Suspicious
Suspect

PE Executable
MD5: 9824d358a08e172534e8066e384eb4ba
Size: 783.36 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 9824d358a08e172534e8066e384eb4ba
Sha1 8a3d9e2e83b445663ce5cf49de0989192c97a766
Sha256 239cf71611fe5e6a3c829fe323d0fa0286eafaffee69a8085cdaf203ed15f7e4
Sha384 894a9089d5d79ba5448ac4a1d41f6a84d8eb330b69bdb5b8a5edc108cb262b5892108da9ea872e902564a27603a77c94
Sha512 416ed02cf851356dff3e3899f456ab984391a37289ec8352733c02c026165d2da604b230b58650be9d032570868155a41cf6802d7d90f993ccfa9bec44803492
SSDeep 12288:Fon4WEC7vYDv7621IRrZZ0a9UuVIbzM2pdbbDq5pSvRKwiMO8Ny8gP9Hf8Vm4Ka7:F24w8760IRtuaeuuvq5IvALMOuyBVEX1
TLSH 80F423846619CD27E65118F00EB2C17526F8DCC68714C2DB5FE82EAF3EFA380595A397
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
SolarSystem.Azz.resources
SolarSystem.Form1.resources
$this.Icon
[NBF]root.IconData
Mars
[NBF]root.Data
contextMenuStrip1.TrayLocation
menuStrip1.TrayLocation
SolarSystem.Properties.Resources.resources
dtOw
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
xift.exe
Full Name
xift.exe
EntryPoint
System.Void SolarSystem.Program::Main()
Scope Name
xift.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xift
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
48
Main Method
System.Void SolarSystem.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void SolarSystem.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
xift.exe
Full Name
xift.exe
EntryPoint
System.Void SolarSystem.Program::Main()
Scope Name
xift.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xift
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
48
Main Method
System.Void SolarSystem.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void SolarSystem.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
SolarSystem.Azz.resources
SolarSystem.Form1.resources
$this.Icon
[NBF]root.IconData
Mars
[NBF]root.Data
contextMenuStrip1.TrayLocation
menuStrip1.TrayLocation
SolarSystem.Properties.Resources.resources
dtOw
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙