Suspicious
Suspect

PE Executable
MD5: 36fb2d17c879ad649f7087dc79dc80be
Size: 757.76 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 36fb2d17c879ad649f7087dc79dc80be
Sha1 ff9e687a7e11c945f77d39d41228ccb45bb8148f
Sha256 4cc4ef1db310f70a8f0a7b8c316e7701ffbe9086d75d5bec6f7a8cae9502ce54
Sha384 a1611a1f1e7847c523e094a9caf407b2294610ab0e21861bd9382b7e5f4cf95a523e243280bfb4185ea041f53cc5fa31
Sha512 7fb916309a0d041e0885be1944087beb89378cd781ad7763754d0b444fceded88223aa4016aecdeca62271984de14c1e7a223c24ddeb58cacf4b7f3655d65a11
SSDeep 12288:SjN6ACdnvdSRgCuWLmdGGWOfBHS3+P558hojeGg8fiYDN4zn:QYAUFRCuZ0GZQ3e5Yg02iMC
TLSH F4F4E040AD5DAB1EECA467F1C871F27407B56C696822E30A4EE53CD77B23B0C1619B53
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SoftwareMercado.frmPrincipal.resources
$this.Icon
[NBF]root.IconData
gr
[NBF]root.Data
SoftwareMercado.Properties.Resources.resources
PSYO
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
EgYo.exe
Full Name
EgYo.exe
EntryPoint
System.Void SoftwareMercado.Program::Main()
Scope Name
EgYo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
EgYo
Assembly Version
3.7.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
573
Main Method
System.Void SoftwareMercado.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SoftwareMercado.frmPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
?huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SoftwareMercado.frmPrincipal.resources
$this.Icon
[NBF]root.IconData
gr
[NBF]root.Data
SoftwareMercado.Properties.Resources.resources
PSYO
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
?huhuhuhu
36fb2d17c879ad649f7087dc79dc80be
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙