Suspicious
Suspect

e8be24aa25aadd26d1553362b154fff3

PE Executable
MD5: e8be24aa25aadd26d1553362b154fff3
Size: 1.65 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 e8be24aa25aadd26d1553362b154fff3
Sha1 99d22eb0fb1b231184bde7b1e8da866c4ef92d0c
Sha256 089c6fa1bc4e09739b603b68c412885ea7818339364f27a41f1b2e250e7fdb8c
Sha384 09e1339f5ab4010d8e2ebf41a1f06262e5b48845e7d6ae9aa4065159de377fccaf4084e5054d67d85978a3eb4f336559
Sha512 3617131b7bfed9cdd22259440e7a7861cf0c83320a472f2f4e8fa2a023b5705fe37648628b3447f5e3613405d2843cfb93c791d867a05dbc48dd92e3eb4dc205
SSDeep 49152:9UsE0XMiGJxw5kOVwflkEEt7ER9Pj6k9:9PEaMiGJxw5jVqlkPtUV6m
TLSH A17522846602C926CA5107341AB1F3F6173D1DDCA101E2239FE9FDEBBA7AE516D842D3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
SpaceFactoryTycoon.AA.resources
SpaceFactoryTycoon.Properties.Resources.resources
TY
[NBF]root.Data
nBuc
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\olDKDlzyXy\src\obj\Debug\lauI.pdb
Module Name
lauI.exe
Full Name
lauI.exe
EntryPoint
System.Void SpaceFactoryTycoon.Program::Main()
Scope Name
lauI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lauI
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
53
Main Method
System.Void SpaceFactoryTycoon.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SpaceFactoryTycoon.UI.MasterControlDesk::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
lauI.exe
Full Name
lauI.exe
EntryPoint
System.Void SpaceFactoryTycoon.Program::Main()
Scope Name
lauI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lauI
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
53
Main Method
System.Void SpaceFactoryTycoon.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SpaceFactoryTycoon.UI.MasterControlDesk::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
SpaceFactoryTycoon.AA.resources
SpaceFactoryTycoon.Properties.Resources.resources
TY
[NBF]root.Data
nBuc
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙