Suspicious
Suspect

0984af427efe1e93c8b0e306f202f378

PE Executable
MD5: 0984af427efe1e93c8b0e306f202f378
Size: 913.41 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 0984af427efe1e93c8b0e306f202f378
Sha1 9a210c9acbc8d10cfc9ba8f3f50a969d185bf68e
Sha256 f49d6efeab5a163ccaff6d8166c0be80e8430d50b4ba7c43df903dbb05bb7bfa
Sha384 9a18b2a8340e084ce523e199d650e6437c836d90a9a94cf19275cd0b80f903ab615ec95ec58cdfd1c793f94c2aeb1098
Sha512 51b5e78409b13ba3e8f1e555bebf2b10ad967cfaf05ad8ba14663db6ff1b63e2242f54d212fe868367bb9ff7a3d520f40faad2a8ae735a6c5be2d76326639f84
SSDeep 24576:77v+tf8KKDwmADU5mzJUfWBWzMxWMI/NG6AGvSTnR:772l8K1zDJJUuczcWMI/NGKun
TLSH B61523580B1EDE03D8821BBC15A0D3752374DD64E801C3338FFE7DEB7969B5929292A6
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
oiMundo.Form1.resources
$this.Icon
[NBF]root.IconData
NI
[NBF]root.Data
oiMundo.Properties.Resources.resources
VCLq
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
bVsC.exe
Full Name
bVsC.exe
EntryPoint
System.Void oiMundo.Program::Main()
Scope Name
bVsC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
bVsC
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
161
Main Method
System.Void oiMundo.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void oiMundo.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
oiMundo.Form1.resources
$this.Icon
[NBF]root.IconData
NI
[NBF]root.Data
oiMundo.Properties.Resources.resources
VCLq
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙