Suspicious
Suspect

Revised Proforma Invoice8268001.exe

PE Executable
MD5: 070990c15f9e332a72962db22fb227af
Size: 1.24 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 070990c15f9e332a72962db22fb227af
Sha1 32b2e84d4156ea97889af4325cf0de5d9ea5b221
Sha256 c706b4916bbdcd3fd321932aa497d4680fcaee1c2b18c53e2642cb5658e08a3d
Sha384 71b3db55591af33926e0443ef5f2b2cadeef997744795a81bb8648d2e1c6999505bb338e15d5a10cb045e9462b6f8624
Sha512 5fac8091a3a102d8fc637b1e62ebbbc4b2f062fbe4a7bc78e144eb9b15089f410b2734c57f82aa82ac3a6bd9189c8ccf07ecf4d41b6e8fb70017fe20c8663ed3
SSDeep 24576:spcgn4Hi6H2CuaJ+VECiLH+hTo53lP/lr78oFaByrL9pcVxTsy3:C4CTCjcVECiySZJ/hpIyrL9pCR3
TLSH 42452254A77CEF02F0E22BF02678D0B427B5BD9D9829C24A4ED47CDFB4A1B050A91797
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MazeSolver.Formularios.FormPrincipal.resources
MazeSolver.Properties.Resources.resources
Fast_Tot
[NBF]root.Data
[NBF]root.Data-preview.png
oO
[NBF]root.Data
[NBF]root.Data-preview.png
rgKk
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x12BC00 size 13832 bytes
Info
PDB Path: hWRZ.pdb
Module Name
hWRZ.exe
Full Name
hWRZ.exe
EntryPoint
System.Void MazeSolver.Program::Main()
Scope Name
hWRZ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hWRZ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
319
Main Method
System.Void MazeSolver.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void MazeSolver.Formularios.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
hWRZ.exe
Full Name
hWRZ.exe
EntryPoint
System.Void MazeSolver.Program::Main()
Scope Name
hWRZ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hWRZ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
319
Main Method
System.Void MazeSolver.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void MazeSolver.Formularios.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MazeSolver.Formularios.FormPrincipal.resources
MazeSolver.Properties.Resources.resources
Fast_Tot
[NBF]root.Data
[NBF]root.Data-preview.png
oO
[NBF]root.Data
[NBF]root.Data-preview.png
rgKk
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙