Suspicious
Suspect

c83902c8a82924213e2057605d292258

PE Executable
MD5: c83902c8a82924213e2057605d292258
Size: 922.62 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 c83902c8a82924213e2057605d292258
Sha1 e05f50bfff8caa536c02d36ff9387b93db4a3da2
Sha256 7cc79c56e65205f98fdb5c0b1f6e3f3d971cdf0d9ac4dc5678b929c19f1062bb
Sha384 2cc3752bb9e4dae89ee1857939cc87bdaf33ab3f3145c66d83634e2a3aac04cebee4a8850cf155eb743938fe41ee6b10
Sha512 4301c047aceff25ca0d7cb0190a83029a77e76807b744b22f1aaf9022468331d71a2bb8c978eb91726fba09af5f0303d6e6fecd5ed8af004bd932f71a129d5b4
SSDeep 12288:uLrp+4moClH1bzJsDoKx4ri/C61LMMwCzGMJF5rscph3quiqxjJqH6B2JzbE4pZg:ufpx5CR1PyDhquMMhzGMf5L3ziqprb
TLSH AA15BD582617DB37C56177B4D9B3E6F012641E9AE801E23F5AE9BEBB7F31E305900242
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RicePaddy.Properties.Resources.resources
Tissue
[NBF]root.Data
ZYhb
[NBF]root.Data
[NBF]root.Data-preview.png
RicePaddy.SeasonForm.resources
$this.Icon
[NBF]root.IconData
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
LirG.exe
Full Name
LirG.exe
EntryPoint
System.Void RicePaddy.Program::Main()
Scope Name
LirG.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LirG
Assembly Version
1.2.4.7
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
345
Main Method
System.Void RicePaddy.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RicePaddy.PaddyForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
LirG.exe
Full Name
LirG.exe
EntryPoint
System.Void RicePaddy.Program::Main()
Scope Name
LirG.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LirG
Assembly Version
1.2.4.7
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
345
Main Method
System.Void RicePaddy.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RicePaddy.PaddyForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RicePaddy.Properties.Resources.resources
Tissue
[NBF]root.Data
ZYhb
[NBF]root.Data
[NBF]root.Data-preview.png
RicePaddy.SeasonForm.resources
$this.Icon
[NBF]root.IconData
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙