Suspicious
Suspect

Rar Archive
MD5: 9bfba66569cd561038ea846453415737
Size: 1.85 MB
application/vnd.rar

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 9bfba66569cd561038ea846453415737
Sha1 68885ee494ab69ddde482f172dea4457a2a91f32
Sha256 72df054cc19ea7327ca090fa5419fa0006168fa7808d247ebbd3509e0fdae5c0
Sha384 2a49703459f9939671d2c0605c62e19fc512cdd460465e0702288fc7da09c8f11a03ae3bebbd5d04070447df153247c1
Sha512 4e0dd8b6699950c3909f5329dafddb476bc91493a4ee0a85b5176e10ebf490dfc87493de6a2a3d523e56b5011d33a576261035725de5e9878bb938a9287d0377
SSDeep 49152:Wd58e3oqxXSnYmEoAiUlod1Cv3NI84MthZ3bpAV:i82NxXNmEoAdlobCfZLK
TLSH 63853399B72B3D07C62238D806FC0D696B6E67C9434026C271D7CE83D49AE84FB646DD
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Star_generator.Properties.Resources.resources
KWSF
[NBF]root.Data
[NBF]root.Data-preview.png
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Star_generator.Form1.resources
$this.Icon
[NBF]root.IconData
Moon
[NBF]root.Data
Star_generator.Properties.Resources.resources
DwFO
[NBF]root.Data
[NBF]root.Data-preview.png
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Star_generator.Properties.Resources.resources
KWSF
[NBF]root.Data
[NBF]root.Data-preview.png
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Star_generator.Form1.resources
$this.Icon
[NBF]root.IconData
Moon
[NBF]root.Data
Star_generator.Properties.Resources.resources
DwFO
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙