Suspicious
Suspect

PE Executable
MD5: 16771ad1d7491ef2b9904b844fa9f5bb
Size: 896.01 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 16771ad1d7491ef2b9904b844fa9f5bb
Sha1 183b8eaaa240fa0439ece03c3c4eeefba538b770
Sha256 b5def5a71c2c8f07fa30379346fdd97c89bc77f8fbd5200bc41a3bb13ce4ee4c
Sha384 69d3e7b082ebba928f79a2de6185cd29ff134efc9158177004d7eed8da4b452de8a0775845e7dc978cdb84d8954505b6
Sha512 d2badaf546f2a6eb69498713e1e95874386b21abac8bb2d3d89b1ff8bfb96ec9c5c7c85fbca3e76f153a71b7922e5ba35f01ea37fcb4b83187faa5177082a7b8
SSDeep 12288:qMrX+82k5++6kQ9Y/BfgQ+Pqdez4pqVTwKqwxfmVzkk6QyzBDw6RjOjk5LvkR:v+82N+nQ93VS4s0Vv62BEWisq
TLSH 3315024023F9EB02C0B78BF00574D3B517756E95AA22D31A8EE66CEF3D75B412A09397
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MarcarConsulta.marcaConsulta.resources
bindingNavigatorAddNewItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorDeleteItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveFirstItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveLastItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveNextItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMovePreviousItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
tableBindingNavigatorSaveItem.Image
Project1_Lagrange_Naydanov_I.MainForm.resources
$this.Icon
[NBF]root.IconData
WR
[NBF]root.Data
MarcarConsulta.menu.resources
MarcarConsulta.Properties.Resources.resources
YErb
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xD7600 size 13832 bytes
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\pPxzBELvFq\src\obj\Debug\RZKc.pdb
Module Name
RZKc.exe
Full Name
RZKc.exe
EntryPoint
System.Void MarcarConsulta.Program::Main()
Scope Name
RZKc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
RZKc
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
676
Main Method
System.Void MarcarConsulta.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void MarcarConsulta.menu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
RZKc.exe
Full Name
RZKc.exe
EntryPoint
System.Void MarcarConsulta.Program::Main()
Scope Name
RZKc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
RZKc
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
676
Main Method
System.Void MarcarConsulta.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void MarcarConsulta.menu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MarcarConsulta.marcaConsulta.resources
bindingNavigatorAddNewItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorDeleteItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveFirstItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveLastItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveNextItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMovePreviousItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
tableBindingNavigatorSaveItem.Image
Project1_Lagrange_Naydanov_I.MainForm.resources
$this.Icon
[NBF]root.IconData
WR
[NBF]root.Data
MarcarConsulta.menu.resources
MarcarConsulta.Properties.Resources.resources
YErb
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙