Suspicious
Suspect

de568d8e0106a2dac076077eb97a5614

PE Executable
MD5: de568d8e0106a2dac076077eb97a5614
Size: 349.7 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 de568d8e0106a2dac076077eb97a5614
Sha1 da2554552af2eab641cef1410ef999552dfd1d4c
Sha256 6248ec3495d5d099d62d99806e583d487df327ccff205a272122965ebb3db042
Sha384 e87faa77b893959811d47818d0dc46a3509d1c285c22f0af0840737221c49576c37a19f696e1bfdfb26f0f1adb4fe081
Sha512 0e2987f60603f1eeb702d9a8fa44b627413ceba74c1c28321f1a19d4fb04be7f74500b7af856ac20a4dd39704e2dead23fca51e9a9c8cdcecf812085384f3497
SSDeep 6144:ZvudWpFh/Nu6iBo+SCVW0sR5E9u0rDgVV+poMrE44eFDmyUH/uJhhhhhhhhhhYik:tnnh/Nb+zVW0U5EQQ5wyzUHGJhhhhhhy
TLSH C8743B2162B31F71E6584AF790ED8080077AC27D9EFBFF29904F67BCAD02355A613952
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
.Net Resources
17i1pYF2ICkN3On0UL.XJQqbdlOIYd1xEMuX3
VZrTENovM7KcprXSFtN.v5xIaDo10te9yooy9dp.resources
label1.DefaultModifiers
$this.Icon
[NBF]root.IconData
tabPage2.GridSize
openFileDialog1.Location
$this.Language
toolTip1.Location
Pi35YPpNBcaICMaWCc.uR68AB0JqkhZ4aOWlw.resources
fo0D.resources
fo0D
SbN0yEu1OUUqgCgIbu.tytkCeIoNhA4A51iQO
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
Overlay_9e688c58.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Module Name
Noogen.Validation.dll
Full Name
Noogen.Validation.dll
Scope Name
Noogen.Validation.dll
Scope Type
ModuleDef
Kind
Dll
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Noogen.Validation
Assembly Version
12.7.5.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
45
Main Method
Not found or no body
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_9e688c58.bin (1 bytes)
Module Name
Noogen.Validation.dll
Full Name
Noogen.Validation.dll
Scope Name
Noogen.Validation.dll
Scope Type
ModuleDef
Kind
Dll
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Noogen.Validation
Assembly Version
12.7.5.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
45
Main Method
Not found or no body
.Net Resources
17i1pYF2ICkN3On0UL.XJQqbdlOIYd1xEMuX3
VZrTENovM7KcprXSFtN.v5xIaDo10te9yooy9dp.resources
label1.DefaultModifiers
$this.Icon
[NBF]root.IconData
tabPage2.GridSize
openFileDialog1.Location
$this.Language
toolTip1.Location
Pi35YPpNBcaICMaWCc.uR68AB0JqkhZ4aOWlw.resources
fo0D.resources
fo0D
SbN0yEu1OUUqgCgIbu.tytkCeIoNhA4A51iQO
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
Overlay_9e688c58.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙