Suspicious
Suspect

PE Executable
MD5: 0ab08ed23781399e6be793d95d6106d4
Size: 780.29 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 0ab08ed23781399e6be793d95d6106d4
Sha1 d466368c576b27a50e30f542d3235c4c283e70ef
Sha256 3d8d20e3fc6127d5eaf0a70e70e6ec227b9c4c7fee65ef195547ae83db5b18a3
Sha384 e70511cd1b3e3581bc9929ffee5b6081d1d303f8f46c4fb1458f39c874cb4fc0d0a6fa926df57088a29845ec0ce8708f
Sha512 344e9125ad78227b06881a6563a05701dfc69e896044286bd695ddbb39e7f9f12a47169c2c6430a0653fcb55c06fcca5624c1373be81b0811fc6c8fdee81270f
SSDeep 12288:RjhqhqhDCcFx4lYCahLDS/wpiTf2TZOquK13aeGYVuXWwr4Gx8+6sCJ4izidbTRT:RjhqhqhFxc2BDS/t28quKxVGYy/4fdsb
TLSH AFF40169325DBC03C4560EF80930E7BA43B84D5CE419D3E64FFBADEBB9AAB412944153
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DesktopProject.AddEmployee.resources
DesktopProject.DeleteEmployee.resources
$this.Icon
[NBF]root.IconData
DesktopProject.Properties.Resources.resources
Teacher
[NBF]root.Data
kGhg
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\eVKrEeiJbl\src\obj\Debug\dAZD.pdb
Module Name
dAZD.exe
Full Name
dAZD.exe
EntryPoint
System.Void DesktopProject.Program::Main()
Scope Name
dAZD.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dAZD
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
270
Main Method
System.Void DesktopProject.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void DesktopProject.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
dAZD.exe
Full Name
dAZD.exe
EntryPoint
System.Void DesktopProject.Program::Main()
Scope Name
dAZD.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dAZD
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
270
Main Method
System.Void DesktopProject.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void DesktopProject.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DesktopProject.AddEmployee.resources
DesktopProject.DeleteEmployee.resources
$this.Icon
[NBF]root.IconData
DesktopProject.Properties.Resources.resources
Teacher
[NBF]root.Data
kGhg
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙