Suspicious
Suspect

a08abb310919ee6aee953c3669a382c0

PE Executable
MD5: a08abb310919ee6aee953c3669a382c0
Size: 717.82 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 a08abb310919ee6aee953c3669a382c0
Sha1 ddab67dd3cd8572c7b4f9702df21358935ef0fd2
Sha256 e5cfe69cb96d8fa21b39cb4a0dc60333fa7bacc7b452ebcd8acfbf58ef0625cf
Sha384 774e1a4e1ed650bbb25832d08114c0173b328cc97770f8cf4719588677f7dd50c1d8ff4e1731afddfafbde3cbb772494
Sha512 d16d0837f42a92232300d48c0792a2872c713b88dce2c96665faae1de4d29e6f91c2df610b09f4cf014b108d12dbb07b05b61648fdd324dfdf871728c07e3088
SSDeep 12288:rNmVEp3/Pxbis9FRl+TCwQYkJ6jkweF0U9MtjAwj2SIcN2i2CZdcFIuN:rIVahO0RlECkpU/9MhrrL6CZ2FP
TLSH E0E41230A71DD842D6D183764DB4D3B201B4BEEEE616D6638BECBCFBB962B014844356
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NeuralNetStudio.Properties.Resources.resources
Cringe
[NBF]root.Data
Wlbs
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\kRfwZikEAt\src\obj\Debug\PhBe.pdb
Module Name
PhBe.exe
Full Name
PhBe.exe
EntryPoint
System.Void NeuralNetStudio.Program::Main()
Scope Name
PhBe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PhBe
Assembly Version
6.9.3.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
224
Main Method
System.Void NeuralNetStudio.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void NeuralNetStudio.StudioUI::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NeuralNetStudio.Properties.Resources.resources
Cringe
[NBF]root.Data
Wlbs
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙