Suspicious
Suspect

PE Executable
MD5: 360744f8a161eaa3414a166830677825
Size: 780.29 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 360744f8a161eaa3414a166830677825
Sha1 35f53ea535bc4145263e90b6bbed5a5a1a52e6cd
Sha256 078cabe3f98bbf49468d898d869cd8f58df0ff0a1bddd9d00524ac49dd04f3af
Sha384 41aecd5d53104ef1e8223e38210011d999be2a9209c2404101f88b07e1364aa3541e0fbf60959cd2662cfba99130cede
Sha512 011658589e30f62e82f84fe163fa65d7cd5ab58643894cfc47bd8f936ce8e4bab0c3e9f009bb49d23dc0c3087aba42598a3f2fa267e12d4f015c16760df63ce4
SSDeep 12288:qQAHVBff5TYEOuqAKBKLXYQEVu2OkTId0iSP9/gaiADc7:3eBffRhKBoIQUuLiq0ZPialD
TLSH A6F4020B5645C812C3F713B05D23E3B892B41EDAAC11D3C39AE9AFF3B8253569944DA7
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BTH1.Calculator1.resources
$this.Icon
[NBF]root.IconData
BTH1.Calculator2.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
$this.Icon
[NBF]root.IconData
FT
[NBF]root.Data
BTH1.Properties.Resources.resources
YjQ
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: zRB.pdb
Module Name
zRB.exe
Full Name
zRB.exe
EntryPoint
System.Void BTH1.Program::Main()
Scope Name
zRB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
zRB
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
98
Main Method
System.Void BTH1.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BTH1.Calculator2::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BTH1.Calculator1.resources
$this.Icon
[NBF]root.IconData
BTH1.Calculator2.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
$this.Icon
[NBF]root.IconData
FT
[NBF]root.Data
BTH1.Properties.Resources.resources
YjQ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙