Suspicious
Suspect

3a25be6cd88c961611676047a1409b32

PE Executable
MD5: 3a25be6cd88c961611676047a1409b32
Size: 734.72 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 3a25be6cd88c961611676047a1409b32
Sha1 3eda9a14768550cb087219d997ba182917e2bc93
Sha256 bb17aae78c989184f3618223ea0e06d307fee6a6467ba61bb4b9e15ca42cf06c
Sha384 8401bb38ed537fff737ce58780281993b9f8ec7c777b594e35437d0172965297965c5c283999495e8cef8e09a7b75b3d
Sha512 a6b06e3c3aaf674dfdd039730bb8e1218a219b4e7bc1e94b0c64b0b8fcff6b50b53189718727b25c224a701fc0177d688b910b2f23f47808c4f1068fb5415282
SSDeep 12288:/UyJSaVsdDM430YI8lhn9Glmc3PJV1ghhKLV4qRB2RHcjdCushan2:J6pjlRQ5fb1ghhy42/dC
TLSH F0F4125532A6D612D0FB2BB85C61C37403B97E9E7922D3065FDAACDF3C25B50A941383
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DailyPlanner.MainForm.resources
DailyPlanner.Properties.Resources.resources
XvBR
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: UBPe.pdb
Module Name
UBPe.exe
Full Name
UBPe.exe
EntryPoint
System.Void DailyPlanner.Program::Main()
Scope Name
UBPe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
UBPe
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
294
Main Method
System.Void DailyPlanner.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DailyPlanner.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
UBPe.exe
Full Name
UBPe.exe
EntryPoint
System.Void DailyPlanner.Program::Main()
Scope Name
UBPe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
UBPe
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
294
Main Method
System.Void DailyPlanner.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DailyPlanner.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DailyPlanner.MainForm.resources
DailyPlanner.Properties.Resources.resources
XvBR
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙