Suspicious
Suspect

c086246a14362e356f3413615b778079

Share on LinkedIn
Print
PE Executable
MD5: c086246a14362e356f3413615b778079
Size: 1.44 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 c086246a14362e356f3413615b778079
Sha1 7d77f2a106b3229587143cc962eaa2f36b288f43
Sha256 a511d02211003769575ee9e8a44888c5e11263400a8188033f9892da1b6b6a0a
Sha384 a6a5e24fcc7e1c297bac36b6c1f9205343f50f68b121b3d0f0ed7cae168de42415e4efe7388e9fa1f702022f741e60f4
Sha512 cf6c2436bc74dd5934fcbc414fdaf0a423f7c33c68bacaac3842eeded0dcfefc7013dba3256471ddfca4eacc5b03bcd5c3c3c02b4005cc388fd9a08ab5384e15
SSDeep 24576:3oULR4THPSnhaN7LUNaQWfDlFFcMi7SxjTPgZzVj5CMqLF7PjE14Xkv:3oULRiH6gyopfDNcMi7cPyj5CPRjE14U
TLSH EE65D02B2D13A536D7716EBF0C60E0B517686C56A5E4E1063EDEFDAB7C3AE013904352
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CloudSpotter.Properties.Resources.resources
Pu1
[NBF]root.Data
Pun
[NBF]root.Data
WrmN
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
aTqC.exe
Full Name
aTqC.exe
EntryPoint
System.Void CloudSpotter.Program::Main()
Scope Name
aTqC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
aTqC
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
400
Main Method
System.Void CloudSpotter.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CloudSpotter.FormSky::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
aTqC.exe
Full Name
aTqC.exe
EntryPoint
System.Void CloudSpotter.Program::Main()
Scope Name
aTqC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
aTqC
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
400
Main Method
System.Void CloudSpotter.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CloudSpotter.FormSky::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙