Suspicious
Suspect

8af53c73b486d2017e50379c952d2a88

PE Executable
MD5: 8af53c73b486d2017e50379c952d2a88
Size: 3.25 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 8af53c73b486d2017e50379c952d2a88
Sha1 3c9828ab7e7a8050dab5e76a5578cffe5caa2cc4
Sha256 fa255bb8ed5c97597ba1ebeac61679e837bca83d8ced48293ea9c2f497aae66f
Sha384 08f87ee40f614678bb09d1fd17784f301850d759ec06a795f103afd60434d1db2f6b394ccbc6bdf08b2a0f6d6b9a3990
Sha512 cbfd679fc19ade1651199d76467c64237b87066b6334e7371fea1caa883aba45d1e19600683fb9f205224170bc0ce7485c09330df89328934d4cc0e3da0aec6b
SSDeep 49152:v115IJ4M5AcHG9dJRYkZrT2tbifmc0YWmwKC09BWSeOGrIC+gmZdCGQ1zXa8g20:biJECkJT2tbPc0VKC09BWZFrCgmO1zJ
TLSH B8E533944106C610FAFB5BB34A57F332B374FE6AA140E2129FF96CEF32256184906F56
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
.Net Resources
TermiteMound.Properties.Resources.resources
Cringe
[NBF]root.Data
HClY
[NBF]root.Data
[NBF]root.Data-preview.png
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Module Name
KXaK.exe
Full Name
KXaK.exe
EntryPoint
System.Void TermiteMound.Program::Main()
Scope Name
KXaK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KXaK
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
419
Main Method
System.Void TermiteMound.Program::Main()
Main IL Instruction Count
60
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void System.Random::.ctor()
stloc.0 <null>
ldc.i4.0 <null>
stloc.1 <null>
br.s IL_007C: ldloc.1
nop <null>
ldsfld System.Single[] TermiteMound.Program::robitnykyX
ldloc.1 <null>
ldloc.0 <null>
ldc.i4.s 50
ldc.i4 250
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
conv.r4 <null>
stelem.r4 <null>
ldsfld System.Single[] TermiteMound.Program::robitnykyY
ldloc.1 <null>
ldloc.0 <null>
ldc.i4 150
ldc.i4 350
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
conv.r4 <null>
stelem.r4 <null>
ldsfld System.Single[] TermiteMound.Program::robitnykySpeed
ldloc.1 <null>
ldloc.0 <null>
callvirt System.Double System.Random::NextDouble()
ldc.r8 3
mul <null>
ldc.r8 1
add <null>
conv.r4 <null>
stelem.r4 <null>
ldsfld System.Int32[] TermiteMound.Program::robitnykyTunnel
ldloc.1 <null>
ldloc.0 <null>
ldc.i4.0 <null>
ldc.i4.4 <null>
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
stelem.i4 <null>
nop <null>
ldloc.1 <null>
ldc.i4.1 <null>
add <null>
stloc.1 <null>
ldloc.1 <null>
ldc.i4.s 25
clt <null>
stloc.2 <null>
ldloc.2 <null>
brtrue.s IL_0018: nop
newobj System.Void TermiteMound.KupynaForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Info
PE Detect: PeReader OK (file layout)
.Net Resources
TermiteMound.Properties.Resources.resources
Cringe
[NBF]root.Data
HClY
[NBF]root.Data
[NBF]root.Data-preview.png
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙