Suspicious
Suspect

c2c4fcaa0b2a62e71056e0d4f7411f9d

Share on LinkedIn
Print
PE Executable
MD5: c2c4fcaa0b2a62e71056e0d4f7411f9d
Size: 1.34 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 c2c4fcaa0b2a62e71056e0d4f7411f9d
Sha1 6d2c4dec7124013ede8472a8cc4af34dff96f2f7
Sha256 f37d19918ca9a92945198b23ab4e10be7d681e4aa1f8dfd1b0905482a006e7dd
Sha384 5adda5e2140a191c9bb55166834260a83362866f76b19ce05cf10fa1fc8440fd91caf4d5dba3d04be0603b32336ab58b
Sha512 167afb074882002a667a916f95635caafdaa593f48cae69178e98e12eafdbb99ca1476cf34ea259e7b068291cc65376c86060ee3a0c59a341766705473c511a5
SSDeep 24576:ja6UwZel6gjdS1AWlTePMrP99wVWjy1TvPCL0k:ja69ZQ6ISuqB9iTvPX
TLSH 2055021026EEDA01E4B64FB80872D2B01BB77D996931E20A4EEC3DDFB777B415814792
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GargoyleSculptor.Properties.Resources.resources
Feep
[NBF]root.Data
VJhc
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
xHkE.exe
Full Name
xHkE.exe
EntryPoint
System.Void GargoyleSculptor.Program::Main()
Scope Name
xHkE.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xHkE
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
469
Main Method
System.Void GargoyleSculptor.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void GargoyleSculptor.Program::InitializeData()
nop <null>
newobj System.Void GargoyleSculptor.StudioForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙