Suspicious
Suspect

71527a93de96710a1c83c3083189e323

PE Executable
MD5: 71527a93de96710a1c83c3083189e323
Size: 1.44 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 71527a93de96710a1c83c3083189e323
Sha1 ce60ffc172f18ba31d8384ebff0b843ae2f82fe4
Sha256 018cff3b8d3d9ecd0cdff35222c83d0859933652f5b368246a8641d96fa7154c
Sha384 eb921ad4ace70e594213849e4a00bdd6ac9ed8d71c39acb0acb10799f1100cae5fead72c9d9cf03b85e36af3ae5ce509
Sha512 38efdaf98093a4019faa3893c35bc1120fed88569a9b4282fe641bb1f3e221e466c7ca3b9feb6f128a57819f74984495ae201edc61a63bda801db3b657478643
SSDeep 24576:DW+YQDVIWZUdrjJX13CYgsKg/ZT9x/EUwKRiCa8WaL3qpkzVbUE:iVGIWZQt13u7gV9xplRiCaFabpVo
TLSH 3B65238193D98038C6A66B361ED5F27343B6ADB8B532C72A6FECBDDB75353058C01252
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GalacticEmpire4X.MainDashboard.resources
$this.Icon
[NBF]root.IconData
MR5
[NBF]root.Data
GalacticEmpire4X.ColonyManagerDesk.resources
GalacticEmpire4X.Properties.Resources.resources
mUqV
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: bAJO.pdb
Module Name
bAJO.exe
Full Name
bAJO.exe
EntryPoint
System.Void GalacticEmpire4X.Program::Main()
Scope Name
bAJO.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
bAJO
Assembly Version
4.2.6.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
69
Main Method
System.Void GalacticEmpire4X.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void GalacticEmpire4X.MainDashboard::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GalacticEmpire4X.MainDashboard.resources
$this.Icon
[NBF]root.IconData
MR5
[NBF]root.Data
GalacticEmpire4X.ColonyManagerDesk.resources
GalacticEmpire4X.Properties.Resources.resources
mUqV
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙