Suspicious
Suspect

11df6e112d70c508d9b131e5ec81959c

PE Executable
MD5: 11df6e112d70c508d9b131e5ec81959c
Size: 694.27 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 11df6e112d70c508d9b131e5ec81959c
Sha1 906de277d44063e6d2f5e5e736da6678fc5592ad
Sha256 ce8cdbdac7f2dc6b5b8068a910e3309c97bf897904753447ed842d4fef60cdb6
Sha384 33e70f35afe9ea4be11f8877c2934bc000eca9e599f1e98ccfb2871ac1d69b8f49c5fb956ceb5129ca454ef062a55c3d
Sha512 b3602dd5aa0e1bec0af3ba1df31600a7e80ff8b35846db9c1a8c11ddad5950847afc4ba84444b33a0dc6101b66f059f98bdae738dec470df8d82905141f9613d
SSDeep 12288:a27qbdvnJ5oQK0q3IZZ11ei/eW1SeHFptJfBrbXDqcJPauJwmLYUAdcBh:a27qbFoQU4nTR/eW19pt5ZbucJy9m3A
TLSH F4E41244375ACB06C9A26BF41AB1E27907397D9DE411E2069EE86EFF787BF104C14683
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordLength.Forms.MainForm.resources
WordLength.Properties.Resources.resources
foto
[NBF]root.Data
[NBF]root.Data-preview.png
logo
[NBF]root.Data
scVZ
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: zgUW.pdb
Module Name
zgUW.exe
Full Name
zgUW.exe
EntryPoint
System.Void WordLength.Program::Main()
Scope Name
zgUW.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
zgUW
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
182
Main Method
System.Void WordLength.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WordLength.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordLength.Forms.MainForm.resources
WordLength.Properties.Resources.resources
foto
[NBF]root.Data
[NBF]root.Data-preview.png
logo
[NBF]root.Data
scVZ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙