Suspicious
Suspect

PE Executable
MD5: 1766dfab5b571bc4deef51298430fffc
Size: 103.55 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 1766dfab5b571bc4deef51298430fffc
Sha1 cc37e5e493d4958d9baaddc347b711c391b2cb7f
Sha256 83db39d3dcb2b20724085d4e8c49b8b5e74c2dda134fdce39cfd0f3344fc4cfe
Sha384 f6bc648d2deb2318811af4ef951bb9adf9ffa8392a76da23caa9b701d25d5f2e6f103c2e044cb829a6058ab5e25e0e5d
Sha512 8cc7f5322f326bec7aecd297aa28c08bfa1ace902d36ff305861efdce6f8ba5011a88c2674d56c4ba57ba54c71e65a040d2d983e7cd2913aa195a51abdc90c32
SSDeep 1536:MYxlY23kGwgMBUQGum2U8aVCguHEvQEbFeDVC3woFRKpTdm66:DlY23kg3sguGDFaXmR
TLSH 63A3E1387E862133C67EC1F1A9E6768AABA9212F3191DDCE4C97028518F2F155EC1D1F
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Overlay_b36b7eaa.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
26fc2.resources
1973c.png
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_b36b7eaa.bin (5760 bytes)
Module Name
1.exe
Full Name
1.exe
EntryPoint
System.Void MusicExpress.Program::Main()
Scope Name
1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
1
Assembly Version
1.28.14.52
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
1178
Main Method
System.Void MusicExpress.Program::Main()
Main IL Instruction Count
3
Main IL
newobj System.Void MusicExpress.MusicExpressMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
1.exe
Full Name
1.exe
EntryPoint
System.Void MusicExpress.Program::Main()
Scope Name
1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
1
Assembly Version
1.28.14.52
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
1178
Main Method
System.Void MusicExpress.Program::Main()
Main IL Instruction Count
3
Main IL
newobj System.Void MusicExpress.MusicExpressMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Overlay_b36b7eaa.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
26fc2.resources
1973c.png
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙