Suspicious
Suspect

6df184262c6d363c71558ca517ca9b59

PE Executable
MD5: 6df184262c6d363c71558ca517ca9b59
Size: 454.66 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 6df184262c6d363c71558ca517ca9b59
Sha1 63aab9fcbf74d7a25fcec136fd06e134b4627d62
Sha256 f5bb2c09472d5b68f7b1bfae1eadfa4391d4524031497161a2483869300ee70e
Sha384 70eae4f7188d04ae67fc17098a331e8d3a33b363b1ed5d54f7ddce9c1de3484c2929259c3339704c0a0de72f296780bc
Sha512 f303acf0dd606e9dab4d0f8e4da7745c540280147fe7f32f1e2e092681ac0e5540018d8cbb7bb3837789048da0f8d9e339fa94bdd7c5000dc16d69bfe485e342
SSDeep 6144:cd+6LOuxlHvYEUqyfAInKzHmBCTdk77CvYDIfXJ287mCPR9w+H6ugLhfuDK:R0OWlfyfAInsBkFIPIImCrPLM1uDK
TLSH 70A401A823ABDA23E9A547F55CE1D3B553782FD9A401C3138ADAFDE738267412C503D2
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ColorSchemeGenerator.ExportForm.resources
ColorSchemeGenerator.Properties.Resources.resources
KS
[NBF]root.Data
veFw
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: iFrA.pdb
Module Name
iFrA.exe
Full Name
iFrA.exe
EntryPoint
System.Void ColorSchemeGenerator.Program::Main()
Scope Name
iFrA.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
iFrA
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
168
Main Method
System.Void ColorSchemeGenerator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ColorSchemeGenerator.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ColorSchemeGenerator.ExportForm.resources
ColorSchemeGenerator.Properties.Resources.resources
KS
[NBF]root.Data
veFw
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙