Suspicious
Suspect

7c84081b3d55fd6c8497b5f980c65909

PE Executable
MD5: 7c84081b3d55fd6c8497b5f980c65909
Size: 900.1 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 7c84081b3d55fd6c8497b5f980c65909
Sha1 340aaef808241e106812eaa007ca5719310e467b
Sha256 a283f8fa8b08688bac38396e9b59aacf89037577177611df9891c58a0739d4a9
Sha384 d5076ff8d184306b3cf761be60ec3fa361d99d65c7a5852bfb32d8c94632586c5b93a35f1c235694f4a95e8d49d01315
Sha512 20181dd5f1d2771e5199d77eede1258835ef7626258ec844a8638676e57e030032c0390674b7cca73af7112300ec1b2d1be036a2aa67212d3da4d151368e989e
SSDeep 24576:0XLXQM6RJeweGN3Tw+6sD5wTUm3pcY0e8eQFJo+:iLXfwowwpsDmX9l8eu
TLSH 2C1512797364FA19DA7E47F50E76E63A17B66E4EB411D31A8DE88DEB3E247042C00603
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PonsFuniculus.Properties.Resources.resources
AOLi
[NBF]root.Data
[NBF]root.Data-preview.png
Apollo
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
PuAA.exe
Full Name
PuAA.exe
EntryPoint
System.Void PonsFuniculus.Program::Main()
Scope Name
PuAA.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PuAA
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
338
Main Method
System.Void PonsFuniculus.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PonsFuniculus.HiatusForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PonsFuniculus.Properties.Resources.resources
AOLi
[NBF]root.Data
[NBF]root.Data-preview.png
Apollo
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙