Suspicious
Suspect

893341936cf9c01e93d422c6f2145711

PE Executable
MD5: 893341936cf9c01e93d422c6f2145711
Size: 1.63 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 893341936cf9c01e93d422c6f2145711
Sha1 6327b718f3c8aefd85f04795131d5f2c550e1189
Sha256 7f4206422bf5259a304fd5fe7fe8ea0d09292faf3d9a73cc83a70c87c6d2e3ea
Sha384 4f75176b6dddeb1abfc8dcca3275a806983765ddfa57a7f7db88fe6a50409f8e909600d4f2a8a0e321ac1158b8e231c6
Sha512 c886ec58ba189c78b79ed953a6bf2a89ca787238ba7c6223e9f8a5b42da8268c4a16ea3bbbd401a12fa280eec3655325594572f3992ed7ca711450908f016562
SSDeep 49152:X0tR6/CHcg0YmLzjjZWfFIRlVTgfdmx5mRWGiVGwq:E2E0YmUfF2bTgVG5OWGVwq
TLSH 967512396A69CE02C8D953B10977E77923795DACD520C3065FF9FDE73426B0A3C082A6
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmokeRace.Properties.Resources.resources
LLpe
[NBF]root.Data
[NBF]root.Data-preview.png
VIN
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
YrpY.exe
Full Name
YrpY.exe
EntryPoint
System.Void SmokeRace.Program::Main()
Scope Name
YrpY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YrpY
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
351
Main Method
System.Void SmokeRace.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SmokeRace.FormSpiel::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
YrpY.exe
Full Name
YrpY.exe
EntryPoint
System.Void SmokeRace.Program::Main()
Scope Name
YrpY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YrpY
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
351
Main Method
System.Void SmokeRace.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SmokeRace.FormSpiel::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmokeRace.Properties.Resources.resources
LLpe
[NBF]root.Data
[NBF]root.Data-preview.png
VIN
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙