Suspicious
Suspect

2c3182f4aa16fd3c249557366ac6de37

PE Executable
MD5: 2c3182f4aa16fd3c249557366ac6de37
Size: 1 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 2c3182f4aa16fd3c249557366ac6de37
Sha1 4c6f37929cb4777bd0fab2de73cb868c2453b3be
Sha256 eb27c96a09f6c81ef8baca23b0024fc1c26dd3c9b2fa0a5b728cb56e1e2425af
Sha384 480161c90959b20276c7126c996232c8edb7658d84756334cc5996f59e4a939fbf8212c21122c577ad053da5f88e6a1b
Sha512 d89fe60bff6498d441fe798bba8ee22d898313392ac2a087b5b1178ebbb3edee52607d345d1922036d3c5b64cf7426f99202cc32daa788d5558a284f890115d9
SSDeep 24576:s2f7Nh7ETnPPGaPiP/6FN4g6jPh1ElETc:/f7NCTnPeaPVTp6jf/I
TLSH B52512056B1AEF52E8A21BF80D71E37117B4AE5CA815D31B4FD93CDBB4B9F142818A43
PeID
Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SpaceCalculator.MainForm.resources
SpaceCalculator.Properties.Resources.resources
CHT
[NBF]root.Data
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
qYPv
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: WnVP.pdb
Module Name
WnVP.exe
Full Name
WnVP.exe
EntryPoint
System.Void SpaceCalculator.Program::Main()
Scope Name
WnVP.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
WnVP
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
414
Main Method
System.Void SpaceCalculator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SpaceCalculator.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SpaceCalculator.MainForm.resources
SpaceCalculator.Properties.Resources.resources
CHT
[NBF]root.Data
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
qYPv
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙