Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 1c1f15a713a56ec6590bd32a4f5f0437
Size: 570.88 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 1c1f15a713a56ec6590bd32a4f5f0437
Sha1 3acc806959f1524aa84317f200ef86eb5ed8523a
Sha256 aa2d17f2af1fcc37424c29d0c49be04f29c4c94dcbe089ddc36037e4b6b5b3b8
Sha384 b2fa36f6e29aeee5d4cddc9c1c52bfe98f1be664ca1573b2588e5fde379ac5b7eeb5e93acd8d4346c12f110130cd36c4
Sha512 1b41b7658988e9e98f41562b07c67608475464a301e265aa09e54e23e42a9ce920b9a91984927eaf5447b6fd5fd965541fa7f0438d7f58f68aae8396e831c13a
SSDeep 12288:LK390Rk1Fh9pkRW10cLyWuqTi2jMh4nlxESZeAsLA6kKX:e34w/f0cLy9cjTlxEShsk6kK
TLSH 43C4E12471B9CC06CA5D833C59B3F17803B9DE89A612C31E9FD47EAFB9697911E011A3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GroupBoxDemo.ContentView.resources
GroupBoxDemo.Form1.resources
$this.Icon
[NBF]root.IconData
HQ
[NBF]root.Data
GroupBoxDemo.Form2.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
GroupBoxDemo.Properties.Resources.resources
sTIk
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
DHcE.exe
Full Name
DHcE.exe
EntryPoint
System.Void GroupBoxDemo.Program::Main()
Scope Name
DHcE.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DHcE
Assembly Version
4.2.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
122
Main Method
System.Void GroupBoxDemo.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void GroupBoxDemo.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
DHcE.exe
Full Name
DHcE.exe
EntryPoint
System.Void GroupBoxDemo.Program::Main()
Scope Name
DHcE.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DHcE
Assembly Version
4.2.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
122
Main Method
System.Void GroupBoxDemo.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void GroupBoxDemo.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
PDB Path PATH
DHhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙