Suspicious
Suspect

c2c4fcaa0b2a62e71056e0d4f7411f9d

PE Executable
MD5: c2c4fcaa0b2a62e71056e0d4f7411f9d
Size: 1.34 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 c2c4fcaa0b2a62e71056e0d4f7411f9d
Sha1 6d2c4dec7124013ede8472a8cc4af34dff96f2f7
Sha256 f37d19918ca9a92945198b23ab4e10be7d681e4aa1f8dfd1b0905482a006e7dd
Sha384 5adda5e2140a191c9bb55166834260a83362866f76b19ce05cf10fa1fc8440fd91caf4d5dba3d04be0603b32336ab58b
Sha512 167afb074882002a667a916f95635caafdaa593f48cae69178e98e12eafdbb99ca1476cf34ea259e7b068291cc65376c86060ee3a0c59a341766705473c511a5
SSDeep 24576:ja6UwZel6gjdS1AWlTePMrP99wVWjy1TvPCL0k:ja69ZQ6ISuqB9iTvPX
TLSH 2055021026EEDA01E4B64FB80872D2B01BB77D996931E20A4EEC3DDFB777B415814792
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GargoyleSculptor.Properties.Resources.resources
Feep
[NBF]root.Data
VJhc
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
xHkE.exe
Full Name
xHkE.exe
EntryPoint
System.Void GargoyleSculptor.Program::Main()
Scope Name
xHkE.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xHkE
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
469
Main Method
System.Void GargoyleSculptor.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void GargoyleSculptor.Program::InitializeData()
nop <null>
newobj System.Void GargoyleSculptor.StudioForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GargoyleSculptor.Properties.Resources.resources
Feep
[NBF]root.Data
VJhc
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙