Suspicious
Suspect

bf1eb8d8ac889baaa77dfc8bd379fff9

PE Executable
MD5: bf1eb8d8ac889baaa77dfc8bd379fff9
Size: 1.59 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 bf1eb8d8ac889baaa77dfc8bd379fff9
Sha1 963229ae2ca4da7c10c75683e440e65fff414407
Sha256 54a8d0df199ee2b8bf8fea306f6a6df3cd4b2e9de579ba2dbf8e20ec9c3518b4
Sha384 ed6a91a91d0fadc7c6be5caf0d048f09bd185969f123e74be89ed1e50881d2e62a2b214e30f68948b6513d9783ca4875
Sha512 5f8e82ff2acfee62ee54f51b563b595eb3d7285940cc6ae996b6f1aeb1a6a4ffdb12a72af98e17cf1d644cea33992e707b8b06e6b34a69e0b08d7041cbb7bebd
SSDeep 49152:OV3qKtaocQYdo1IvtyMauQ8KCwsarOwMyBe+TUB:43qKtaoBPuJQ1tyx++
TLSH FD7523B093A5CC52EEEC873350B6D3B95174AE9DA8029747CBDEBDF77A5421C3890680
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
NetworkSniffer.Properties.Resources.resources
UDP
[NBF]root.Data
zFcu
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\DHinbSsGzI\src\obj\Debug\wUua.pdb
Module Name
wUua.exe
Full Name
wUua.exe
EntryPoint
System.Void NetworkSniffer.Program::Main()
Scope Name
wUua.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
wUua
Assembly Version
7.6.4.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
134
Main Method
System.Void NetworkSniffer.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NetworkSniffer.MainUI::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
NetworkSniffer.Properties.Resources.resources
UDP
[NBF]root.Data
zFcu
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙