Suspicious
Suspect

cbb907d008c300b1ba66d760d71263a8

PE Executable
MD5: cbb907d008c300b1ba66d760d71263a8
Size: 12.07 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 cbb907d008c300b1ba66d760d71263a8
Sha1 fc957170cafa2c8b35acefd858ec2530b52a407f
Sha256 329cb3582506bc7b7da039b4f75ea2a2ccdb45f8b8ad6817fd52fbe2e975b0e8
Sha384 c9f60eb962218919c48e220d4e7edbe0a66ee637cc4538a46beab6d609847b2683aa027267fda93a1002246cc7dfa0cc
Sha512 83af53a34337d73a3081b582c6153c773a43e7aa28bb748ebb1731c8a9da6b7fbe48475a5e884bc90534c33f49de33867e9a531b9159a7ea1a8fabfad3eb9fff
SSDeep 196608:KyNHSFPZDFrMFipIjAPbRNrFO647KW2xXyvNbHkp+FQpDfynl8jxkOWlpRmYagg:Kky7FrM4/dS37kXSNbEDpDNxEP4Yagg
TLSH F0C6332DDEE8D901CAE82B739263D178D170DE81EA1F8964C1F77E833D1D13625607AA
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
NetworkSniffer.Properties.Resources.resources
Khyd
[NBF]root.Data
[NBF]root.Data-preview.png
UDP
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\fOImnGTmyV\src\obj\Debug\kjrN.pdb
Module Name
kjrN.exe
Full Name
kjrN.exe
EntryPoint
System.Void NetworkSniffer.Program::Main()
Scope Name
kjrN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kjrN
Assembly Version
7.6.4.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
134
Main Method
System.Void NetworkSniffer.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NetworkSniffer.MainUI::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
NetworkSniffer.Properties.Resources.resources
Khyd
[NBF]root.Data
[NBF]root.Data-preview.png
UDP
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙