Suspicious
Suspect

PE Executable
MD5: 2ccb858aa9f1f1e8bb7ec02e44759acb
Size: 793.09 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 2ccb858aa9f1f1e8bb7ec02e44759acb
Sha1 95995b99cf475193c891adb4ce34e882df614f0b
Sha256 70ffcccdedd4cbfce9d10e4bf42f9917f33c055ba2078b76976827f3d604ccfb
Sha384 04a038f9ce58d3cbfeef5c805f38f57327a080fd12499a9a43dfa9241d94109de600b5c6193572ef84e05b00a9aa8567
Sha512 95d043429c3a4ce8c012c6d9021a8eb82120e8ffb4f4b7bb9f5738b5e0186910e727b6fae53bad5ed8293cc9265e396b9bd875e034fba777544184193404fa36
SSDeep 24576:smZoN+WIo10uyC8JK1NWGRCTfU6GT9Ge:kv1wJK1jF6s9
TLSH BEF4CFAC3251B5DFC893C9328DA4DD74AA207DBA530BD20394D71DABB90E996DF101F2
PeID
.NET executableHQR data fileMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CSVViewer.Forms.MainForm.resources
CSVViewer.Properties.Resources.resources
KS
[NBF]root.Data
cdfz
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
mtrB.exe
Full Name
mtrB.exe
EntryPoint
System.Void CSVViewer.Program::Main()
Scope Name
mtrB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
mtrB
Assembly Version
3.4.3.4
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
183
Main Method
System.Void CSVViewer.Program::Main()
Main IL Instruction Count
25
Main IL
nop <null>
call System.Void CSVViewer.Program::‮‪‮‮‏‏‌‪‮​‎​‎​‬‌​‏‍‭‪‮()
nop <null>
ldc.i4.0 <null>
call System.Void CSVViewer.Program::​‪‭‌‏‍‬‏‮‏‍‫‎‫‍‌‬‍‪‪‌‏‏‬​‭‬‫‪‌‮(System.Boolean)
nop <null>
ldc.i4 -703962143
ldc.i4 -1716846425
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.3 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_004A: ret
newobj System.Void CSVViewer.Forms.MainForm::.ctor()
call System.Void CSVViewer.Program::‮​‭‏‍‏‭‫‌‮​‎‪‫‍‮‬​‪‎‌‭‏‪‌‎‮‎‎‮(System.Windows.Forms.Form)
nop <null>
ldloc.0 <null>
ldc.i4 -1581204728
mul <null>
ldc.i4 542196079
xor <null>
br.s IL_0013: ldc.i4 -1716846425
ret <null>
Module Name
mtrB.exe
Full Name
mtrB.exe
EntryPoint
System.Void CSVViewer.Program::Main()
Scope Name
mtrB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
mtrB
Assembly Version
3.4.3.4
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
183
Main Method
System.Void CSVViewer.Program::Main()
Main IL Instruction Count
25
Main IL
nop <null>
call System.Void CSVViewer.Program::‮‪‮‮‏‏‌‪‮​‎​‎​‬‌​‏‍‭‪‮()
nop <null>
ldc.i4.0 <null>
call System.Void CSVViewer.Program::​‪‭‌‏‍‬‏‮‏‍‫‎‫‍‌‬‍‪‪‌‏‏‬​‭‬‫‪‌‮(System.Boolean)
nop <null>
ldc.i4 -703962143
ldc.i4 -1716846425
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.3 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_004A: ret
newobj System.Void CSVViewer.Forms.MainForm::.ctor()
call System.Void CSVViewer.Program::‮​‭‏‍‏‭‫‌‮​‎‪‫‍‮‬​‪‎‌‭‏‪‌‎‮‎‎‮(System.Windows.Forms.Form)
nop <null>
ldloc.0 <null>
ldc.i4 -1581204728
mul <null>
ldc.i4 542196079
xor <null>
br.s IL_0013: ldc.i4 -1716846425
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CSVViewer.Forms.MainForm.resources
CSVViewer.Properties.Resources.resources
KS
[NBF]root.Data
cdfz
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙