Suspicious
Suspect

04e3780ff2ce50ea234e2582f08a8cbe

PE Executable
MD5: 04e3780ff2ce50ea234e2582f08a8cbe
Size: 692.74 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 04e3780ff2ce50ea234e2582f08a8cbe
Sha1 f2c86e00695626d5faf226055f52fef19381b84e
Sha256 bdd442200b52bcfa39ba1659915abd75ab8b44c0b6e7b9b47e0bbb9a1c3df99f
Sha384 5bc10cf957e969b4bb7b6673c2da0ec8eca30a340f270530bffc11fc83a7444992ab29c5cc70d764ccc083a5a8a1e2d2
Sha512 bf050e82d7ef7a1967c85e233333b9744945680db8abf5147d5060e05a91f9ba95fd44ecaa473a37c545fb89c324bac7188c2c6c5a346a24985b0583a16f3289
SSDeep 12288:rE+FqbdvnJ58d22uceDduAvXr82nIWaDQHcv/3feAxe951/KnssbsGmt:rE+FqbFGucnpiPHLqk51QHbsJt
TLSH 98E401942B41EB11C9A1A7B54971E23C173DAE9DF921E2431FDC7EEF78AAB014C54283
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordLength.Forms.MainForm.resources
WordLength.Properties.Resources.resources
foto
[NBF]root.Data
[NBF]root.Data-preview.png
logo
[NBF]root.Data
pars
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: IrIF.pdb
Module Name
IrIF.exe
Full Name
IrIF.exe
EntryPoint
System.Void WordLength.Program::Main()
Scope Name
IrIF.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
IrIF
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
182
Main Method
System.Void WordLength.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WordLength.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordLength.Forms.MainForm.resources
WordLength.Properties.Resources.resources
foto
[NBF]root.Data
[NBF]root.Data-preview.png
logo
[NBF]root.Data
pars
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙