Suspicious
Suspect

7d416b5043b39130e356bd387d565f99

PE Executable
MD5: 7d416b5043b39130e356bd387d565f99
Size: 742.91 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 7d416b5043b39130e356bd387d565f99
Sha1 ed586a7f9974e52935be05d9b7868f481ad3031b
Sha256 c1e2ba7b65d7e8611f83d0ffbef4412083bcbdb8d26a496d82c98c635f64fddd
Sha384 4a0ae94cf13a07f9711a3c2948b0c70157a04b13c00b90e610ab97e9566dd5033c3b6a1857cf36912c5d9a078e144840
Sha512 5ee4a89dc87d734261de27223be4593c109e1abb0778472a0413e61f5395f7265a429e9d8270a6f0421dc7eae365ee80b202792ffc3deb2c5d7198b26a0645ad
SSDeep 12288:x0JHDqqipd07QkZ+FTyFL8O+2ucz1EeObI18Qs7Tizk1Pc6zdpW:x0FGVpadZgOFL8O+23z1HJ8QacepW
TLSH 60F4121633695F86F47F97F82BA0654203F2E2677B20E65D5DC422FB16B2B414A30E93
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AirPortStand.ApronForm.resources
AirPortStand.Properties.Resources.resources
TkFn
[NBF]root.Data
[NBF]root.Data-preview.png
abigail
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
XNHj.exe
Full Name
XNHj.exe
EntryPoint
System.Void AirPortStand.Program::Main()
Scope Name
XNHj.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XNHj
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
485
Main Method
System.Void AirPortStand.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AirPortStand.ApronForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AirPortStand.ApronForm.resources
AirPortStand.Properties.Resources.resources
TkFn
[NBF]root.Data
[NBF]root.Data-preview.png
abigail
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙