Suspicious
Suspect

d85b23c9ae906be9ecc5e2fe03d19a49

PE Executable
MD5: d85b23c9ae906be9ecc5e2fe03d19a49
Size: 1.05 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 d85b23c9ae906be9ecc5e2fe03d19a49
Sha1 fc830f43a03372668b4643d30df1273298b0d45f
Sha256 5d9d3d0e80ef2f08455bc4c451da1a66853c3ca96e80838b139449460bd63abf
Sha384 612c2f660f636126522930068ccd8c2608fbbd3d244c8eb8f683f5ad749a5494b8effa09f16b590379378dd82c5ed408
Sha512 69c8555233fb6bcc2ae027bd96aa6d6ef58b4de2610a5f9f3f993e0a90d8a795d2b6b244c909d15f2dfe5c2fa2472df5c1d038234f5b47debfa0ca83f1347dce
SSDeep 24576:hMPdqrqjjLh/vLJcDVynKFQaveI22dOyuMsGdxj9rem2S:Lejvxy8yDIY7uo9L
TLSH CB252256B3A8AB16F1BA83FD77D4350053F5BD1A3221D78D9DC523D62AA2F504A30D23
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AirPortStand.ApronForm.resources
AirPortStand.Properties.Resources.resources
abigail
[NBF]root.Data
[NBF]root.Data-preview.png
bbHo
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
vHiO.exe
Full Name
vHiO.exe
EntryPoint
System.Void AirPortStand.Program::Main()
Scope Name
vHiO.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
vHiO
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
485
Main Method
System.Void AirPortStand.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AirPortStand.ApronForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AirPortStand.ApronForm.resources
AirPortStand.Properties.Resources.resources
abigail
[NBF]root.Data
[NBF]root.Data-preview.png
bbHo
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙