Suspicious
Suspect

03d937fffd1812da9ba7d282322059eb

PE Executable
MD5: 03d937fffd1812da9ba7d282322059eb
Size: 1.4 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 03d937fffd1812da9ba7d282322059eb
Sha1 39aa99ffe8442ec3ff1918834902abb8398e283d
Sha256 ef99ea97c4c73ddaecd5e1dd916c4ad2be4ad57313df192e245d992f6b6f363d
Sha384 a07a5fec96a5f0a218357ca3cd62f106a5da0cf2b002b0a62842847be016bdfb7049bad8b8d2035f66be1651d3577a4d
Sha512 b2042d8639653bc288f8737eb075ca63242de45f565df5e8cc2a654ec4c859210c35b32e7d7870d912cab243c0dc76be86c41c35f315945782c67fc5334b7776
SSDeep 24576:t07AfxAjt6j0C2wzBFJFhnF4Q7hL8GAaUQYzCxPk75+onR:t0AxAjt64C2wzLJFD4Q7hLm5QW6PC59R
TLSH 305523084542F387DA0A17B11A72F1B11B38AFDAF621F6279EDE3CDB75A9F104C05692
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BirthdayParadox.Forms.MainForm.resources
BirthdayParadox.Properties.Resources.resources
Eat_Other
[NBF]root.Data
[NBF]root.Data-preview.png
Oh
[NBF]root.Data
[NBF]root.Data-preview.png
Sort1
[NBF]root.Data
eWAi
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: hopA.pdb
Module Name
hopA.exe
Full Name
hopA.exe
EntryPoint
System.Void BirthdayParadox.Program::Main()
Scope Name
hopA.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hopA
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
152
Main Method
System.Void BirthdayParadox.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BirthdayParadox.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BirthdayParadox.Forms.MainForm.resources
BirthdayParadox.Properties.Resources.resources
Eat_Other
[NBF]root.Data
[NBF]root.Data-preview.png
Oh
[NBF]root.Data
[NBF]root.Data-preview.png
Sort1
[NBF]root.Data
eWAi
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙