Suspicious
Suspect

96dda1ac2129f9283c23a07b47a4d05b

PE Executable
MD5: 96dda1ac2129f9283c23a07b47a4d05b
Size: 1.08 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 96dda1ac2129f9283c23a07b47a4d05b
Sha1 10c11fc4079a4619d79f4007535c2828955dd66c
Sha256 a5350fb5b4e5a8dce705883533f71826d48cd3001cc423de68ad8e071f5a88ce
Sha384 de3851b7598eda2602ad31773b382412fb40e857b0d0d014c404d9f2a803b0fa28acf21e8aa623b8ae90f0b730aa9b35
Sha512 8c659c9322cdc1f437ec9fd6df0f868917543e17f6d3f1521c40443f751ece784fb742d7f483d047234a08518808b2f636174bb93ce08a34a01ec52a3d25a46d
SSDeep 24576:WwfiZ1/uRwOrjuutTOjBDqv61yyhg9/VhkelMcGJ:Wwqnmr3uIOjVqvj9/VhWcW
TLSH 48350134AA58DE02C46617F04536FBB617746C7DE620D3468EEABDEB7825F462C08393
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FrostBreath.Properties.Resources.resources
VIN
[NBF]root.Data
XtVp
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
ufXR.exe
Full Name
ufXR.exe
EntryPoint
System.Void FrostBreath.Program::Main()
Scope Name
ufXR.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ufXR
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
369
Main Method
System.Void FrostBreath.Program::Main()
Main IL Instruction Count
18
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void FrostBreath.GameForm::.ctor()
stsfld FrostBreath.GameForm FrostBreath.Program::GameFormInstance
newobj System.Void FrostBreath.PuzzleForm::.ctor()
stsfld FrostBreath.PuzzleForm FrostBreath.Program::PuzzleFormInstance
newobj System.Void FrostBreath.TimerForm::.ctor()
stsfld FrostBreath.TimerForm FrostBreath.Program::TimerFormInstance
newobj System.Void FrostBreath.ScoreForm::.ctor()
stsfld FrostBreath.ScoreForm FrostBreath.Program::ScoreFormInstance
ldsfld FrostBreath.GameForm FrostBreath.Program::GameFormInstance
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FrostBreath.Properties.Resources.resources
VIN
[NBF]root.Data
XtVp
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙