Suspicious
Suspect

15609d182759b28e6c2970f777731bee

PE Executable
MD5: 15609d182759b28e6c2970f777731bee
Size: 744.96 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 15609d182759b28e6c2970f777731bee
Sha1 5414ec8b6966b24956153cc6baac8dd93c30da92
Sha256 c6b3670cddf920fc00ea229582ee373eaf17a5aed181b85f8df54a571ddfba64
Sha384 afc08b25406354fdfbc5e8557b18a04e41ab8b7fe007be400f6423da581e87f79afbcefb082e9f5882c4a787712d3f48
Sha512 5024ebc54e541f2bb7a1fef831d16cc0045a4fcf6203b423d2d5b0e6340c68c51eeb65c859936da55d05dc1b99f033bfd70fc54718aeb7f8e75f09ecc6b1873f
SSDeep 12288:+EO3nCWRDz1pVPDuvPvahEwE4qjsGB9PJqmWMzmqTDeJ0LPRxjEL149z4:+RCwDJpwXauwpqDqmWIyJcnw
TLSH FCF4126C3B05E10BEA915B385671F379166DADEDB901C2029FD9AEEBFE37E405D00182
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AyInisAraci.AnaForm.resources
AyInisAraci.Properties.Resources.resources
GWYU
[NBF]root.Data
[NBF]root.Data-preview.png
SR1
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: EfAq.pdb
Module Name
EfAq.exe
Full Name
EfAq.exe
EntryPoint
System.Void AyInisAraci.Program::Main()
Scope Name
EfAq.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
EfAq
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
55
Main Method
System.Void AyInisAraci.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AyInisAraci.AnaForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
EfAq.exe
Full Name
EfAq.exe
EntryPoint
System.Void AyInisAraci.Program::Main()
Scope Name
EfAq.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
EfAq
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
55
Main Method
System.Void AyInisAraci.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AyInisAraci.AnaForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AyInisAraci.AnaForm.resources
AyInisAraci.Properties.Resources.resources
GWYU
[NBF]root.Data
[NBF]root.Data-preview.png
SR1
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙