Suspicious
Suspect

dfbcc2ae0c3566aa28b12f119ba1423f

Share on LinkedIn
Print
PE Executable
MD5: dfbcc2ae0c3566aa28b12f119ba1423f
Size: 1.02 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 dfbcc2ae0c3566aa28b12f119ba1423f
Sha1 5cff223a66065afa3601066a4b9dd801e8b6e49e
Sha256 014d90b220ae7333d1811174a381cf9bce2befbc96f3ce66a3266b28aebcc652
Sha384 41a0fc49719dc3b786eac126e384f6da3295673d383fbbd00fcf86f63f5bfc45439421f6c12830777b944833a46baa2f
Sha512 330a43d35632e74f7090390b50fc5514feb454e9fd90a025544a88b02f8a28405ebe8ef1a969786bbb9292d56e4d0b1863b1bba73dea529b07a7077dae6453b9
SSDeep 24576:RQfVaW6Bgn1tbql1wZVo2vSKo/whciHlcV:mIWQgnbbqlYC0SB/mZI
TLSH E2251218568ECA01E6FA17F71E62E37917B17EA6A060E7138FF87CEB7522B059411343
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
.Net Resources
TermiteMound.Properties.Resources.resources
Cringe
[NBF]root.Data
WnLq
[NBF]root.Data
[NBF]root.Data-preview.png
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Module Name
HRHh.exe
Full Name
HRHh.exe
EntryPoint
System.Void TermiteMound.Program::Main()
Scope Name
HRHh.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
HRHh
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
419
Main Method
System.Void TermiteMound.Program::Main()
Main IL Instruction Count
60
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void System.Random::.ctor()
stloc.0 <null>
ldc.i4.0 <null>
stloc.1 <null>
br.s IL_007C: ldloc.1
nop <null>
ldsfld System.Single[] TermiteMound.Program::robitnykyX
ldloc.1 <null>
ldloc.0 <null>
ldc.i4.s 50
ldc.i4 250
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
conv.r4 <null>
stelem.r4 <null>
ldsfld System.Single[] TermiteMound.Program::robitnykyY
ldloc.1 <null>
ldloc.0 <null>
ldc.i4 150
ldc.i4 350
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
conv.r4 <null>
stelem.r4 <null>
ldsfld System.Single[] TermiteMound.Program::robitnykySpeed
ldloc.1 <null>
ldloc.0 <null>
callvirt System.Double System.Random::NextDouble()
ldc.r8 3
mul <null>
ldc.r8 1
add <null>
conv.r4 <null>
stelem.r4 <null>
ldsfld System.Int32[] TermiteMound.Program::robitnykyTunnel
ldloc.1 <null>
ldloc.0 <null>
ldc.i4.0 <null>
ldc.i4.4 <null>
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
stelem.i4 <null>
nop <null>
ldloc.1 <null>
ldc.i4.1 <null>
add <null>
stloc.1 <null>
ldloc.1 <null>
ldc.i4.s 25
clt <null>
stloc.2 <null>
ldloc.2 <null>
brtrue.s IL_0018: nop
newobj System.Void TermiteMound.KupynaForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Info
PE Detect: PeReader OK (file layout)
Module Name
HRHh.exe
Full Name
HRHh.exe
EntryPoint
System.Void TermiteMound.Program::Main()
Scope Name
HRHh.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
HRHh
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
419
Main Method
System.Void TermiteMound.Program::Main()
Main IL Instruction Count
60
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void System.Random::.ctor()
stloc.0 <null>
ldc.i4.0 <null>
stloc.1 <null>
br.s IL_007C: ldloc.1
nop <null>
ldsfld System.Single[] TermiteMound.Program::robitnykyX
ldloc.1 <null>
ldloc.0 <null>
ldc.i4.s 50
ldc.i4 250
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
conv.r4 <null>
stelem.r4 <null>
ldsfld System.Single[] TermiteMound.Program::robitnykyY
ldloc.1 <null>
ldloc.0 <null>
ldc.i4 150
ldc.i4 350
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
conv.r4 <null>
stelem.r4 <null>
ldsfld System.Single[] TermiteMound.Program::robitnykySpeed
ldloc.1 <null>
ldloc.0 <null>
callvirt System.Double System.Random::NextDouble()
ldc.r8 3
mul <null>
ldc.r8 1
add <null>
conv.r4 <null>
stelem.r4 <null>
ldsfld System.Int32[] TermiteMound.Program::robitnykyTunnel
ldloc.1 <null>
ldloc.0 <null>
ldc.i4.0 <null>
ldc.i4.4 <null>
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
stelem.i4 <null>
nop <null>
ldloc.1 <null>
ldc.i4.1 <null>
add <null>
stloc.1 <null>
ldloc.1 <null>
ldc.i4.s 25
clt <null>
stloc.2 <null>
ldloc.2 <null>
brtrue.s IL_0018: nop
newobj System.Void TermiteMound.KupynaForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙