Suspicious
Suspect

PE Executable
MD5: 2cba88fc2c33458b2532acf4e215a8bd
Size: 682.5 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 2cba88fc2c33458b2532acf4e215a8bd
Sha1 cfb9f2f6eece86ec61029f951cc029bfbec75a20
Sha256 8ccd299fea6467b706e5b9108fb8e18c2dfab8fad9b324464f4ff74f067be6ad
Sha384 f8c906bcbd92daa1e08948fa3788152cfa198d5fd09f2b5860625bd7dac2cd82710eb52c9a4e0d9839e00d3a928dcbdc
Sha512 dac391113b8b4b0b2c9c4ed915a2f2ad969a3bc9cb87f4efc457cedca948ee511d9cbb0785e262aa2051e73fed466da2cc1b57eb3c45ef97a8e4725d29cd1515
SSDeep 12288:Uh682BMRTHoQ6/DwyQsPBbce1Z+/0KMVj8iJPW/tiJH3HU9CwY:Un22mPnPBbZ3xVj8U+iJH3HUc7
TLSH 10E401493A2EDF16D8B55BF50DA0E37023346D5AA921D2065FE6BCEBB439F115C083A3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: KoGUiZ.pdb
Module Name
KoGUiZ.exe
Full Name
KoGUiZ.exe
EntryPoint
System.Void BitTools.Program::Main()
Scope Name
KoGUiZ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KoGUiZ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
456
Main Method
System.Void BitTools.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BitTools.Forms.MainLauncher::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
KoGUiZ.exe
Full Name
KoGUiZ.exe
EntryPoint
System.Void BitTools.Program::Main()
Scope Name
KoGUiZ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KoGUiZ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
456
Main Method
System.Void BitTools.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BitTools.Forms.MainLauncher::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙