Suspicious
Suspect

d650d8f8c57390f4c39ad0cab2751dc2

PE Executable
MD5: d650d8f8c57390f4c39ad0cab2751dc2
Size: 687.62 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 d650d8f8c57390f4c39ad0cab2751dc2
Sha1 b6e169ff6d28e58a6ee7bcdb037ce95df33a37b5
Sha256 49494f29c02ad372f888b3669595fb189e248b29fcc1d35a3e2be2e57d787fbd
Sha384 124a471d3ff93b602eddc9b00ab0d3373b87f4d35610833932156d1a1d10a44a26dc79d8289bde0367785ebcf8e4c051
Sha512 22767957cad816364eaedd5257eb23a1be66f5a39f5760a3473ed146e93c8b8442592fcf7dd5c2b224a12af4bb0366ab8ce0eeb0033393098c1e2884ffc314b0
SSDeep 12288:1NGxdTDN6jbE7bywYxiLkNQeOVW+nRXmghyFkxAzuN3Xo41GvDKWBh:mVNZfLki0Q2g0I
TLSH 7EE47CAC3240B59FC917C9728AA4ED74A6602CBA530BC20395D71DAFB90DA97DF141F3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Oversee.fAccountProfile.resources
Oversee.Properties.Resources.resources
GFSz
[NBF]root.Data
[NBF]root.Data-preview.png
Oversee.flogin.resources
$this.Icon
[NBF]root.IconData
Resite
[NBF]root.Data
Oversee.fAdmin.resources
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Module Name
inBO.exe
Full Name
inBO.exe
EntryPoint
System.Void Oversee.Program::Main()
Scope Name
inBO.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
inBO
Assembly Version
11.4.7.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Info
PE Detect: PeReader OK (file layout)
Total Strings
3
Main Method
System.Void Oversee.Program::Main()
Main IL Instruction Count
27
Main IL
call System.Void Oversee.Program::‮‎‍‫‮‏‏‏‏‪‏​‮‍‍‍‫‏‎‏‪‫‭‮‮()
ldc.i4 942693249
ldc.i4 208474515
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.4 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0059: ret
ldc.i4.0 <null>
call System.Void Oversee.Program::​​‏‬‭‫‪‫‫‎‏‎‌‬​‫‫‪‫‍‬‍‮(System.Boolean)
ldloc.0 <null>
ldc.i4 -385469191
mul <null>
ldc.i4 185954632
xor <null>
br.s IL_000A: ldc.i4 208474515
newobj System.Void Oversee.flogin::.ctor()
call System.Void Oversee.Program::‬‏‍‎‪‎‌‬​‪‬‭‏‍‌‭‫‌‏‍‪‪‫‌‏‏‮(System.Windows.Forms.Form)
ldloc.0 <null>
ldc.i4 -1761120261
mul <null>
ldc.i4 -2012287400
xor <null>
br.s IL_000A: ldc.i4 208474515
ret <null>
Module Name
inBO.exe
Full Name
inBO.exe
EntryPoint
System.Void Oversee.Program::Main()
Scope Name
inBO.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
inBO
Assembly Version
11.4.7.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
3
Main Method
System.Void Oversee.Program::Main()
Main IL Instruction Count
27
Main IL
call System.Void Oversee.Program::‮‎‍‫‮‏‏‏‏‪‏​‮‍‍‍‫‏‎‏‪‫‭‮‮()
ldc.i4 942693249
ldc.i4 208474515
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.4 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0059: ret
ldc.i4.0 <null>
call System.Void Oversee.Program::​​‏‬‭‫‪‫‫‎‏‎‌‬​‫‫‪‫‍‬‍‮(System.Boolean)
ldloc.0 <null>
ldc.i4 -385469191
mul <null>
ldc.i4 185954632
xor <null>
br.s IL_000A: ldc.i4 208474515
newobj System.Void Oversee.flogin::.ctor()
call System.Void Oversee.Program::‬‏‍‎‪‎‌‬​‪‬‭‏‍‌‭‫‌‏‍‪‪‫‌‏‏‮(System.Windows.Forms.Form)
ldloc.0 <null>
ldc.i4 -1761120261
mul <null>
ldc.i4 -2012287400
xor <null>
br.s IL_000A: ldc.i4 208474515
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Oversee.fAccountProfile.resources
Oversee.Properties.Resources.resources
GFSz
[NBF]root.Data
[NBF]root.Data-preview.png
Oversee.flogin.resources
$this.Icon
[NBF]root.IconData
Resite
[NBF]root.Data
Oversee.fAdmin.resources
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙