Suspicious
Suspect

bf1e808d7e6812bed9d86fd5aea256dd

PE Executable
MD5: bf1e808d7e6812bed9d86fd5aea256dd
Size: 1.24 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 bf1e808d7e6812bed9d86fd5aea256dd
Sha1 78c69adac0710e8ee3fa14f442fb1dce22ee4bb3
Sha256 4f9df700891ba8fcf918a8bcdd527d9109c7888be2201876fa64d73bfdcfd98a
Sha384 a3e7a02d916eb03d8d55d8b4f42df7c4269a0651c1513ff99d145ff58f1f1a0e53473e6f3d1a729c93b50a0a3b613f57
Sha512 3f50758b0b69d0f186ec99b56826b76e38c147f5339cfa3422221bf12510dad07c1b99baa2abd2c8ea0a0bde9b4333c76a49e66eb903b7a24b23be71158b1017
SSDeep 24576:kPJGFsijP/2oSdvZfyluDjAQTqclTmfKXaY1l/V5zyr71Ik:k41b/2oSL7jhTaYb95en1
TLSH FA45DF9C3210F88FC4579E728964ED74AA202CA6970BD30395E72DEFF91D59B9E041E3
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CharcoalKiln.Properties.Resources.resources
Pro
[NBF]root.Data
XLHJ
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
CRyz.exe
Full Name
CRyz.exe
EntryPoint
System.Void CharcoalKiln.Program::Main()
Scope Name
CRyz.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CRyz
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
3
Main Method
System.Void CharcoalKiln.Program::Main()
Main IL Instruction Count
31
Main IL
nop <null>
ldc.i4 -77807218
ldc.i4 -1737084284
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.4 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_005D: ret
call System.Void CharcoalKiln.Program::‍‫‏‌​​​‫‪‏‫‍​‫‪‌‪‪‫‌‮‍‪‎‍‮()
nop <null>
ldc.i4.0 <null>
call System.Void CharcoalKiln.Program::‭‏‌‭‍‭‌‬‬‬‍‫‌‍‏‌‫‪‬‎​‬‮‫‪‎‌‭‮(System.Boolean)
nop <null>
newobj System.Void CharcoalKiln.UgnForm::.ctor()
call System.Void CharcoalKiln.Program::‎​‌‫‭‫‌‮‮‭‭‮‫‫‎​‎‮‪‎‪‭‏​‍‪‪‍‬‎‎‮(System.Windows.Forms.Form)
ldloc.0 <null>
ldc.i4 640156414
mul <null>
ldc.i4 -639027855
xor <null>
br.s IL_0006: ldc.i4 -1737084284
nop <null>
ldloc.0 <null>
ldc.i4 1221165366
mul <null>
ldc.i4 -800928034
xor <null>
br.s IL_0006: ldc.i4 -1737084284
ret <null>
Module Name
CRyz.exe
Full Name
CRyz.exe
EntryPoint
System.Void CharcoalKiln.Program::Main()
Scope Name
CRyz.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CRyz
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
3
Main Method
System.Void CharcoalKiln.Program::Main()
Main IL Instruction Count
31
Main IL
nop <null>
ldc.i4 -77807218
ldc.i4 -1737084284
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.4 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_005D: ret
call System.Void CharcoalKiln.Program::‍‫‏‌​​​‫‪‏‫‍​‫‪‌‪‪‫‌‮‍‪‎‍‮()
nop <null>
ldc.i4.0 <null>
call System.Void CharcoalKiln.Program::‭‏‌‭‍‭‌‬‬‬‍‫‌‍‏‌‫‪‬‎​‬‮‫‪‎‌‭‮(System.Boolean)
nop <null>
newobj System.Void CharcoalKiln.UgnForm::.ctor()
call System.Void CharcoalKiln.Program::‎​‌‫‭‫‌‮‮‭‭‮‫‫‎​‎‮‪‎‪‭‏​‍‪‪‍‬‎‎‮(System.Windows.Forms.Form)
ldloc.0 <null>
ldc.i4 640156414
mul <null>
ldc.i4 -639027855
xor <null>
br.s IL_0006: ldc.i4 -1737084284
nop <null>
ldloc.0 <null>
ldc.i4 1221165366
mul <null>
ldc.i4 -800928034
xor <null>
br.s IL_0006: ldc.i4 -1737084284
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CharcoalKiln.Properties.Resources.resources
Pro
[NBF]root.Data
XLHJ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙