Suspicious
Suspect

6e5585270e20bf3421497993c28e016d

PE Executable
MD5: 6e5585270e20bf3421497993c28e016d
Size: 1.08 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 6e5585270e20bf3421497993c28e016d
Sha1 c977bcc05a6bc95f37bbe978331f5f8e95b51546
Sha256 320a63cee8599bbc338ea723cca731a411e34b4a3d6d90ad25a7266f0db75c38
Sha384 31a6e6ba1f694e5baa5af3b100addfa6cfb2d5b23d304e8bb1e50bf79d4cb32e80c1fc5f6f7781d0cd4af139dd204e01
Sha512 28e1bd078d66e63db6febfab92c07be8aa929c7a67ab4e48db6f4de350e2eaf33a13b0aca8eaae4e12a9d2e3a925004657d9ab9c6dbced253989f0fe005ab917
SSDeep 24576:BD5mIiJR+zaVhikRack0U4ldhEOfToo80CIFwfiZ:wR+zaHiH3uKKdCCwq
TLSH 89350228AA6DDF02C49557F00676F6B607782DADE520D3479EF5FDEB3825F492808283
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FrostBreath.Properties.Resources.resources
TYPr
[NBF]root.Data
[NBF]root.Data-preview.png
VIN
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
ALic.exe
Full Name
ALic.exe
EntryPoint
System.Void FrostBreath.Program::Main()
Scope Name
ALic.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ALic
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
369
Main Method
System.Void FrostBreath.Program::Main()
Main IL Instruction Count
18
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void FrostBreath.GameForm::.ctor()
stsfld FrostBreath.GameForm FrostBreath.Program::GameFormInstance
newobj System.Void FrostBreath.PuzzleForm::.ctor()
stsfld FrostBreath.PuzzleForm FrostBreath.Program::PuzzleFormInstance
newobj System.Void FrostBreath.TimerForm::.ctor()
stsfld FrostBreath.TimerForm FrostBreath.Program::TimerFormInstance
newobj System.Void FrostBreath.ScoreForm::.ctor()
stsfld FrostBreath.ScoreForm FrostBreath.Program::ScoreFormInstance
ldsfld FrostBreath.GameForm FrostBreath.Program::GameFormInstance
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FrostBreath.Properties.Resources.resources
TYPr
[NBF]root.Data
[NBF]root.Data-preview.png
VIN
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙