Suspicious
Suspect

84d2ee9147402c4f85dbadde518f2872

Share on LinkedIn
Print
PE Executable
MD5: 84d2ee9147402c4f85dbadde518f2872
Size: 1.19 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 84d2ee9147402c4f85dbadde518f2872
Sha1 20d813990f0e3ec8b319fa2fbbf6e1c87de8aecd
Sha256 b974f6e408fee02342f4cc5fbc1580da54c4fbbdb3c7541f8cd0cc7aeb097df7
Sha384 30406a15e913b729e2f1dedbc8d4a46ff11c03d958c048d03496b59d52c3efae09548adc662cb26a811aaacfd11b747d
Sha512 aad2be8f4c6d1b3636f166bdc92042bde8e4c0336d83264507c460432f38e06e1a5ebb56949b13d543b9c946e3051f007a782afb84a739d40a82ac91464898c0
SSDeep 24576:B6q7vLr9CBLbpXuoHk4m/1CjP8ouQNROd3oJfnhDBE/1tVYIDg7v:B6q7jr9OpeoE4m4j4qROd3oJZtwE7
TLSH 1C4522AC169FCCB2DAFA2BB895A0D57303786E5D1902D30B9EEDBCF7780339A1545250
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
FormComboListBox.Form1.resources
$this.Icon
cls
StIvesLib.Properties.Resources.resources
zmxf
Name Value
Module Name
KoFy.exe
Full Name
KoFy.exe
EntryPoint
System.Void StIvesLib.main::Main()
Scope Name
KoFy.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KoFy
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
107
Main Method
System.Void StIvesLib.main::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void FormComboListBox.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
KoFy.exe
Full Name
KoFy.exe
EntryPoint
System.Void StIvesLib.main::Main()
Scope Name
KoFy.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KoFy
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
107
Main Method
System.Void StIvesLib.main::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void FormComboListBox.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙