Suspicious
Suspect

b424246e9d67f5266b9b9113f9ca4234

PE Executable
MD5: b424246e9d67f5266b9b9113f9ca4234
Size: 2.97 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 b424246e9d67f5266b9b9113f9ca4234
Sha1 416ff073576f79669e1e24b3df2eeaec9235953f
Sha256 42cc3afcffb3d21b60ddd95d5de6522a3f3798eb70e7033787257dcdd2226a93
Sha384 619588934430aae88ef9dbb5e6ed724ceac13da52de014951dbcbf0e22af526f76a06939ff7742d9c3183fc826fb7c9c
Sha512 15c4ed0e624e4ea5bdf7e1fd7620058e451427f325dd7b8f6d3d9fea7c621ace4bf556586024706965a06d5f9552bfc881487097cafa1279771c6e105c134f2f
SSDeep 49152:zW1tgMoAnn0dMsm9nkjNXFWWjL5rVmW1tgMoAnn0dMsm9nkjNXFWWjL5IV:igMx8Mf9GNXFHn5rfgMx8Mf9GNXFHn5I
TLSH 54D523D0B6439553DF2F05B44692AA3C0BF0B8DAB113E7FA98B4465D6ACFF00254D29E
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
ID:0007
ID:0
ID:0-preview.png
ID:0008
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
.Net Resources
LegendsL2Launcher.launcher.config.json
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
L2AncientsInstaller.background.jpg
L2AncientsInstaller.background.jpg-preview.png
L2AncientsInstaller.brand.png
L2AncientsInstaller.brand.png-preview.png
b424246e9d67f5266b9b9113f9ca4234
0x000273B5.svg
0x000273B5.svg-preview.jpg
STICH beta

No STICH Path has been generated for this analysis yet.

5 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 3img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
L2AncientsSetup.exe
Full Name
L2AncientsSetup.exe
EntryPoint
System.Void L2AncientsInstaller.Program::Main(System.String[])
Scope Name
L2AncientsSetup.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
L2AncientsSetup
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
48
Main Method
System.Void L2AncientsInstaller.Program::Main(System.String[])
Main IL Instruction Count
58
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void L2AncientsInstaller.InstallerForm::.ctor()
stloc.0 <null>
ldarg.0 <null>
ldlen <null>
conv.i4 <null>
ldc.i4.2 <null>
bne.un.s IL_007A: ldloc.0
ldarg.0 <null>
ldc.i4.0 <null>
ldelem.ref <null>
ldstr --preview
ldc.i4.5 <null>
call System.Boolean System.String::Equals(System.String,System.String,System.StringComparison)
brfalse.s IL_007A: ldloc.0
ldloc.0 <null>
callvirt System.Void System.Windows.Forms.Control::Show()
call System.Void System.Windows.Forms.Application::DoEvents()
ldloc.0 <null>
callvirt System.Int32 System.Windows.Forms.Control::get_Width()
ldloc.0 <null>
callvirt System.Int32 System.Windows.Forms.Control::get_Height()
newobj System.Void System.Drawing.Bitmap::.ctor(System.Int32,System.Int32)
stloc.1 <null>
ldloc.0 <null>
ldloc.1 <null>
ldc.i4.0 <null>
ldc.i4.0 <null>
ldloc.1 <null>
callvirt System.Int32 System.Drawing.Image::get_Width()
ldloc.1 <null>
callvirt System.Int32 System.Drawing.Image::get_Height()
newobj System.Void System.Drawing.Rectangle::.ctor(System.Int32,System.Int32,System.Int32,System.Int32)
callvirt System.Void System.Windows.Forms.Control::DrawToBitmap(System.Drawing.Bitmap,System.Drawing.Rectangle)
ldloc.1 <null>
ldarg.0 <null>
ldc.i4.1 <null>
ldelem.ref <null>
call System.Drawing.Imaging.ImageFormat System.Drawing.Imaging.ImageFormat::get_Png()
callvirt System.Void System.Drawing.Image::Save(System.String,System.Drawing.Imaging.ImageFormat)
leave.s IL_0078: leave.s IL_008C
ldloc.1 <null>
brfalse.s IL_0077: endfinally
ldloc.1 <null>
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
leave.s IL_008C: ret
ldloc.0 <null>
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
leave.s IL_008C: ret
ldloc.0 <null>
brfalse.s IL_008B: endfinally
ldloc.0 <null>
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
ret <null>
Module Name
L2AncientsSetup.exe
Full Name
L2AncientsSetup.exe
EntryPoint
System.Void L2AncientsInstaller.Program::Main(System.String[])
Scope Name
L2AncientsSetup.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
L2AncientsSetup
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
48
Main Method
System.Void L2AncientsInstaller.Program::Main(System.String[])
Main IL Instruction Count
58
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void L2AncientsInstaller.InstallerForm::.ctor()
stloc.0 <null>
ldarg.0 <null>
ldlen <null>
conv.i4 <null>
ldc.i4.2 <null>
bne.un.s IL_007A: ldloc.0
ldarg.0 <null>
ldc.i4.0 <null>
ldelem.ref <null>
ldstr --preview
ldc.i4.5 <null>
call System.Boolean System.String::Equals(System.String,System.String,System.StringComparison)
brfalse.s IL_007A: ldloc.0
ldloc.0 <null>
callvirt System.Void System.Windows.Forms.Control::Show()
call System.Void System.Windows.Forms.Application::DoEvents()
ldloc.0 <null>
callvirt System.Int32 System.Windows.Forms.Control::get_Width()
ldloc.0 <null>
callvirt System.Int32 System.Windows.Forms.Control::get_Height()
newobj System.Void System.Drawing.Bitmap::.ctor(System.Int32,System.Int32)
stloc.1 <null>
ldloc.0 <null>
ldloc.1 <null>
ldc.i4.0 <null>
ldc.i4.0 <null>
ldloc.1 <null>
callvirt System.Int32 System.Drawing.Image::get_Width()
ldloc.1 <null>
callvirt System.Int32 System.Drawing.Image::get_Height()
newobj System.Void System.Drawing.Rectangle::.ctor(System.Int32,System.Int32,System.Int32,System.Int32)
callvirt System.Void System.Windows.Forms.Control::DrawToBitmap(System.Drawing.Bitmap,System.Drawing.Rectangle)
ldloc.1 <null>
ldarg.0 <null>
ldc.i4.1 <null>
ldelem.ref <null>
call System.Drawing.Imaging.ImageFormat System.Drawing.Imaging.ImageFormat::get_Png()
callvirt System.Void System.Drawing.Image::Save(System.String,System.Drawing.Imaging.ImageFormat)
leave.s IL_0078: leave.s IL_008C
ldloc.1 <null>
brfalse.s IL_0077: endfinally
ldloc.1 <null>
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
leave.s IL_008C: ret
ldloc.0 <null>
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
leave.s IL_008C: ret
ldloc.0 <null>
brfalse.s IL_008B: endfinally
ldloc.0 <null>
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
ID:0007
ID:0
ID:0-preview.png
ID:0008
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
.Net Resources
LegendsL2Launcher.launcher.config.json
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
L2AncientsInstaller.background.jpg
L2AncientsInstaller.background.jpg-preview.png
L2AncientsInstaller.brand.png
L2AncientsInstaller.brand.png-preview.png
b424246e9d67f5266b9b9113f9ca4234
0x000273B5.svg
0x000273B5.svg-preview.jpg
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙