Suspicious
Suspect

cb345182c2482cb19834f6e0bfc0322c

PE Executable
MD5: cb345182c2482cb19834f6e0bfc0322c
Size: 3.78 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 cb345182c2482cb19834f6e0bfc0322c
Sha1 3672751b149d961b1626b0aa2501574e1fddce02
Sha256 b975fc15637a72cb3452655dc5d7ba2d8230bda8a5752c3047eb4c0851c4c372
Sha384 7ca830bb968286a642c10c68f0f3a7bc31779b974201be5cecfda81139c487a3829f68a5db6f8dd8f3922526e6f33d76
Sha512 6a580e26f45b7e3cd345813d7036ba4b307ef42818529e4aeec7c1204a92e0fcf1107e542862b5055b7537030266a8de9c2cc0459a3266203861952a5507cb51
SSDeep 98304:CaE61jWE0WzQVbj/Yt9DHoGjORa/9nYjJe5fWelP/I4lnpHBIx:CajzJzQVf/69dB9noepvBIunph
TLSH A20611182117DB2BC25076B0C932E2F96374DD94D932C36F4AE67DBB7F35AB5A8400A1
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FlaxRetting.Form1.resources
$this.Icon
[NBF]root.IconData
FlaxRetting.Properties.Resources.resources
BZkK
[NBF]root.Data
[NBF]root.Data-preview.png
Btlj
[NBF]root.Data
icons8_customer_26
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_graph_report_50
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_package_64
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_purchase_order_50
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Ijcz.exe
Full Name
Ijcz.exe
EntryPoint
System.Void FlaxRetting.Program::Main()
Scope Name
Ijcz.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Ijcz
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
257
Main Method
System.Void FlaxRetting.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void FlaxRetting.FormHaupt::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FlaxRetting.Form1.resources
$this.Icon
[NBF]root.IconData
FlaxRetting.Properties.Resources.resources
BZkK
[NBF]root.Data
[NBF]root.Data-preview.png
Btlj
[NBF]root.Data
icons8_customer_26
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_graph_report_50
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_package_64
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_purchase_order_50
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙