Suspicious
Suspect

d28cd7d8b350a9b7727bf4c07c83d43a

PE Executable
MD5: d28cd7d8b350a9b7727bf4c07c83d43a
Size: 1.12 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 d28cd7d8b350a9b7727bf4c07c83d43a
Sha1 4de7aad0649450daa6c8b1b8d1762690b9feb390
Sha256 babf0d6686c3c6637fe17f6813ea8e2e412d33cdc46f940f2b577ce06a04ed05
Sha384 b5e89e1fcd8972b369cbbc6e6abf3c26e87ae939ec8f7ac80ec7b2f635faf281d02bd5030ba6d69d02c750351f56d83e
Sha512 6508b5a7384eb04c56f71cfff00a80c6ccf6de2a099bbffd2f6b428357799bc82bb82c4c4d67fce048162efd545795afdeeadd48b23aede7897c942d2276a4bf
SSDeep 24576:xSVqkt4mML+Nrqfqz0AQh6ZW/FBHxkpH8eoO5VOtgsmA:uJuRfqz0Ao6+FBRkFVoGVOu3
TLSH DE35E1AC7250F99FC857C9738AA4ED70AA105CAB530BD203D0E71DEBBA0D5979E141F2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PuddleSkipper.Properties.Resources.resources
FrOd
[NBF]root.Data
[NBF]root.Data-preview.png
UDP
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Module Name
Avwx.exe
Full Name
Avwx.exe
EntryPoint
System.Void PuddleSkipper.Program::Main()
Scope Name
Avwx.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Avwx
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Info
PE Detect: PeReader OK (file layout)
Total Strings
0
Main Method
System.Void PuddleSkipper.Program::Main()
Main IL Instruction Count
37
Main IL
nop <null>
ldc.i4 -97179607
ldc.i4 -1892172454
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.5 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0070: ret
call System.Void PuddleSkipper.Program::‍​‍‌‎‪‫‬‬‌‫‍‫‭‎‌‫‭‫‫‬‍‎‮()
nop <null>
ldloc.0 <null>
ldc.i4 -641087670
mul <null>
ldc.i4 1456283506
xor <null>
br.s IL_0006: ldc.i4 -1892172454
ldc.i4.0 <null>
call System.Void PuddleSkipper.Program::‭‭‬‮‏‍‏‭‎‍‪‮‏​‮‫‫‏‬‏‌‮‎‎‫‪‫‬‮(System.Boolean)
nop <null>
newobj System.Void PuddleSkipper.FormSpiel::.ctor()
call System.Void PuddleSkipper.Program::‬‮‭‌‭‬‎‭‎‌‭‮​‮‪​‫​​‌‌‌‫‍‪‮‭‭‮‮(System.Windows.Forms.Form)
ldloc.0 <null>
ldc.i4 -126153584
mul <null>
ldc.i4 -1507997670
xor <null>
br.s IL_0006: ldc.i4 -1892172454
nop <null>
ldloc.0 <null>
ldc.i4 -1007050448
mul <null>
ldc.i4 294736268
xor <null>
br.s IL_0006: ldc.i4 -1892172454
ret <null>
Module Name
Avwx.exe
Full Name
Avwx.exe
EntryPoint
System.Void PuddleSkipper.Program::Main()
Scope Name
Avwx.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Avwx
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
0
Main Method
System.Void PuddleSkipper.Program::Main()
Main IL Instruction Count
37
Main IL
nop <null>
ldc.i4 -97179607
ldc.i4 -1892172454
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.5 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0070: ret
call System.Void PuddleSkipper.Program::‍​‍‌‎‪‫‬‬‌‫‍‫‭‎‌‫‭‫‫‬‍‎‮()
nop <null>
ldloc.0 <null>
ldc.i4 -641087670
mul <null>
ldc.i4 1456283506
xor <null>
br.s IL_0006: ldc.i4 -1892172454
ldc.i4.0 <null>
call System.Void PuddleSkipper.Program::‭‭‬‮‏‍‏‭‎‍‪‮‏​‮‫‫‏‬‏‌‮‎‎‫‪‫‬‮(System.Boolean)
nop <null>
newobj System.Void PuddleSkipper.FormSpiel::.ctor()
call System.Void PuddleSkipper.Program::‬‮‭‌‭‬‎‭‎‌‭‮​‮‪​‫​​‌‌‌‫‍‪‮‭‭‮‮(System.Windows.Forms.Form)
ldloc.0 <null>
ldc.i4 -126153584
mul <null>
ldc.i4 -1507997670
xor <null>
br.s IL_0006: ldc.i4 -1892172454
nop <null>
ldloc.0 <null>
ldc.i4 -1007050448
mul <null>
ldc.i4 294736268
xor <null>
br.s IL_0006: ldc.i4 -1892172454
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PuddleSkipper.Properties.Resources.resources
FrOd
[NBF]root.Data
[NBF]root.Data-preview.png
UDP
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙