Suspicious
Suspect

b980b243307e67831945f3171edd200c

PE Executable
MD5: b980b243307e67831945f3171edd200c
Size: 2.86 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 b980b243307e67831945f3171edd200c
Sha1 60bee9be8b1a782592243014d0d0907f3d660241
Sha256 c522e49fa2f87b3e8e9925555377aa77a42ed9d1790c17b25c2ad052efa96569
Sha384 0d9607c8844143a6bf0fb2cfdf876cb5bdc2d8efc0ea55534d96759718128b5255f8e617718ff71c613360fa00ed0a1c
Sha512 b2477021702584eebc95b21f926029fc7d36816affe1d2b7e1c82fc221570c495c135c094a391b24e5089930fcee35619f988b876e29e7f0bbea06b42183ab41
SSDeep 49152:1dEOxZyO7J5EP6In/EZevrvjQa47tOjcpSimHvb/2oS:15QO7HEP6sEZevLjQa474cp2Hvbuo
TLSH 2CD5124C3251F94EC463DE718D70EEB0BA645DA19217D20395E72DAFB92D48AEF042F2
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BellFoundry.Properties.Resources.resources
IRXC
[NBF]root.Data
[NBF]root.Data-preview.png
Pro
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
trwk.exe
Full Name
trwk.exe
EntryPoint
System.Void BellFoundry.Program::Main()
Scope Name
trwk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
trwk
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
324
Main Method
System.Void BellFoundry.Program::Main()
Main IL Instruction Count
25
Main IL
nop <null>
call System.Void BellFoundry.Program::‍‌‫‭‏‭‍‫‌‍‏‪‎‍​‏‭‍‏‏‫‫‌‍‍‮()
nop <null>
ldc.i4.0 <null>
call System.Void BellFoundry.Program::‎‪‍‍‫‎​‬‎‬‪‎‪‍‬‫‎‎‍‍‏‭‎‮‎‎‮‭‮‏‭‮(System.Boolean)
ldc.i4 -952060022
ldc.i4 -1184969629
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.3 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_004A: ret
nop <null>
newobj System.Void BellFoundry.GjuteriForm::.ctor()
call System.Void BellFoundry.Program::‌‌‍‎‎‌​‏‎‭‬‭‏‏​‪‮‌‌​‍‭‬‌‮(System.Windows.Forms.Form)
nop <null>
ldloc.0 <null>
ldc.i4 1157505636
mul <null>
ldc.i4 -1234962670
xor <null>
br.s IL_0012: ldc.i4 -1184969629
ret <null>
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BellFoundry.Properties.Resources.resources
IRXC
[NBF]root.Data
[NBF]root.Data-preview.png
Pro
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙