Suspicious
Suspect

7dbf1dd9fa7ca2165077c1289ba0acf9

PE Executable
MD5: 7dbf1dd9fa7ca2165077c1289ba0acf9
Size: 3.15 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 7dbf1dd9fa7ca2165077c1289ba0acf9
Sha1 724cf38a0d0ae333834841937ac646306fbd09b2
Sha256 5679dcddde61ea4ea8ee5199339ba059940b1257211fcf95c80d1d5b4063e85a
Sha384 6c79141c63c088c35a8f17e4f779f1e117fd77bea612573ef51e4e73582405c833786e073741c3c0e484ce749b603b1d
Sha512 e3db572052f17c61795e361970de6918708c387e0975aa42c8ca21f45cfa81339c90ceca4192f592f25e1d344ec018593400da4222d050ea8e996fd503f198bb
SSDeep 49152:bOPxMJrnMoYj1662IGEmNa3nXuigV3tBPXep:aPSBnKj166PFmNanIVPXe
TLSH 17E523E8E39DCF1AC7954FB00555D27523F02D8AD410D7029EEAACDFB426F2191983A7
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Overlay_4f137f45.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HeartbeatMonitor.Properties.Resources.resources
DR
[NBF]root.Data
RDxf
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_4f137f45.bin (1577984 bytes)
Info
PDB Path: ?
Module Name
Fhmo.exe
Full Name
Fhmo.exe
EntryPoint
System.Void HeartbeatMonitor.Program::Main()
Scope Name
Fhmo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Fhmo
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
200
Main Method
System.Void HeartbeatMonitor.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HeartbeatMonitor.SrtiMonitorForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Overlay_4f137f45.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HeartbeatMonitor.Properties.Resources.resources
DR
[NBF]root.Data
RDxf
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙