Suspicious
Suspect

faee13c66726df7a224cba552a0f1b2a

PE Executable
MD5: faee13c66726df7a224cba552a0f1b2a
Size: 998.4 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 faee13c66726df7a224cba552a0f1b2a
Sha1 b5ad2a263bcc3c1d6282067a649e2d14ec2cbbd6
Sha256 87d0be38269a7c3ac7cc71b87c7f9cbfddb60cfb287b30840564ebe70418a73e
Sha384 ae261c4004df5fefacdfd3cac78a47e0487a83894040e4fea50de1cd65f812189ba70c499f7fd7f9eae74f9030b51aef
Sha512 30554171cb9003d1aeb7984ccebb078a16d9c99a7d4cfdf07e2f5b3676d00644008ccedf4786a6eddc00d109076fad5f00ec0cae082bc8d33b73512650bd3daa
SSDeep 24576:oU3e4O66AHgRsSGnMT+EWpT5WRy7vTr3xahuOcszGTpjgZmsm:oa3gGDBp9WRen3D9szGdj3
TLSH D42512696755DF12E4F94BF11832E33003B16CEDA916C3168FEADEEB3521B0D68486D2
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TideWhistle.Properties.Resources.resources
QuAW
[NBF]root.Data
[NBF]root.Data-preview.png
UDP
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Module Name
BmNp.exe
Full Name
BmNp.exe
EntryPoint
System.Void TideWhistle.Program::Main()
Scope Name
BmNp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
BmNp
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
322
Info
PE Detect: PeReader OK (file layout)
Main Method
System.Void TideWhistle.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TideWhistle.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TideWhistle.Properties.Resources.resources
QuAW
[NBF]root.Data
[NBF]root.Data-preview.png
UDP
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙