Suspicious
Suspect

2c42498362384576632b791c7b1a8eed

PE Executable
MD5: 2c42498362384576632b791c7b1a8eed
Size: 805.38 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 2c42498362384576632b791c7b1a8eed
Sha1 2f87ac06f7e202698575b22ea5efe5758a09a27a
Sha256 be6cfa96f2af2d275323fc9722c8bef9d4b0abd5716a7d344d6dc6ece60a72c5
Sha384 53f5e78310dbd6bb1d76d05ec6126aeb8eaef45963d9db91885e9255ab73bce0f4126f2a683aff4cbadbb30d405d991c
Sha512 12e981159b53451685513fc51bed7998435b1b4a90aeca165b84001ded3fdd8618fffce7ab23a2ffdf98e88812ca99985d2189b9f692f6d3908e1500382c58ff
SSDeep 12288:rgrSnbKk3pWRalBbACbdznVMW10ZnS3riYV7oZNow/oglUPbCBdrdfyY2:Bnbj3pllxhMWiZnS32YV7oZNQTC3R2
TLSH 1E05F114629A9F11C9AA27F90512D4B553BABDEDA030D70E4FC97CFB3EB37920406A53
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RepositoryModule.MainForm.resources
RepositoryModule.Properties.Resources.resources
DQ
FtlL
Name Value
Module Name
zlcf.exe
Full Name
zlcf.exe
EntryPoint
System.Void RepositoryModule.Program::Main()
Scope Name
zlcf.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
zlcf
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
679
Main Method
System.Void RepositoryModule.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void RepositoryModule.Program::InitializeApplication()
nop <null>
newobj System.Void RepositoryModule.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
zlcf.exe
Full Name
zlcf.exe
EntryPoint
System.Void RepositoryModule.Program::Main()
Scope Name
zlcf.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
zlcf
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
679
Main Method
System.Void RepositoryModule.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void RepositoryModule.Program::InitializeApplication()
nop <null>
newobj System.Void RepositoryModule.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
8huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RepositoryModule.MainForm.resources
RepositoryModule.Properties.Resources.resources
DQ
FtlL
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
8huhuhuhu
2c42498362384576632b791c7b1a8eed
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
2c42498362384576632b791c7b1a8eed
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙