Suspicious
Suspect

7b7cd85a2c2ec3b1433f5fe51ba5204e

PE Executable
MD5: 7b7cd85a2c2ec3b1433f5fe51ba5204e
Size: 774.14 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 7b7cd85a2c2ec3b1433f5fe51ba5204e
Sha1 b08580c9bf8cf84ab8b97d785365a2711542bd41
Sha256 d1303941d2d3f6d1337f74fb0ec07984614d4bad8bb76143fe89a285b9dbeaaf
Sha384 e648ae6d4321b3cb3a0efcaa25b2416365a3e95996c26b263fda3afaef11c8eaa80fe30fab695c9363536ec265b1c03a
Sha512 66d88d7deaf7d57c6c6274ba6d9413849430e6afee62f8c8554e232b24f63f115ba4f956a0d511a617a294f6610f67b98179107374d88ad92cb8b8270a5fcc89
SSDeep 12288:/MQGLFTWHsvm2KnU7S4wUR2Nkpuw7yTcHFN4CmaZezhSTP2lQth9+kkPaXo+0Hj:joKHsu9U7S4wUR2NkEasoFG3aAzIT9hT
TLSH 7FF41262B325FA56DA7E1BF64A75E33207B60E4EA525D306CEEDADCB3C147106C05283
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PonsFuniculus.Properties.Resources.resources
AmtS
[NBF]root.Data
[NBF]root.Data-preview.png
Apollo
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
iupe.exe
Full Name
iupe.exe
EntryPoint
System.Void PonsFuniculus.Program::Main()
Scope Name
iupe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
iupe
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
338
Main Method
System.Void PonsFuniculus.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PonsFuniculus.HiatusForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PonsFuniculus.Properties.Resources.resources
AmtS
[NBF]root.Data
[NBF]root.Data-preview.png
Apollo
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙