Suspicious
Suspect

c4637228898b32d3b0f545f8f6abe6fa

PE Executable
MD5: c4637228898b32d3b0f545f8f6abe6fa
Size: 1.11 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 c4637228898b32d3b0f545f8f6abe6fa
Sha1 b85317a6c4bf72076b51a6ed6c6cd401874d48d5
Sha256 6db1729e39bac1b582584c68919f2ab31ea015e7bb6ed5e4b1d2a5bf5b020095
Sha384 bf28541747c2c46d2ca2aacd5cb4173f9697f2d105dfddd3c35b2e75930227fb67be81c36ce26cbaeec5ff044ea1342b
Sha512 7a387a3449015b00cf26fb65a41c1b044268f45aab585fa1ef1f1805969496b344ae1de7b6dfb5a21c8982aff8de144b45b993f3e854a81b88e8e23dce8a9daf
SSDeep 24576:FThRQUotxNsAOYwDX3gI2t00QPkHc8Ik8SrW4x7GH4o:FNuUoBsAOYwDX3gIBD888IFSB7G
TLSH 4035DF542217DB33C462BBB0C933E2F516A45D95E911C23B9AE57DFBBF36E342844282
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AvalancheSlope.FormHang.resources
AvalancheSlope.FormSchneedecke.resources
$this.Icon
[NBF]root.IconData
AvalancheSlope.Properties.Resources.resources
Kare
[NBF]root.Data
UBka
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
xHFb.exe
Full Name
xHFb.exe
EntryPoint
System.Void AvalancheSlope.Program::Main()
Scope Name
xHFb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xHFb
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
323
Main Method
System.Void AvalancheSlope.Program::Main()
Main IL Instruction Count
13
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AvalancheSlope.SchneeDataSet::.ctor()
stloc.0 <null>
ldloc.0 <null>
newobj System.Void AvalancheSlope.FormHang::.ctor(AvalancheSlope.SchneeDataSet)
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
xHFb.exe
Full Name
xHFb.exe
EntryPoint
System.Void AvalancheSlope.Program::Main()
Scope Name
xHFb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xHFb
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
323
Main Method
System.Void AvalancheSlope.Program::Main()
Main IL Instruction Count
13
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AvalancheSlope.SchneeDataSet::.ctor()
stloc.0 <null>
ldloc.0 <null>
newobj System.Void AvalancheSlope.FormHang::.ctor(AvalancheSlope.SchneeDataSet)
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AvalancheSlope.FormHang.resources
AvalancheSlope.FormSchneedecke.resources
$this.Icon
[NBF]root.IconData
AvalancheSlope.Properties.Resources.resources
Kare
[NBF]root.Data
UBka
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙