Suspicious
Suspect

6e5585270e20bf3421497993c28e016d

Share on LinkedIn
Print
PE Executable
MD5: 6e5585270e20bf3421497993c28e016d
Size: 1.08 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 6e5585270e20bf3421497993c28e016d
Sha1 c977bcc05a6bc95f37bbe978331f5f8e95b51546
Sha256 320a63cee8599bbc338ea723cca731a411e34b4a3d6d90ad25a7266f0db75c38
Sha384 31a6e6ba1f694e5baa5af3b100addfa6cfb2d5b23d304e8bb1e50bf79d4cb32e80c1fc5f6f7781d0cd4af139dd204e01
Sha512 28e1bd078d66e63db6febfab92c07be8aa929c7a67ab4e48db6f4de350e2eaf33a13b0aca8eaae4e12a9d2e3a925004657d9ab9c6dbced253989f0fe005ab917
SSDeep 24576:BD5mIiJR+zaVhikRack0U4ldhEOfToo80CIFwfiZ:wR+zaHiH3uKKdCCwq
TLSH 89350228AA6DDF02C49557F00676F6B607782DADE520D3479EF5FDEB3825F492808283
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FrostBreath.Properties.Resources.resources
TYPr
[NBF]root.Data
[NBF]root.Data-preview.png
VIN
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
ALic.exe
Full Name
ALic.exe
EntryPoint
System.Void FrostBreath.Program::Main()
Scope Name
ALic.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ALic
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
369
Main Method
System.Void FrostBreath.Program::Main()
Main IL Instruction Count
18
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void FrostBreath.GameForm::.ctor()
stsfld FrostBreath.GameForm FrostBreath.Program::GameFormInstance
newobj System.Void FrostBreath.PuzzleForm::.ctor()
stsfld FrostBreath.PuzzleForm FrostBreath.Program::PuzzleFormInstance
newobj System.Void FrostBreath.TimerForm::.ctor()
stsfld FrostBreath.TimerForm FrostBreath.Program::TimerFormInstance
newobj System.Void FrostBreath.ScoreForm::.ctor()
stsfld FrostBreath.ScoreForm FrostBreath.Program::ScoreFormInstance
ldsfld FrostBreath.GameForm FrostBreath.Program::GameFormInstance
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙