Suspicious
Suspect

PE Executable
MD5: 06fd98802f4a1353f738a9ecf119d037
Size: 784.9 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 06fd98802f4a1353f738a9ecf119d037
Sha1 2b1a1a3079e786750954360db5174add5dc9648b
Sha256 83ac2145013dfaebbf27d69340996ccc9ccbd9e609dce2b7be58c10f32b29a9b
Sha384 30b073229eef16a7365bfb367d9f53d926bc8bd507bec2ca32d1c86403e8a205e8029ded1dfecd918aabc2a8a2c6ad29
Sha512 d5bd8866725b23e32fb2686120c0c2c7ff0de2e8e5d3179e9f37c50dfa49a7c0003be33275a0e235f810a07cb04846ca3a4dfc346ae133c8e9ab01bd57a8fbfc
SSDeep 12288:+edYCDwRAfzah8Sj9UF6NW/ONGxMUjJXKZpsT8xJ5UZOy8y8/DnR63TZdQx0E6m+:+edY+4mqP060SE8IYNKOly8/1
TLSH 2FF4F09C3215F99FC89795729AA4EE74A2243D6AC306C11386EB5CDFB90CD47DE180F2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsCSharpProject.FormMain.resources
$this.Icon
[NBF]root.IconData
Perl
[NBF]root.Data
candlestickBindingSource.TrayLocation
openFileDialogTicker.TrayLocation
WindowsFormsCSharpProject.Form2.resources
WindowsFormsCSharpProject.Properties.Resources.resources
HmLr
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
crku.exe
Full Name
crku.exe
EntryPoint
System.Void WindowsFormsCSharpProject.Program::Main()
Scope Name
crku.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
crku
Assembly Version
6.8.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
143
Main Method
System.Void WindowsFormsCSharpProject.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void WindowsFormsCSharpProject.Program::‌‌‎‬‬‪‪‏‏​‬‬‮‎‌‮‫‭‫‬​‏‎‪‍‎‎​‫‭‎‮()
ldc.i4.0 <null>
call System.Void WindowsFormsCSharpProject.Program::‍‭‬‎‏‭‬‍‬‭‎‏‮‌‪‭​‮‫‍‫‏‪‮‮‮‮(System.Boolean)
newobj System.Void WindowsFormsCSharpProject.FormMain::.ctor()
call System.Void WindowsFormsCSharpProject.Program::‍‭‪‫‌‎‍‎‬‭‫‏‬‮‬‮‌‏‌‎‮‬‏‫‬‮(System.Windows.Forms.Form)
ret <null>
Module Name
crku.exe
Full Name
crku.exe
EntryPoint
System.Void WindowsFormsCSharpProject.Program::Main()
Scope Name
crku.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
crku
Assembly Version
6.8.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
143
Main Method
System.Void WindowsFormsCSharpProject.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void WindowsFormsCSharpProject.Program::‌‌‎‬‬‪‪‏‏​‬‬‮‎‌‮‫‭‫‬​‏‎‪‍‎‎​‫‭‎‮()
ldc.i4.0 <null>
call System.Void WindowsFormsCSharpProject.Program::‍‭‬‎‏‭‬‍‬‭‎‏‮‌‪‭​‮‫‍‫‏‪‮‮‮‮(System.Boolean)
newobj System.Void WindowsFormsCSharpProject.FormMain::.ctor()
call System.Void WindowsFormsCSharpProject.Program::‍‭‪‫‌‎‍‎‬‭‫‏‬‮‬‮‌‏‌‎‮‬‏‫‬‮(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsCSharpProject.FormMain.resources
$this.Icon
[NBF]root.IconData
Perl
[NBF]root.Data
candlestickBindingSource.TrayLocation
openFileDialogTicker.TrayLocation
WindowsFormsCSharpProject.Form2.resources
WindowsFormsCSharpProject.Properties.Resources.resources
HmLr
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙