Suspicious
Suspect

PE Executable
MD5: 0dcfa83bc32f60d83428021a250188c8
Size: 773.12 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 0dcfa83bc32f60d83428021a250188c8
Sha1 7ba29e7e52fcc373524e25ff25d3de41bb55e6cb
Sha256 a1a9a1eb021b4358e6585bd24332ec331ab91973b4286eee6f82f778997bfc33
Sha384 bdd4d63614852054d8519412e507a35fa7aec002daac0f84ede70ae1e19d0118d81a618e6224f14524336becdf754bc0
Sha512 e4d478298544bbf3788360353a76058da55cae3c6b93e0e64304743f2457b3c0828f847572ca05a5c4eb66391a31b11dd7c763ed26bf65bc6ef06e60f6dc007c
SSDeep 12288:BNbrQ6Qcx6983rZVlISB7TnUu+jKd0NLaDZ8SDuq2+xaxBtH6D/:vfMYrZVF5TnuK05aDZBfTxQBtH6
TLSH 84F4F0A712DBF932F4B6E6750861F2F822BC5DB2540393024ADB7F973D362B865021D6
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Ping_Pong.Form1.resources
$this.Icon
[NBF]root.IconData
nch
[NBF]root.Data
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
timer1.TrayLocation
ListingMatcher.Properties.Resources.resources
mVkg
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: AvPx.pdb
Module Name
AvPx.exe
Full Name
AvPx.exe
EntryPoint
System.Void ListingMatcher.Program::Main()
Scope Name
AvPx.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
AvPx
Assembly Version
1.8.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
58
Main Method
System.Void ListingMatcher.Program::Main()
Main IL Instruction Count
22
Main IL
nop <null>
newobj System.Void Ping_Pong.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ldstr products.txt
call System.Collections.Generic.List`1<ListingMatcher.Product> ListingMatcher.JsonIO::JsonDeserialize<ListingMatcher.Product>(System.String)
stloc.0 <null>
ldstr listings.txt
call System.Collections.Generic.List`1<ListingMatcher.Listing> ListingMatcher.JsonIO::JsonDeserialize<ListingMatcher.Listing>(System.String)
stloc.1 <null>
ldloc.0 <null>
ldloc.1 <null>
call System.Collections.Generic.List`1<ListingMatcher.Result> ListingMatcher.Matcher::FindProductToListingMatching(System.Collections.Generic.List`1<ListingMatcher.Product>,System.Collections.Generic.List`1<ListingMatcher.Listing>)
stloc.2 <null>
ldloc.2 <null>
call System.String[] ListingMatcher.JsonIO::JsonSerialize<ListingMatcher.Result>(System.Collections.Generic.List`1<ListingMatcher.Result>)
stloc.3 <null>
ldstr results.txt
ldloc.3 <null>
call System.Void System.IO.File::WriteAllLines(System.String,System.String[])
nop <null>
ret <null>
Module Name
AvPx.exe
Full Name
AvPx.exe
EntryPoint
System.Void ListingMatcher.Program::Main()
Scope Name
AvPx.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
AvPx
Assembly Version
1.8.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
58
Main Method
System.Void ListingMatcher.Program::Main()
Main IL Instruction Count
22
Main IL
nop <null>
newobj System.Void Ping_Pong.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ldstr products.txt
call System.Collections.Generic.List`1<ListingMatcher.Product> ListingMatcher.JsonIO::JsonDeserialize<ListingMatcher.Product>(System.String)
stloc.0 <null>
ldstr listings.txt
call System.Collections.Generic.List`1<ListingMatcher.Listing> ListingMatcher.JsonIO::JsonDeserialize<ListingMatcher.Listing>(System.String)
stloc.1 <null>
ldloc.0 <null>
ldloc.1 <null>
call System.Collections.Generic.List`1<ListingMatcher.Result> ListingMatcher.Matcher::FindProductToListingMatching(System.Collections.Generic.List`1<ListingMatcher.Product>,System.Collections.Generic.List`1<ListingMatcher.Listing>)
stloc.2 <null>
ldloc.2 <null>
call System.String[] ListingMatcher.JsonIO::JsonSerialize<ListingMatcher.Result>(System.Collections.Generic.List`1<ListingMatcher.Result>)
stloc.3 <null>
ldstr results.txt
ldloc.3 <null>
call System.Void System.IO.File::WriteAllLines(System.String,System.String[])
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Ping_Pong.Form1.resources
$this.Icon
[NBF]root.IconData
nch
[NBF]root.Data
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
timer1.TrayLocation
ListingMatcher.Properties.Resources.resources
mVkg
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙