Suspicious
Suspect

99c7c62a172e67e0067881f779b7e14d

Share on LinkedIn
Print
PE Executable
MD5: 99c7c62a172e67e0067881f779b7e14d
Size: 657.41 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 99c7c62a172e67e0067881f779b7e14d
Sha1 125c5fe9be5d285160c59880ca30b805e669ceb8
Sha256 bd866e2c233c16d404a72d97a09e8b486fc9d479404dfa5ad407d1a856584b58
Sha384 9dba065b5338bf0b9ed990ca9121ff81773627cd9e3ec372037372831dd4429e6abb075a53e15500ab93aa8da2fdee4c
Sha512 fe6584260716a0727a4df10a39b3a24ac215a23cfed57d9f0dc9555435fa9d8097211a916da5a4bc43fefa6d532e9fee2253443d221e66fadb46b5e323c37f10
SSDeep 12288:QNavaoWSx4ZI8wTqfDYXSRTNxLWBb5lGGCFW16pt5rtA2wKWUJz9T0i:txuXdfikWBb2fwQNu2wKfli
TLSH 05E4F1486B99C910E5AA27745874E2B40735BF5AB520E31E9FC87DEF3DB27808D02763
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CustomTips.Forms.MainForm.resources
CustomTips.Properties.Resources.resources
KR
[NBF]root.Data
WxwmS
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
fzfcN.exe
Full Name
fzfcN.exe
EntryPoint
System.Void CustomTips.Program::Main()
Scope Name
fzfcN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
fzfcN
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
841
Main Method
System.Void CustomTips.Program::Main()
Main IL Instruction Count
40
Main IL
nop <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
nop <null>
ldnull <null>
ldftn System.Void CustomTips.Program::Application_ThreadException(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
nop <null>
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void CustomTips.Program::CurrentDomain_UnhandledException(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
nop <null>
newobj System.Void CustomTips.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0070: ret
stloc.0 <null>
nop <null>
ldstr Fatal error starting application: 
ldloc.0 <null>
callvirt System.String System.Exception::get_Message()
call System.String System.String::Concat(System.String,System.String)
ldstr Application Error
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_0070: ret
ret <null>
PDB Path PATH
fzfhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙