Suspicious
Suspect

PE Executable
MD5: 3baf9ad525f5caa5d07dcb14c563abb4
Size: 945.15 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3baf9ad525f5caa5d07dcb14c563abb4
Sha1 5a626e2c3df90014ff37764bfe2e5a51cad205b3
Sha256 99816cd2de501f26cb3227491cf3bf407fba47ed12f8b925a993d7c822b031ae
Sha384 a9fd1abea069da085ba3e6c232c00727bfc151869343f84384fddd61d5a9bde8b9ab9c17c3dfecc9b8216656d3fb31e4
Sha512 15f998e4157ef0410b0f33df3a92fd3862a60e917fdde0979bb9bc723a4263b2c69cee10505c969f3bac570922332b3cdff45ba1b36a25a2d8377e0fdae4d8ad
SSDeep 24576:XPjuby9UtLFY8x1yBn35mbbWgynqAR0445WtjbK2:XPKby9UtLi8Y3fyVWtb
TLSH 4C151326B61AE403E46A1BF90E51D17483794DCEE921E3978FD97CEB30E27112B81B47
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Module Name
VffP.exe
Full Name
VffP.exe
EntryPoint
System.Void SectorRepair.Program::Main()
Scope Name
VffP.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
VffP
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
320
Main Method
System.Void SectorRepair.Program::Main()
Main IL Instruction Count
7
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.Void SectorRepair.Program::InitializeApplication()
newobj System.Void SectorRepair.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
VffP.exe
Full Name
VffP.exe
EntryPoint
System.Void SectorRepair.Program::Main()
Scope Name
VffP.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
VffP
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
320
Main Method
System.Void SectorRepair.Program::Main()
Main IL Instruction Count
7
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.Void SectorRepair.Program::InitializeApplication()
newobj System.Void SectorRepair.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Embedded Resources UNKNWOWNsuspect
5huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
5huhuhuhu
3baf9ad525f5caa5d07dcb14c563abb4
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
3baf9ad525f5caa5d07dcb14c563abb4
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙