Suspicious
Suspect

7cb87b9393ec944bd308e5741fc4f519

Share on LinkedIn
Print
PE Executable
MD5: 7cb87b9393ec944bd308e5741fc4f519
Size: 1.65 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 7cb87b9393ec944bd308e5741fc4f519
Sha1 5229d2bff61aa92c25613e8ae1092ecdbd4178e3
Sha256 39bfe085d93390858b9432749a79bac20dd2cae70e3caa2b3aac88edee48151e
Sha384 78fde573413ebceac35868adaae8c71075b9d09d78c6b838f6996dbeea0bb86b5f71b8e7e2b085388196960226f0f757
Sha512 0f92021043853d4c8e527e75a2cd98931323fabc813505726004569aa3726239371f70e063ce48059fd4be6cbcfd09aa5f774393bb248ee7a9dbeec2c66e2d19
SSDeep 49152:k2iQKAgmT2Iasr+OrelMw6+/yEZPdMRem2wq:k2d16Iall3RdMRv2wq
TLSH 257512255A6CDA12C56603F41A71F2B517B41DAEE522C30A9EF7BDEB3420F167C09393
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FrostBreath.Properties.Resources.resources
EuJn
[NBF]root.Data
[NBF]root.Data-preview.png
VIN
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
iLVO.exe
Full Name
iLVO.exe
EntryPoint
System.Void FrostBreath.Program::Main()
Scope Name
iLVO.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
iLVO
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
369
Main Method
System.Void FrostBreath.Program::Main()
Main IL Instruction Count
18
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void FrostBreath.GameForm::.ctor()
stsfld FrostBreath.GameForm FrostBreath.Program::GameFormInstance
newobj System.Void FrostBreath.PuzzleForm::.ctor()
stsfld FrostBreath.PuzzleForm FrostBreath.Program::PuzzleFormInstance
newobj System.Void FrostBreath.TimerForm::.ctor()
stsfld FrostBreath.TimerForm FrostBreath.Program::TimerFormInstance
newobj System.Void FrostBreath.ScoreForm::.ctor()
stsfld FrostBreath.ScoreForm FrostBreath.Program::ScoreFormInstance
ldsfld FrostBreath.GameForm FrostBreath.Program::GameFormInstance
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙