Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 2e9c24a8a95d6f9dbf03129e31951347
Size: 854.02 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 2e9c24a8a95d6f9dbf03129e31951347
Sha1 f0a9b98714c7ebc6c051257fa258033f45512296
Sha256 98ade9be3b3bc68b8a07a1847014cb228c08dd1d5b8f3fa47597639f2623845a
Sha384 524f9037449dab1824c36503dda4bf7a5be53b51b6bb49175475f285dbce2b283c8aafacad5fb3acdf90674e0c43f600
Sha512 33b8d8bbd39641a96930c913714974ac6242e53b3ecc146f3fd7232ac9a8cba0eccba298e8de918d6dfa3ac2cda864cbb1320396fa9837c6dc9f3ff4bf9c009b
SSDeep 12288:Vm0VN0Rk1Fvbq7CEuhDRQJjRNOz1uyYiDGYGMxMUIQbPCr2Q09orsfs9Bxqo3TBU:+wvWpYyJjWuADGx2JIEqrgysfC5DBR
TLSH 95051248679DC506E4F95BB90B72D2740BB8BD9B9C20D21A9FC86CDB3C36B419D053A3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MonitorSync.Properties.Resources.resources
HQ
[NBF]root.Data
kmcT
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
ULVw.exe
Full Name
ULVw.exe
EntryPoint
System.Void MonitorSync.Program::Main()
Scope Name
ULVw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ULVw
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
491
Main Method
System.Void MonitorSync.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void MonitorSync.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
ULhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙