Suspicious
Suspect

b980b243307e67831945f3171edd200c

Share on LinkedIn
Print
PE Executable
MD5: b980b243307e67831945f3171edd200c
Size: 2.86 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 b980b243307e67831945f3171edd200c
Sha1 60bee9be8b1a782592243014d0d0907f3d660241
Sha256 c522e49fa2f87b3e8e9925555377aa77a42ed9d1790c17b25c2ad052efa96569
Sha384 0d9607c8844143a6bf0fb2cfdf876cb5bdc2d8efc0ea55534d96759718128b5255f8e617718ff71c613360fa00ed0a1c
Sha512 b2477021702584eebc95b21f926029fc7d36816affe1d2b7e1c82fc221570c495c135c094a391b24e5089930fcee35619f988b876e29e7f0bbea06b42183ab41
SSDeep 49152:1dEOxZyO7J5EP6In/EZevrvjQa47tOjcpSimHvb/2oS:15QO7HEP6sEZevLjQa474cp2Hvbuo
TLSH 2CD5124C3251F94EC463DE718D70EEB0BA645DA19217D20395E72DAFB92D48AEF042F2
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BellFoundry.Properties.Resources.resources
IRXC
[NBF]root.Data
[NBF]root.Data-preview.png
Pro
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
trwk.exe
Full Name
trwk.exe
EntryPoint
System.Void BellFoundry.Program::Main()
Scope Name
trwk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
trwk
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
324
Main Method
System.Void BellFoundry.Program::Main()
Main IL Instruction Count
25
Main IL
nop <null>
call System.Void BellFoundry.Program::‍‌‫‭‏‭‍‫‌‍‏‪‎‍​‏‭‍‏‏‫‫‌‍‍‮()
nop <null>
ldc.i4.0 <null>
call System.Void BellFoundry.Program::‎‪‍‍‫‎​‬‎‬‪‎‪‍‬‫‎‎‍‍‏‭‎‮‎‎‮‭‮‏‭‮(System.Boolean)
ldc.i4 -952060022
ldc.i4 -1184969629
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.3 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_004A: ret
nop <null>
newobj System.Void BellFoundry.GjuteriForm::.ctor()
call System.Void BellFoundry.Program::‌‌‍‎‎‌​‏‎‭‬‭‏‏​‪‮‌‌​‍‭‬‌‮(System.Windows.Forms.Form)
nop <null>
ldloc.0 <null>
ldc.i4 1157505636
mul <null>
ldc.i4 -1234962670
xor <null>
br.s IL_0012: ldc.i4 -1184969629
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙