Suspicious
Suspect

PE Executable
MD5: 28d60cdc88c31bd6fe61aeada1375d3b
Size: 673.79 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 28d60cdc88c31bd6fe61aeada1375d3b
Sha1 6df1db2983e568d8d017504200afbabfae93b7e0
Sha256 2af765eda09831851e8d69b1d4d52ec87429fe40f8d03f533e75464a8caaf60c
Sha384 165160f68fc028577ae1083bcc13e298d5cf04aba68588258b679c8c96897e85ba8abd881c39f5f50af53892c843ed88
Sha512 750270f64f9cbee02725b5ee077b2e97ca27d65f09e1d1636ab36d0f6bf6a6dd51a8eeb6d6ce1966c183cda56074f8d72fbadb5e550835bf987b5fe52a2d58ac
SSDeep 12288:7E0f/1P1su7BorrnZnsGcqSDXScHc6q9YwButgCoGUlMCom:7lTsbrtSDXtc61wGGMC
TLSH 82E412A9620EDF17C8821FF44C91D2F423B8DEC8E521C743DFEA6D8F752A644A5452E2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Carubbi.MetroLayoutEngine.PromptDialog.resources
Carubbi.MetroLayoutEngine.MetroLayoutForm.resources
$this.Icon
[NBF]root.IconData
shp
[NBF]root.Data
Carubbi.MetroLayoutEngine.Properties.Resources.resources
IVLT
[NBF]root.Data
[NBF]root.Data-preview.png
blackBack
[NBF]root.Data
[NBF]root.Data-preview.png
whiteback
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\FVWkcyqzKh\src\obj\Debug\EFhk.pdb
Module Name
EFhk.exe
Full Name
EFhk.exe
EntryPoint
System.Void Carubbi.MetroLayoutEngine.MainC::Main()
Scope Name
EFhk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
EFhk
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
47
Main Method
System.Void Carubbi.MetroLayoutEngine.MainC::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Carubbi.MetroLayoutEngine.MetroLayoutForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
EFhk.exe
Full Name
EFhk.exe
EntryPoint
System.Void Carubbi.MetroLayoutEngine.MainC::Main()
Scope Name
EFhk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
EFhk
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
47
Main Method
System.Void Carubbi.MetroLayoutEngine.MainC::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Carubbi.MetroLayoutEngine.MetroLayoutForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Carubbi.MetroLayoutEngine.PromptDialog.resources
Carubbi.MetroLayoutEngine.MetroLayoutForm.resources
$this.Icon
[NBF]root.IconData
shp
[NBF]root.Data
Carubbi.MetroLayoutEngine.Properties.Resources.resources
IVLT
[NBF]root.Data
[NBF]root.Data-preview.png
blackBack
[NBF]root.Data
[NBF]root.Data-preview.png
whiteback
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙