Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 211013cfdb48e16e952f68274de3fd7b
Size: 1.25 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 211013cfdb48e16e952f68274de3fd7b
Sha1 9c4c1aed92947d636109717667136b54bd28e2aa
Sha256 1583f581b4aed3b58c6dfaa9e8934acb0afbfe12ebc7a5c99ee8757242b4f7fa
Sha384 984399ebb5121662e03779c383b513a7b23b1376e2565c9351aea3f43ca84236df05f70eaa06ce70f2b26ed66faea4a9
Sha512 863c1b08d1a77f4cf81468d0e25c334c9b506dede923cf18c8fc50b77b03c3c9d7f017fa0865d9f10772d44c50b7f794d7e49de68ccf55cbb0f2f457944ec067
SSDeep 24576:pZN4BE7DwZOnE3sisdNcJYxJ93jCJH9o:T2ad7isdNjB3Sdo
TLSH A34523A061E5CE01E95847B11932D53417BB2C4EE063C21ADFEB7CD73937B91667AB02
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ScientificCalculator.Forms.GraphPlotterForm.resources
Scientific_Calc.Properties.Resources.resources
PIP
[NBF]root.Data
UBbI
[NBF]root.Data
[NBF]root.Data-preview.png
t1
[NBF]root.Data
[NBF]root.Data-preview.png
t2
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
nlsZ.exe
Full Name
nlsZ.exe
EntryPoint
System.Void ScientificCalculator.Program::Main()
Scope Name
nlsZ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
nlsZ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
380
Main Method
System.Void ScientificCalculator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ScientificCalculator.Forms.MainCalculatorForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
nlsZ.exe
Full Name
nlsZ.exe
EntryPoint
System.Void ScientificCalculator.Program::Main()
Scope Name
nlsZ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
nlsZ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
380
Main Method
System.Void ScientificCalculator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ScientificCalculator.Forms.MainCalculatorForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
nlhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙