Suspicious
Suspect

ffb2de3bb02b0b895e42f7de29f4071b

PE Executable
MD5: ffb2de3bb02b0b895e42f7de29f4071b
Size: 585.73 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 ffb2de3bb02b0b895e42f7de29f4071b
Sha1 3d4e2b64008ea7feefc4e8a87b3b30701c8c1e1e
Sha256 ed9e2702e14b07eeafe408ab9d66d39abb1700e2f6cf4c175db48d741bd19cf8
Sha384 be5f3ab70dcf47b178060a92b2c5a53ff76518af41066590006485194a9649af17520fb546151cb1c03c59d6f73fe563
Sha512 f8c76e67a0722e8fbed84319cc5b80435b57ddd2438db033e59a256e68be54972120010bd42be2c12361bca2e4deb85b67286a1927623395d9fbe878ba3d5fd2
SSDeep 12288:xfO7xKqXxB/CHfh9sIKqaIzgDLh+2ZeXO4yQZqPbbEKt:U1V/C/hCIBrzELh+2Z14yQ8fv
TLSH 0EC412582305EB07D8A197B84AB1F23917BC2EDDA900D3265FDABDEBB533B054D40297
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HourlyChime.Forms.MainForm.resources
HourlyChime.Properties.Resources.resources
de
[NBF]root.Data
xKwn
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: TFfn.pdb
Module Name
TFfn.exe
Full Name
TFfn.exe
EntryPoint
System.Void HourlyChime.Program::Main()
Scope Name
TFfn.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TFfn
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
174
Main Method
System.Void HourlyChime.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HourlyChime.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
TFfn.exe
Full Name
TFfn.exe
EntryPoint
System.Void HourlyChime.Program::Main()
Scope Name
TFfn.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TFfn
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
174
Main Method
System.Void HourlyChime.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HourlyChime.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HourlyChime.Forms.MainForm.resources
HourlyChime.Properties.Resources.resources
de
[NBF]root.Data
xKwn
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙