Suspicious
Suspect

PE Executable
MD5: 2c09eb962e08237efdb07ed10536ed6e
Size: 729.6 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 2c09eb962e08237efdb07ed10536ed6e
Sha1 e6a6c3c6cae05c8a7eafa623f88e481931b1f926
Sha256 28f959fc9483c245c25c6beedc3f449913aeeef3810e43bfb251bc7cb3a998f9
Sha384 67b4f346e582440aa4f2e8040bb8379415e3fd1432e8f77079b01c9c3312de94596b761906f133266409d39cda4d2491
Sha512 4c7d96c45a47722447ef1360174a4aa34083cff40ee2389f1b06ee95643c8bd4d0d5fec751fbb862eca10b1daf0b8c69e79adcba9ee14a1ac80392f7dec15395
SSDeep 12288:SKE44ctN7IBWXWWA5lDsjsx/Lcs0FYj5DfQHESq/vz9CgoF44gVeAqT3iHBrUv1g:lTrIN5lsjI0oDfaivBCgGmeAq+HBi1Tk
TLSH 11F4F114235ACD07C0E24BB67871E3B47B296EDFA892E2969FC93FEFB0356410955342
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BackupSync.Form1.resources
BackupSync.Properties.Resources.resources
Ch1
[NBF]root.Data
OLKJ
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: kxfY.pdb
Module Name
kxfY.exe
Full Name
kxfY.exe
EntryPoint
System.Void BackupSync.Program::Main()
Scope Name
kxfY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kxfY
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
125
Main Method
System.Void BackupSync.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BackupSync.Form4::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
kxfY.exe
Full Name
kxfY.exe
EntryPoint
System.Void BackupSync.Program::Main()
Scope Name
kxfY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kxfY
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
125
Main Method
System.Void BackupSync.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BackupSync.Form4::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BackupSync.Form1.resources
BackupSync.Properties.Resources.resources
Ch1
[NBF]root.Data
OLKJ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙