Suspicious
Suspect

PE Executable
MD5: 02c5e4adffa842eee1ea0afad63b0781
Size: 965.12 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 02c5e4adffa842eee1ea0afad63b0781
Sha1 3ba118404e4479b2917724f2a230468bf29a0431
Sha256 585f964ab32e7e8b968f4d6f3c8395d757abc7bd22afc3ea04f31fd381fb4c5e
Sha384 2ff2c9cacb609dafb906cc468c02e1ba1cc5ac34d40df27b8b2dbd16c6f0069b5824a6d9a7f658c0a554a13de2edf02c
Sha512 3e02781624bb5224077d3428ead99a5ee1fc45b996e3cadd7de4f050d3dd3cc49ac3f559c53a3c62d6ffc4e9f2291e0e3a442c0b813ef4c2db71059225b0580b
SSDeep 24576:TJpfLN7QN2jXTEXdxyZip/Du7G7sqxoMFM9Dpzb:TJFBc0c/nE7GB/FE5b
TLSH 0B2512A8B668DA02E1F66BF81D71D67443FA2F4E7422D3499ED5ACDF3D247016A00393
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DailyPlanner.MainForm.resources
DailyPlanner.Properties.Resources.resources
mNka
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: KSON.pdb
Module Name
KSON.exe
Full Name
KSON.exe
EntryPoint
System.Void DailyPlanner.Program::Main()
Scope Name
KSON.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KSON
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
294
Main Method
System.Void DailyPlanner.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DailyPlanner.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
KSON.exe
Full Name
KSON.exe
EntryPoint
System.Void DailyPlanner.Program::Main()
Scope Name
KSON.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KSON
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
294
Main Method
System.Void DailyPlanner.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DailyPlanner.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DailyPlanner.MainForm.resources
DailyPlanner.Properties.Resources.resources
mNka
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙