Suspicious
Suspect

acca7e588bcc9d72869facde2b77b7e7

PE Executable
MD5: acca7e588bcc9d72869facde2b77b7e7
Size: 1.49 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 acca7e588bcc9d72869facde2b77b7e7
Sha1 9828e766f249432921c0078002b74e120991ef07
Sha256 99d883f9af7ecbf4d3d7a59a6a40cbaa67d2255a86c01f5e39d8d03fd4e7bafc
Sha384 b595d352cc01510ec2546dc107165449e5a95df48c63439f39f78902cc837f442e4230636ca444006a412d4e4a0f7992
Sha512 5a88c03f54ae5e889fe4107af2808718b238347216efe41bd2bf2ff97be17b9a32de2f4c1f70616cd14ef340b341e5abc1bd5fe191bbe3c6bfc652eaffb90594
SSDeep 24576:hFFEsF/21U4S/4Y01vzu/IJVU14K+mFlVm/n7seNw9CAtIISv3T:fFEsF/6
TLSH A2659F19D646DE2EFF028C745B6338224AC5E900CB9617C2D2AC4EBBACB93444D5EDD7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_aa4f93da.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
ID:0007
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TXTconverterSetup.g.resources
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x168A00 size 12096 bytes
Module Name
TXTconverterSetup.exe
Full Name
TXTconverterSetup.exe
EntryPoint
System.Void TXTconverter.Installer.App::Main()
Scope Name
TXTconverterSetup.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TXTconverterSetup
Assembly Version
3.1.1.4
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
123
Main Method
System.Void TXTconverter.Installer.App::Main()
Main IL Instruction Count
6
Main IL
newobj System.Void TXTconverter.Installer.App::.ctor()
dup <null>
callvirt System.Void TXTconverter.Installer.App::InitializeComponent()
callvirt System.Int32 System.Windows.Application::Run()
pop <null>
ret <null>
Module Name
TXTconverterSetup.exe
Full Name
TXTconverterSetup.exe
EntryPoint
System.Void TXTconverter.Installer.App::Main()
Scope Name
TXTconverterSetup.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TXTconverterSetup
Assembly Version
3.1.1.4
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
123
Main Method
System.Void TXTconverter.Installer.App::Main()
Main IL Instruction Count
6
Main IL
newobj System.Void TXTconverter.Installer.App::.ctor()
dup <null>
callvirt System.Void TXTconverter.Installer.App::InitializeComponent()
callvirt System.Int32 System.Windows.Application::Run()
pop <null>
ret <null>
[Authenticode]_aa4f93da.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
ID:0007
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TXTconverterSetup.g.resources
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙