Suspicious
Suspect

PE Executable
MD5: 24d2a14e6ad773a0737a5a250e5f4609
Size: 1.01 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 24d2a14e6ad773a0737a5a250e5f4609
Sha1 1df2398f1d06b37ea9ceba2b778e48a4e10498c3
Sha256 85ec11517de659f7a359f0fac6b06e53229e67bc3ee46bb942c2d4d692cd0982
Sha384 13f14c560a09f11a112afef87670fc3b97c8f1bd532b5ea8455d286777ed0a7d90b4c49aae55a3699ee5cbcb5d80f60b
Sha512 e318d4741eb8e260d1d15c780835b9172b10f6dd115a584f3d92d7120811a18b8debb72a30eae5b807ac9e2f52248ea1f0c4cd0c39bc02535a142c5d7f3c12b3
SSDeep 24576:AZnXqyllglglglvRsA9j+pLXfWWgomK+0TJKXeEATr:06F5+1fWWrx+WJIyv
TLSH A72501E13369CD13D9B151F2D824F6B447F96D9BB822C2D58ED5ACCB36E4F402242A93
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
IndexApp.CalTriangle.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.calBMI.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
IndexApp.FormBSB.resources
iamgeA.ErrorImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.FrmInternetCafe.resources
pictureBox1.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.FrmStudentBMI.resources
IndexApp.GoldPriceFrm.resources
pictureBox1.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.IndexApp.resources
$this.Icon
[NBF]root.IconData
Ce
[NBF]root.Data
menuStrip1.TrayLocation
IndexApp.Properties.Resources.resources
XXsb
[NBF]root.Data
[NBF]root.Data-preview.png
gold-bars
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\RjEzoYnQJL\src\obj\Debug\KBcG.pdb
Module Name
KBcG.exe
Full Name
KBcG.exe
EntryPoint
System.Void IndexApp.Program::Main()
Scope Name
KBcG.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KBcG
Assembly Version
3.3.5.4
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
749
Main Method
System.Void IndexApp.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void IndexApp.IndexApp::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
IndexApp.CalTriangle.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.calBMI.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
IndexApp.FormBSB.resources
iamgeA.ErrorImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.FrmInternetCafe.resources
pictureBox1.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.FrmStudentBMI.resources
IndexApp.GoldPriceFrm.resources
pictureBox1.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.IndexApp.resources
$this.Icon
[NBF]root.IconData
Ce
[NBF]root.Data
menuStrip1.TrayLocation
IndexApp.Properties.Resources.resources
XXsb
[NBF]root.Data
[NBF]root.Data-preview.png
gold-bars
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙