Suspicious
Suspect

PE Executable
MD5: 06e2f6e165a91855b2a462a6cc24be51
Size: 883.71 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 06e2f6e165a91855b2a462a6cc24be51
Sha1 0fdc7c38ee15cce7d882f2c82843a82de85ad32d
Sha256 a666d2038b960b6dc3399f02409739c56ee999ff20ff2eb58f8b8e9543943c7e
Sha384 a16bd30deca3ac717b629fc1dcac8c53892584d18caef007e601a085d04961140c77046a4da4dfdd9328a7f8946a132f
Sha512 779d73ef9a1c7f9c5f49f765a5f58585105361392d3b3d29442657c9a8d8529a7d2b612ba31c85c0fc223c98287c873b70431fe8450a72df47b12e67024f8f82
SSDeep 24576:ikxzAjUjORf43sLMEVMDYljRwLrQ4zyg:ik5R3TkljRwLd
TLSH 9615F1817399DD46E8A61BF40C35D6B003B5BE9DA461C20E0DEB3DEF78B2B8115A2747
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EventTracker.Forms.MainForm.resources
EventTracker.Properties.Resources.resources
AUDI
[NBF]root.Data
JAuY
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: WzAx.pdb
Module Name
WzAx.exe
Full Name
WzAx.exe
EntryPoint
System.Void EventTracker.Program::Main()
Scope Name
WzAx.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
WzAx
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
507
Main Method
System.Void EventTracker.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void EventTracker.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
WzAx.exe
Full Name
WzAx.exe
EntryPoint
System.Void EventTracker.Program::Main()
Scope Name
WzAx.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
WzAx
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
507
Main Method
System.Void EventTracker.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void EventTracker.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EventTracker.Forms.MainForm.resources
EventTracker.Properties.Resources.resources
AUDI
[NBF]root.Data
JAuY
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙