Suspicious
Suspect

72af7c0cc99f80886919bacedcc8dcbe

Share on LinkedIn
Print
PE Executable
MD5: 72af7c0cc99f80886919bacedcc8dcbe
Size: 1.03 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 72af7c0cc99f80886919bacedcc8dcbe
Sha1 5273bb84ffac947b7afe801d02624c0abdde5ba4
Sha256 95b393d7cafa87c480b7e773dc39e7d43fc1c19e1145d1a37314c2b64c5fe19f
Sha384 64a23cf0b87be2262c847bf60b37b9ec7d51ab9a2f89c2457bd102f0f1fd6ab72dac24969d21bcaf84b9cb25e27e7f56
Sha512 28cba4775755499abbcc6f2646c9e71c7238d7e98371d0d6c51e2d81790965f80137d93a5f4ee444e78542129d4701eba81932c7dcf5ddd9bfc28bb48f09fca5
SSDeep 12288:NBGuspe1/TQ2fzArCm1k6hNTWTSFV6thavkuSCoGU3Mz4GyaEdq0SnuCAr01LpFd:9s12Euim5mLSYrEd1SnzS0fF4uRsm
TLSH 5C251258279DCE12E8F547B20876D37043B1DCCEA419D316CFEDADE73A20B0929686D6
.Net Resources
PuddleSkipper.Properties.Resources.resources
TBUY
[NBF]root.Data
[NBF]root.Data-preview.png
UDP
[NBF]root.Data
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Module Name
sgan.exe
Full Name
sgan.exe
EntryPoint
System.Void PuddleSkipper.Program::Main()
Scope Name
sgan.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
sgan
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
286
Main Method
System.Void PuddleSkipper.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PuddleSkipper.FormSpiel::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Info
PE Detect: PeReader OK (file layout)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙