Suspicious
Suspect

b029a8256104108b1c96594a86b8493f

PE Executable
MD5: b029a8256104108b1c96594a86b8493f
Size: 1.84 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 b029a8256104108b1c96594a86b8493f
Sha1 f0589a7bcb9c80cda3e11170b838a712505846cb
Sha256 4c67547dfe0e49d3735287dae9596b983bc82faa75363161197640c73fe2f902
Sha384 29d6ae49cd351467fe1dbcf3d30cfb0cd093fec071f6dab918c9415b3ee20adf0ef28ca52b30042780df65e54a093b10
Sha512 9bf78f46f2e41136668c82201b0a9c3e01ed02da487ed4dea57d154b310265f7dfd2adcdd04c8975e1db4d57730b3ce4fcc5129d232c18c01026dff70c3fd1f4
SSDeep 49152:QYSCym06Rqt1ntq0iQd7dad7AZV0IkVdqt3WqeQGZ7H:YmFqt1ntNdMAWqoB
TLSH 9E8523A552F49E10D5FD13B26A02E6B413B16EAAF262E3125BF2ACF377237456C40743
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TermiteMound.Properties.Resources.resources
Cringe
[NBF]root.Data
gAxz
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Module Name
xUVW.exe
Full Name
xUVW.exe
EntryPoint
System.Void TermiteMound.Program::Main()
Scope Name
xUVW.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xUVW
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
419
Info
PE Detect: PeReader OK (file layout)
Main Method
System.Void TermiteMound.Program::Main()
Main IL Instruction Count
60
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void System.Random::.ctor()
stloc.0 <null>
ldc.i4.0 <null>
stloc.1 <null>
br.s IL_007C: ldloc.1
nop <null>
ldsfld System.Single[] TermiteMound.Program::robitnykyX
ldloc.1 <null>
ldloc.0 <null>
ldc.i4.s 50
ldc.i4 250
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
conv.r4 <null>
stelem.r4 <null>
ldsfld System.Single[] TermiteMound.Program::robitnykyY
ldloc.1 <null>
ldloc.0 <null>
ldc.i4 150
ldc.i4 350
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
conv.r4 <null>
stelem.r4 <null>
ldsfld System.Single[] TermiteMound.Program::robitnykySpeed
ldloc.1 <null>
ldloc.0 <null>
callvirt System.Double System.Random::NextDouble()
ldc.r8 3
mul <null>
ldc.r8 1
add <null>
conv.r4 <null>
stelem.r4 <null>
ldsfld System.Int32[] TermiteMound.Program::robitnykyTunnel
ldloc.1 <null>
ldloc.0 <null>
ldc.i4.0 <null>
ldc.i4.4 <null>
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
stelem.i4 <null>
nop <null>
ldloc.1 <null>
ldc.i4.1 <null>
add <null>
stloc.1 <null>
ldloc.1 <null>
ldc.i4.s 25
clt <null>
stloc.2 <null>
ldloc.2 <null>
brtrue.s IL_0018: nop
newobj System.Void TermiteMound.KupynaForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
xUVW.exe
Full Name
xUVW.exe
EntryPoint
System.Void TermiteMound.Program::Main()
Scope Name
xUVW.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xUVW
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
419
Main Method
System.Void TermiteMound.Program::Main()
Main IL Instruction Count
60
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void System.Random::.ctor()
stloc.0 <null>
ldc.i4.0 <null>
stloc.1 <null>
br.s IL_007C: ldloc.1
nop <null>
ldsfld System.Single[] TermiteMound.Program::robitnykyX
ldloc.1 <null>
ldloc.0 <null>
ldc.i4.s 50
ldc.i4 250
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
conv.r4 <null>
stelem.r4 <null>
ldsfld System.Single[] TermiteMound.Program::robitnykyY
ldloc.1 <null>
ldloc.0 <null>
ldc.i4 150
ldc.i4 350
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
conv.r4 <null>
stelem.r4 <null>
ldsfld System.Single[] TermiteMound.Program::robitnykySpeed
ldloc.1 <null>
ldloc.0 <null>
callvirt System.Double System.Random::NextDouble()
ldc.r8 3
mul <null>
ldc.r8 1
add <null>
conv.r4 <null>
stelem.r4 <null>
ldsfld System.Int32[] TermiteMound.Program::robitnykyTunnel
ldloc.1 <null>
ldloc.0 <null>
ldc.i4.0 <null>
ldc.i4.4 <null>
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
stelem.i4 <null>
nop <null>
ldloc.1 <null>
ldc.i4.1 <null>
add <null>
stloc.1 <null>
ldloc.1 <null>
ldc.i4.s 25
clt <null>
stloc.2 <null>
ldloc.2 <null>
brtrue.s IL_0018: nop
newobj System.Void TermiteMound.KupynaForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TermiteMound.Properties.Resources.resources
Cringe
[NBF]root.Data
gAxz
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙