Suspicious
Suspect

e9a760bdd778e40a7ec3aa6d9e9861cc

PE Executable
MD5: e9a760bdd778e40a7ec3aa6d9e9861cc
Size: 1.58 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 e9a760bdd778e40a7ec3aa6d9e9861cc
Sha1 289ca4cc16975ca20a024738587fc7b8a345ce32
Sha256 22929fd615674a4e46fa8d2f845b19675d0328c687a136cd847a1f2411dd84d4
Sha384 792fe1dc5bc1a7f8aa01de6fe736c09fba6c1ff1419815a91a47b95fcdf94abbbd7f156c914971180ddda97295cad22e
Sha512 30b3f2fe20dd7d64d123f294fadf14f342de1b57a49ef5ff66767b9a125b98a5b11828a63d9d395895f090fa6c32428028a4533e82117f9a49a9ab6fec48e85f
SSDeep 24576:vrWJTM4XPk75bGqtlgjKOTP4/kKq21xldge/Vv7c1czsPBKelcynMyTJCi5:vrAPXPk75bG+CJP4M0D9bsMeCqMKJ
TLSH 1B7523AC5452FA12CE981BB857A4F2B267BD0DAA3400D152CFCDBFEBFD657184C58092
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BalanceBoard.Properties.Resources.resources
Fec
[NBF]root.Data
Voxe
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
oIzO.exe
Full Name
oIzO.exe
EntryPoint
System.Void BalanceBoard.Program::Main()
Scope Name
oIzO.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oIzO
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
82
Main Method
System.Void BalanceBoard.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BalanceBoard.KhaghDzev::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
oIzO.exe
Full Name
oIzO.exe
EntryPoint
System.Void BalanceBoard.Program::Main()
Scope Name
oIzO.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oIzO
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
82
Main Method
System.Void BalanceBoard.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BalanceBoard.KhaghDzev::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BalanceBoard.Properties.Resources.resources
Fec
[NBF]root.Data
Voxe
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙