Suspicious
Suspect

c086246a14362e356f3413615b778079

PE Executable
MD5: c086246a14362e356f3413615b778079
Size: 1.44 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 c086246a14362e356f3413615b778079
Sha1 7d77f2a106b3229587143cc962eaa2f36b288f43
Sha256 a511d02211003769575ee9e8a44888c5e11263400a8188033f9892da1b6b6a0a
Sha384 a6a5e24fcc7e1c297bac36b6c1f9205343f50f68b121b3d0f0ed7cae168de42415e4efe7388e9fa1f702022f741e60f4
Sha512 cf6c2436bc74dd5934fcbc414fdaf0a423f7c33c68bacaac3842eeded0dcfefc7013dba3256471ddfca4eacc5b03bcd5c3c3c02b4005cc388fd9a08ab5384e15
SSDeep 24576:3oULR4THPSnhaN7LUNaQWfDlFFcMi7SxjTPgZzVj5CMqLF7PjE14Xkv:3oULRiH6gyopfDNcMi7cPyj5CPRjE14U
TLSH EE65D02B2D13A536D7716EBF0C60E0B517686C56A5E4E1063EDEFDAB7C3AE013904352
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CloudSpotter.Properties.Resources.resources
Pu1
[NBF]root.Data
Pun
[NBF]root.Data
WrmN
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
aTqC.exe
Full Name
aTqC.exe
EntryPoint
System.Void CloudSpotter.Program::Main()
Scope Name
aTqC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
aTqC
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
400
Main Method
System.Void CloudSpotter.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CloudSpotter.FormSky::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
aTqC.exe
Full Name
aTqC.exe
EntryPoint
System.Void CloudSpotter.Program::Main()
Scope Name
aTqC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
aTqC
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
400
Main Method
System.Void CloudSpotter.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CloudSpotter.FormSky::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CloudSpotter.Properties.Resources.resources
Pu1
[NBF]root.Data
Pun
[NBF]root.Data
WrmN
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙