Suspicious
Suspect

PE Executable
MD5: f2e786ebcfec5f21c6baef68db875e0e
Size: 690.18 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 f2e786ebcfec5f21c6baef68db875e0e
Sha1 aed99c95830ca1d764581778aa7c740a752bd6c8
Sha256 8d472caf596f0d5c7a9d1fc2bfc371f55eca7016ffe249409da702227f60a0a2
Sha384 5b56472abb4be7455dd8ec76312a3caf193ecd3693b160aa2bf8fbfda2b1fedd0a28fa2672108ca340efce5d82295a39
Sha512 6809777184e33facb068a47a7fad76bb386f989ea28554c1c44512fca1f9242d26ebf4e656b21a2a29a2474bb34df15b2e47dd047ebd9c20c50b652c875f2968
SSDeep 12288:WGNDejs6MvM9lVduhx1uE8kzfBE3YJlCMWoFglUmZY7ZMATU+0o8YD:WGNUFVEx1u2f6kg+t9TTiY
TLSH FDE412253B98C622D8AE67780931D3316379BCACE721E35A8FE9FDE73409BD46900751
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NotepadPlus.Properties.Resources.resources
PIP
[NBF]root.Data
PQwB
[NBF]root.Data
[NBF]root.Data-preview.png
grass
[NBF]root.Data
[NBF]root.Data-preview.png
grass_tile
[NBF]root.Data
[NBF]root.Data-preview.png
grass_tile_2
[NBF]root.Data
[NBF]root.Data-preview.png
t1
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
niss.exe
Full Name
niss.exe
EntryPoint
System.Void NotepadPlus.Program::Main(System.String[])
Scope Name
niss.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
niss
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
203
Main Method
System.Void NotepadPlus.Program::Main(System.String[])
Main IL Instruction Count
52
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NotepadPlus.MainForm::.ctor()
stloc.0 <null>
ldarg.0 <null>
ldlen <null>
ldc.i4.0 <null>
cgt.un <null>
stloc.1 <null>
ldloc.1 <null>
brfalse.s IL_0060: ldloc.0
nop <null>
ldarg.0 <null>
ldc.i4.0 <null>
ldelem.ref <null>
stloc.2 <null>
ldloc.2 <null>
call System.Boolean System.IO.File::Exists(System.String)
stloc.3 <null>
ldloc.3 <null>
brfalse.s IL_005F: nop
nop <null>
nop <null>
ldloc.0 <null>
ldloc.2 <null>
callvirt System.Void NotepadPlus.MainForm::OpenFile(System.String)
nop <null>
nop <null>
leave.s IL_005E: nop
stloc.s ex
nop <null>
ldstr Error opening file: 
ldloc.s ex
callvirt System.String System.Exception::get_Message()
call System.String System.String::Concat(System.String,System.String)
ldstr NotepadPlus
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_005E: nop
nop <null>
nop <null>
ldloc.0 <null>
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
niss.exe
Full Name
niss.exe
EntryPoint
System.Void NotepadPlus.Program::Main(System.String[])
Scope Name
niss.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
niss
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
203
Main Method
System.Void NotepadPlus.Program::Main(System.String[])
Main IL Instruction Count
52
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NotepadPlus.MainForm::.ctor()
stloc.0 <null>
ldarg.0 <null>
ldlen <null>
ldc.i4.0 <null>
cgt.un <null>
stloc.1 <null>
ldloc.1 <null>
brfalse.s IL_0060: ldloc.0
nop <null>
ldarg.0 <null>
ldc.i4.0 <null>
ldelem.ref <null>
stloc.2 <null>
ldloc.2 <null>
call System.Boolean System.IO.File::Exists(System.String)
stloc.3 <null>
ldloc.3 <null>
brfalse.s IL_005F: nop
nop <null>
nop <null>
ldloc.0 <null>
ldloc.2 <null>
callvirt System.Void NotepadPlus.MainForm::OpenFile(System.String)
nop <null>
nop <null>
leave.s IL_005E: nop
stloc.s ex
nop <null>
ldstr Error opening file: 
ldloc.s ex
callvirt System.String System.Exception::get_Message()
call System.String System.String::Concat(System.String,System.String)
ldstr NotepadPlus
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_005E: nop
nop <null>
nop <null>
ldloc.0 <null>
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
nihuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NotepadPlus.Properties.Resources.resources
PIP
[NBF]root.Data
PQwB
[NBF]root.Data
[NBF]root.Data-preview.png
grass
[NBF]root.Data
[NBF]root.Data-preview.png
grass_tile
[NBF]root.Data
[NBF]root.Data-preview.png
grass_tile_2
[NBF]root.Data
[NBF]root.Data-preview.png
t1
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
nihuhuhuhu
f2e786ebcfec5f21c6baef68db875e0e
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙