Suspicious
Suspect

fbaaa07e5bcb9b692d1a90d426bef18b

PE Executable
MD5: fbaaa07e5bcb9b692d1a90d426bef18b
Size: 1.08 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 fbaaa07e5bcb9b692d1a90d426bef18b
Sha1 6e21df4978928acfb4a6a6cffced2ff826d39934
Sha256 55ea55d00c35618218783fa8b647a760a7876eaa9fad2d30dddee8600b15895a
Sha384 0d0b26b3910f6789253e3b3a420542a8da8a046f479386e1806cde0dc540791fd5047d87c1f33e76ac97be4f12994851
Sha512 b5f8f1f501b5e2ae297f57de36e96187b7f59a2f1d3e1be59995fbafe2fffdcc29e74b812e597bdaec0cc8c8c7e4966e95d98f21eec1c64e0d8614b0b6493999
SSDeep 24576:dwoWEkiboo8ikR5SXN405NA3RiFXODl3MA:JWEnbooTkHS9ZAA9ODlc
TLSH D53512296B6AC712E8A91BB508B4F37503B51E4EFA20D3458FFDACDB3411F066849793
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CormorantColony.Properties.Resources.resources
DWad
[NBF]root.Data
[NBF]root.Data-preview.png
critsh
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
aLUc.exe
Full Name
aLUc.exe
EntryPoint
System.Void CormorantColony.Programme::Main()
Scope Name
aLUc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
aLUc
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
227
Main Method
System.Void CormorantColony.Programme::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CormorantColony.Vues.FormPrincipale::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CormorantColony.Properties.Resources.resources
DWad
[NBF]root.Data
[NBF]root.Data-preview.png
critsh
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙