Suspicious
Suspect

b72fc12da2c876164c892a2807e79ecb

Share on LinkedIn
Print
PE Executable
MD5: b72fc12da2c876164c892a2807e79ecb
Size: 1.8 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 b72fc12da2c876164c892a2807e79ecb
Sha1 d87dd66ee47d0185413f0cd86ee5fe16f274fac3
Sha256 22500061a04539aeb8acbe477bc94b8edcb83191885bd3477e7cdf7da1a7dece
Sha384 a294ee423e0a12328e8e1e0cc0ea0bc7b29db5ba7fee56a28ac15f2d73e09984cf3dda68a5fd2dc8fb99c3137dd94419
Sha512 0dfabd658b84708b0a460b69c69c0e82a41f36f6626032b0a13bd1ec6cd05ad87bf0b6e8e809b7b3822bdf5c19ef53cccc6adc01014d1321e930d5bd82265d5a
SSDeep 49152:1Y3GaAACNt4rjQ0kvoKkWwBXlb3tvd1z:1Y3ZATNt6kHoLXlbdn
TLSH E0851255128DCD01D29A1FB546A0D379837B8E19E932D3079BEEBCEB7B2730569013E2
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ProjectCafe.CompressionInspiredExtractor.resources
btnAbout.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnDashboard.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnLogout.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnSettings.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnSidebar.Image
btnSubMenu1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnSubMenu2.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
button2.Image
[NBF]root.Data
[NBF]root.Data-preview.png
menu.Image
[NBF]root.Data
[NBF]root.Data-preview.png
menuTransititon.TrayLocation
sidebarTransition.TrayLocation
ProjectCafe.FormAbout.resources
ProjectCafe.Properties.Resources.resources
Fee
[NBF]root.Data
Lquk
[NBF]root.Data
[NBF]root.Data-preview.png
Menu
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Xmwp.exe
Full Name
Xmwp.exe
EntryPoint
System.Void ProjectCafe.Program::Main()
Scope Name
Xmwp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Xmwp
Assembly Version
4.5.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\cLIcDYSAXt\src\obj\Debug\Xmwp.pdb
Total Strings
333
Main Method
System.Void ProjectCafe.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ProjectCafe.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙