5: 6cb55456e3e5c099a85a7314076bb741
Size: 1.15 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 6cb55456e3e5c099a85a7314076bb741
Sha1 1f9fc655026196029f316ccec34b19f63ffdd391
Sha256 4f0925945aedb397ad3cbdd0e9b9a3ebf96d64c242699a971c2c016636383569
Sha384 b804f47a821cb4593ca75e3ae913f429d9644b907de36688bd4b750f9193bbae0c6fda4ff5632d873995824ca485fc41
Sha512 76548235d3684f2ed7618ed32e418fcf243a6c88dc80a6087bfe6071a7b7ad36ab8c9d199c65d99ac87574374902c940e00826ee4f818a71ae4f28736b136a4b
SSDeep 24576:9a6Uw1oHMCvI5DHl2vd47GgEcnvUf2b0P9+yAxfl:9a69Efg9wSGgrvUebAM
TLSH 5135021426DEDA02E5B20FF91872D2741B373E896931E20A4EED2DDF7B3BB115810792
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GargoyleSculptor.Properties.Resources.resources
Feep
[NBF]root.Data
zDIP
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
KrmH.exe
Full Name
KrmH.exe
EntryPoint
System.Void GargoyleSculptor.Program::Main()
Scope Name
KrmH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KrmH
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
469
Main Method
System.Void GargoyleSculptor.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void GargoyleSculptor.Program::InitializeData()
nop <null>
newobj System.Void GargoyleSculptor.StudioForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GargoyleSculptor.Properties.Resources.resources
Feep
[NBF]root.Data
zDIP
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙