Suspicious
Suspect

7cb87b9393ec944bd308e5741fc4f519

PE Executable
MD5: 7cb87b9393ec944bd308e5741fc4f519
Size: 1.65 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 7cb87b9393ec944bd308e5741fc4f519
Sha1 5229d2bff61aa92c25613e8ae1092ecdbd4178e3
Sha256 39bfe085d93390858b9432749a79bac20dd2cae70e3caa2b3aac88edee48151e
Sha384 78fde573413ebceac35868adaae8c71075b9d09d78c6b838f6996dbeea0bb86b5f71b8e7e2b085388196960226f0f757
Sha512 0f92021043853d4c8e527e75a2cd98931323fabc813505726004569aa3726239371f70e063ce48059fd4be6cbcfd09aa5f774393bb248ee7a9dbeec2c66e2d19
SSDeep 49152:k2iQKAgmT2Iasr+OrelMw6+/yEZPdMRem2wq:k2d16Iall3RdMRv2wq
TLSH 257512255A6CDA12C56603F41A71F2B517B41DAEE522C30A9EF7BDEB3420F167C09393
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FrostBreath.Properties.Resources.resources
EuJn
[NBF]root.Data
[NBF]root.Data-preview.png
VIN
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
iLVO.exe
Full Name
iLVO.exe
EntryPoint
System.Void FrostBreath.Program::Main()
Scope Name
iLVO.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
iLVO
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
369
Main Method
System.Void FrostBreath.Program::Main()
Main IL Instruction Count
18
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void FrostBreath.GameForm::.ctor()
stsfld FrostBreath.GameForm FrostBreath.Program::GameFormInstance
newobj System.Void FrostBreath.PuzzleForm::.ctor()
stsfld FrostBreath.PuzzleForm FrostBreath.Program::PuzzleFormInstance
newobj System.Void FrostBreath.TimerForm::.ctor()
stsfld FrostBreath.TimerForm FrostBreath.Program::TimerFormInstance
newobj System.Void FrostBreath.ScoreForm::.ctor()
stsfld FrostBreath.ScoreForm FrostBreath.Program::ScoreFormInstance
ldsfld FrostBreath.GameForm FrostBreath.Program::GameFormInstance
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FrostBreath.Properties.Resources.resources
EuJn
[NBF]root.Data
[NBF]root.Data-preview.png
VIN
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙