Suspicious
Suspect

b7c2d94ac4bc98d3b76b446197ea77ac

PE Executable
MD5: b7c2d94ac4bc98d3b76b446197ea77ac
Size: 1.29 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 b7c2d94ac4bc98d3b76b446197ea77ac
Sha1 927980664967efb1c9e5f8a60c5a0bb3dc465758
Sha256 4e56f25f85c6c72ef03efe82a789895feb19990710ca2f7b39b1afa0f6b7e42f
Sha384 db7b7c59041d5b22b9d994c85d037277739a9c6a40223e6af12fd56484d1a5cbc6eebfaba42a045cf2985208f1bb3dbf
Sha512 14019024d93c21b5b6ea56c7acb7ebc0362221d1cda1561040bcfced871af5fc955c5c311da3f44cfb5eb9b4ba270ef483824482fae15e4d5908dece9da03d2e
SSDeep 24576:EdLqjgrX7krBxZaq/TB6vNI8Jjt5a+TmNEXgiTdxEvD/2eW:orkrwqrBMNI8J3FGEXNwvD/W
TLSH F65512543355CA02DAB52BF82932F17813FA6EDEA921D30A5ED96DDB7A32F004D04763
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GlassFurnace.FormFourneau.resources
GlassFurnace.Properties.Resources.resources
AIju
[NBF]root.Data
[NBF]root.Data-preview.png
GM
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
ynKj.exe
Full Name
ynKj.exe
EntryPoint
System.Void GlassFurnace.Program::Main()
Scope Name
ynKj.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ynKj
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
331
Main Method
System.Void GlassFurnace.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void GlassFurnace.FormFourneau::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GlassFurnace.FormFourneau.resources
GlassFurnace.Properties.Resources.resources
AIju
[NBF]root.Data
[NBF]root.Data-preview.png
GM
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙