Suspicious
Suspect

b865d511713d8f0bbb7cd7c209e1e660

PE Executable
MD5: b865d511713d8f0bbb7cd7c209e1e660
Size: 1.02 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 b865d511713d8f0bbb7cd7c209e1e660
Sha1 1cba7604cd06ff3e4af58a8ebc6dbb4f5cc647a4
Sha256 51fec247480d39d3fa354fa4a4d81a08155a9de87330d01cc8299e4cbeab6ca5
Sha384 bc58918dfe8bf976a08967aafc3c2a9f60e95be6b31c4d8b7eec66cba15f50bd16619531f624f9c96d89e0b8d0eb9c85
Sha512 b7f81c69498d7bdc415073caafb21f3a7e2f5c0d04c1d103d78cf87ae06b731a9da0dca8a2518a7e6f0ce8e36bc80a8267fa459c884bdd9c0097ffbd10836521
SSDeep 24576:lNctsC1Vdxdh/PkaB1Nl0ADqK3OLp9gHHAvIlmysAguFyQb:Xc51EaDNl5Dq4OIAvI/IuFyQ
TLSH 9725128C32AA8712D5E657F85EB2E13057B53C8D8634D20E5FD02EEF7970B164A14B27
PeID
ASProtect v1.32
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RooftopHarvest.FormMaison.resources
RooftopHarvest.Properties.Resources.resources
IMG
[NBF]root.Data
QnOk
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
LSsK.exe
Full Name
LSsK.exe
EntryPoint
System.Void RooftopHarvest.Program::Main()
Scope Name
LSsK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LSsK
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
416
Main Method
System.Void RooftopHarvest.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void RooftopHarvest.SharedData::Initialiser()
nop <null>
newobj System.Void RooftopHarvest.FormMaison::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RooftopHarvest.FormMaison.resources
RooftopHarvest.Properties.Resources.resources
IMG
[NBF]root.Data
QnOk
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙