Suspicious
Suspect

PE Executable
MD5: 09dc5d97ed6e2f14c4be7f1846957ee7
Size: 714.24 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 09dc5d97ed6e2f14c4be7f1846957ee7
Sha1 2f1023c338f81e044c542ea5097eb69782146a5b
Sha256 3bbe94e388c5e4d74cbf909acffeb608904eca5cc548b89262dfc135dd86ea83
Sha384 50236e2875e3022eec89d919aa7d29c672a45058f89e37dcfea27b8723a01327744bcefeca4827ee93db441cb3be9bac
Sha512 92a81cbf47de6cb51776b14dc3a16c4c267053a98681015ee180d3d171df6c153ae8fb652e22c7be1283cee2d7a33c6c8dbeb293a756cc448b40f07c6cfeb2de
SSDeep 12288:X5L2iNgbpO0M39yBBuxAwYrHFvlpPDzemmTCahQYDOq0D8pgCUiYZAlRu9:d1Obk0M3QfzebhQCVrrllQ9
TLSH 83E4E164A3D4DD66C3E843756921E27DD2688DABA134C352FACEBD973F367022013267
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CacPhepTinhTrenPhanSo.AboutBox1.resources
logoPictureBox.Image
[NBF]root.Data
[NBF]root.Data-preview.png
CacPhepTinhTrenPhanSo.Form1.resources
$this.Icon
[NBF]root.IconData
cgi
[NBF]root.Data
CacPhepTinhTrenPhanSo.Properties.Resources.resources
KuKV
[NBF]root.Data
[NBF]root.Data-preview.png
BookStore.csdl
BookStore.msl
BookStore.ssdl
Name Value
Module Name
nltc.exe
Full Name
nltc.exe
EntryPoint
System.Void CacPhepTinhTrenPhanSo.Program::Main()
Scope Name
nltc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
nltc
Assembly Version
2.8.5.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
142
Main Method
System.Void CacPhepTinhTrenPhanSo.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void CacPhepTinhTrenPhanSo.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CacPhepTinhTrenPhanSo.AboutBox1.resources
logoPictureBox.Image
[NBF]root.Data
[NBF]root.Data-preview.png
CacPhepTinhTrenPhanSo.Form1.resources
$this.Icon
[NBF]root.IconData
cgi
[NBF]root.Data
CacPhepTinhTrenPhanSo.Properties.Resources.resources
KuKV
[NBF]root.Data
[NBF]root.Data-preview.png
BookStore.csdl
BookStore.msl
BookStore.ssdl
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙