Suspicious
Suspect

aafbdad32bf094faa6358f755099f5e5

PE Executable
MD5: aafbdad32bf094faa6358f755099f5e5
Size: 1.1 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 aafbdad32bf094faa6358f755099f5e5
Sha1 cef835accdedec235a54b63a41502ef96e0ba339
Sha256 37c2c5d56cc763a7731523541ea9b206beb80dace89e1615b0cab7d5afa1ffe5
Sha384 bc3f3fc393c850e3a1d57bf506de3a5b92aff23b8cf03ca76acf53a6b5569c430de5095ba8899f5bcabd68c905b309fa
Sha512 51c7388a4f598a7efd5c71c6b42cfa0ea3b8f5054e949e4528aae8fe8baffc1f3a16dd728b94226e58edf7b409a8d36f6a32ee15007a5929051732ed818f6668
SSDeep 24576:We9WaoceqE4adUcGErglLq5jlZ6klxRr2k:WAbpkdUcfrBdlZ3J3
TLSH EA35E02815274502E9F1BEF05EB1B1F067666C66B239E0291FD20DAFF2772447E8532B
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BeachGroyne.Properties.Resources.resources
Tree
[NBF]root.Data
kftS
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Module Name
wYOo.exe
Full Name
wYOo.exe
EntryPoint
System.Void BeachGroyne.Program::Main()
Scope Name
wYOo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
wYOo
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
454
Main Method
System.Void BeachGroyne.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BeachGroyne.PaaValikkoMuoto::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BeachGroyne.Properties.Resources.resources
Tree
[NBF]root.Data
kftS
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙