Suspicious
Suspect

cd8d560569da4a6c8163f30170085da8

PE Executable
MD5: cd8d560569da4a6c8163f30170085da8
Size: 1.09 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 cd8d560569da4a6c8163f30170085da8
Sha1 387082569ad561ad6e01abfb87d895412850dad2
Sha256 b6a901fba50ca3057ff57f9048da1e23b7ef95170f22902b6d1445e5c2184d8b
Sha384 bf0ddca165645529d527519a5a3b8160412428ac8a30a76dc826c7de6314b51c2995b317722fe0d76bcf6a8af39fc837
Sha512 bb93b7576b11b2fce80a963e0d0a452e6077ef88e585e845057403e13b65196f96eecc83fae23647a410137b91d54a0e9531cefd4e63593680554a128efbd636
SSDeep 24576:vR6pFOdmi6gWk6wcZbxsTUQ2osB5VH3T7Gd0PIPuTowK:Zi7g+WmB3H3T7Gd1g
TLSH 8E3502883246CC02C6A26FF41E70F3B446B95DC4A811E743D6FABDDBB97938A2C552D1
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RhythmClapper.Properties.Resources.resources
RI
[NBF]root.Data
SWJk
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
xhnz.exe
Full Name
xhnz.exe
EntryPoint
System.Void RhythmClapper.Program::Main()
Scope Name
xhnz.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xhnz
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
119
Main Method
System.Void RhythmClapper.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RhythmClapper.YerqForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
xhnz.exe
Full Name
xhnz.exe
EntryPoint
System.Void RhythmClapper.Program::Main()
Scope Name
xhnz.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xhnz
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
119
Main Method
System.Void RhythmClapper.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RhythmClapper.YerqForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RhythmClapper.Properties.Resources.resources
RI
[NBF]root.Data
SWJk
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙