Suspicious
Suspect

f0086648781eb64e6463396158674e31

PE Executable
MD5: f0086648781eb64e6463396158674e31
Size: 1.24 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 f0086648781eb64e6463396158674e31
Sha1 fabe324fcf6f9648169d1652d38c37a352d3781d
Sha256 52dd2fa8b7e7460a5776bbb41c234d66efb7fcb781baac45cd92fc92bea29189
Sha384 4ec7e712aef77e087fcd76c6364ffb85f0ce42014d294fef0d7e977711c7e26047b41401f0ebca92d1219a158ceda2d9
Sha512 d4e9818aa6c817078e4f3fdb8d943a39f5c4cabb21bc40b34f68a1afe99df05baa4290b095fe6734b972dd007c1e60e2c6a4536721b524e98b7d4a52131d16c1
SSDeep 24576:T5SRHYK109Nbnhg+3hxbnY9tN2IBFXdKgEROA8tR:TgF510fbzPEEk
TLSH 9945E19C3600F88FC853CE758D64EEB4AA202DB6970BD30395E72DAFB91D5579E041E2
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SkiLift.Properties.Resources.resources
Kare
[NBF]root.Data
kTHt
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
ARza.exe
Full Name
ARza.exe
EntryPoint
System.Void SkiLift.Program::Main()
Scope Name
ARza.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ARza
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
1
Main Method
System.Void SkiLift.Program::Main()
Main IL Instruction Count
25
Main IL
nop <null>
call System.Void SkiLift.Program::​‭‭‪‭‪‭‬‮‌‍​‭‮‏‌​‫​‍‎‫‮‫‬‏‎‫‍‎‮()
nop <null>
ldc.i4.0 <null>
call System.Void SkiLift.Program::​‍‪​‪‭‮‭‫‍​‌‌‏‎‍‭‭‭‍‭‏‬‏‫‫‮‭‮(System.Boolean)
ldc.i4 901531447
ldc.i4 1505422789
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.3 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_003F: newobj System.Void SkiLift.HirskyiForm::.ctor()
nop <null>
ldloc.0 <null>
ldc.i4 -1950469760
mul <null>
ldc.i4 -2001874510
xor <null>
br.s IL_0012: ldc.i4 1505422789
newobj System.Void SkiLift.HirskyiForm::.ctor()
call System.Void SkiLift.Program::‭‏‌‏‫‬‏‭‬‎‌‭‍‏‏‫‭​‌‪‍‮(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SkiLift.Properties.Resources.resources
Kare
[NBF]root.Data
kTHt
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙