Suspicious
Suspect

eb9656a9ac3dffcfc1677194a67a0279

PE Executable
MD5: eb9656a9ac3dffcfc1677194a67a0279
Size: 798.21 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 eb9656a9ac3dffcfc1677194a67a0279
Sha1 0987466ea2c57cd3b520ef025ed97ece71622ff3
Sha256 dc42da3571e4f907f456b2edb0b0ce4b22a66adc2f2c4d006b0c40ccdf69df77
Sha384 f06c0826bedc8e81d41d77f8280cbcd8623de6ceca25746d9914c3dcfef530fabf964f2a1cc160e88a87306f30429f3e
Sha512 9305d688968045915994101244216f0e74f58f08d3b03ee7625b30b37491fa48edd1a41bc4f00443655e29690789690baf82b7525c68c8b8d5810e43f3a718bb
SSDeep 24576:BSpU6nePRa5SDP4iySRZgstup1ytrdj+Ati/:f45U4BotiaJ+c
TLSH D405027C974AD802ED8247B50A65D3B512709F9CF512C363CBF8FDD77A36B6A2848281
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
SynthStudio.UI.MasterStudioDesk.resources
$this.Icon
[NBF]root.IconData
Zeri
[NBF]root.Data
SynthStudio.Properties.Resources.resources
zahN
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\HaARjsgmTe\src\obj\Debug\OSFm.pdb
Module Name
OSFm.exe
Full Name
OSFm.exe
EntryPoint
System.Void SynthStudio.Program::Main()
Scope Name
OSFm.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
OSFm
Assembly Version
8.4.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
140
Main Method
System.Void SynthStudio.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void SynthStudio.UI.MasterStudioDesk::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
OSFm.exe
Full Name
OSFm.exe
EntryPoint
System.Void SynthStudio.Program::Main()
Scope Name
OSFm.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
OSFm
Assembly Version
8.4.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
140
Main Method
System.Void SynthStudio.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void SynthStudio.UI.MasterStudioDesk::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
SynthStudio.UI.MasterStudioDesk.resources
$this.Icon
[NBF]root.IconData
Zeri
[NBF]root.Data
SynthStudio.Properties.Resources.resources
zahN
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙