Suspicious
Suspect

d01415aa34aca8789632ec7ca8d4b7d1

PE Executable
MD5: d01415aa34aca8789632ec7ca8d4b7d1
Size: 1.14 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 d01415aa34aca8789632ec7ca8d4b7d1
Sha1 e1a505e4df643401a8e432131e61b5b2ea4246e3
Sha256 3d7e662bc64d93a956704e61c3b1b25d0b51db09bea376ee2c5050bd2d121a7a
Sha384 21a4aa40a9efc39dc0e01b4b3137c72c530a0f4b3afcbdebaaf9d0c4b8cedede358c27dd3e68984d2dce4b72ef511e2e
Sha512 86eeb403ea4504df34af378f4ca39ed90378ec5df2e0e34b7c7b45522d19005fe07ab885916e7b3c29b7a77cac834a5c21117d86b19bb32009c269d01a87af6d
SSDeep 24576:QKJWqj0qdPHNKsumh+FMAhg8LKTknGgPhT6g5XPRhHxBoimG:QUFNamhKLhf9nrJ3xBD
TLSH 0B350158A647D803C66693754DE2E2B413B95EEAF400C257AFE87EDB7972F820C44783
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
sURS.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
SourdoughStarter.Properties.Resources.resources
NJ
[NBF]root.Data
h21
[NBF]root.Data
[NBF]root.Data-preview.png
xWud
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Module Name
sURS.exe
Full Name
sURS.exe
EntryPoint
System.Void iH.YZ::pU()
Scope Name
sURS.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
sURS
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
301
Info
PE Detect: PeReader OK (file layout)
Main Method
System.Void iH.YZ::pU()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
nop <null>
newobj System.Void ewL.qwF::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_002B: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0021: call System.Void oIA.aIf::xOn()
call System.Void oIA.aIf::xOn()
br IL_0005: nop
nop <null>
ret <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0015: nop
Module Name
sURS.exe
Full Name
sURS.exe
EntryPoint
System.Void iH.YZ::pU()
Scope Name
sURS.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
sURS
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
301
Main Method
System.Void iH.YZ::pU()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
nop <null>
newobj System.Void ewL.qwF::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_002B: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0021: call System.Void oIA.aIf::xOn()
call System.Void oIA.aIf::xOn()
br IL_0005: nop
nop <null>
ret <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0015: nop
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
sURS.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
SourdoughStarter.Properties.Resources.resources
NJ
[NBF]root.Data
h21
[NBF]root.Data
[NBF]root.Data-preview.png
xWud
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙