Suspicious
Suspect

aeab6e6eb81f1eb3f0120e2b5516537a

PE Executable
MD5: aeab6e6eb81f1eb3f0120e2b5516537a
Size: 916.48 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 aeab6e6eb81f1eb3f0120e2b5516537a
Sha1 88c29b0c509ac28d3e788143f6138b586b9b9a26
Sha256 a0f98f3cc53d1a6a7ad0d9c2df1de1ea370d97dd8af04230d9bb7fb2f76d705a
Sha384 5140ff4b42f6efd9adb78b655c3697bdb8a757e83102ecc2f9e456a69b8dfc53c598d4521244352b63c226bf8a1167ec
Sha512 0ed80b0c54d6aac31ae8723dbec4142e7598ca120c3d65c334c87e18bfea774692a6675390fb0239489e6cc016303e6de30efb49da619694e9828768d5a48925
SSDeep 24576:vuFCqk2wHgzr2LUcGudmuV0QhhxpLaAg5myh64+LD0deIH:cCqk2wgH2LUgdNrpLaF5Vx+fy
TLSH 7E15228173A52F9BE8BB83FE21D1640243F5AA5B7820E34C5DD921DB62F6B414628F53
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AirPortStand.ApronForm.resources
AirPortStand.Properties.Resources.resources
abigail
[NBF]root.Data
[NBF]root.Data-preview.png
sLjX
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
sZfa.exe
Full Name
sZfa.exe
EntryPoint
System.Void AirPortStand.Program::Main()
Scope Name
sZfa.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
sZfa
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
485
Main Method
System.Void AirPortStand.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AirPortStand.ApronForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AirPortStand.ApronForm.resources
AirPortStand.Properties.Resources.resources
abigail
[NBF]root.Data
[NBF]root.Data-preview.png
sLjX
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙