Suspicious
Suspect

3ec541e1a8f74cb9aab3d16cdcc0b1d6

PE Executable
MD5: 3ec541e1a8f74cb9aab3d16cdcc0b1d6
Size: 100.99 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 3ec541e1a8f74cb9aab3d16cdcc0b1d6
Sha1 1ee2db2e5ec2411d86dfe208e5681b7aa43b7e73
Sha256 c411f481563dd48db8a218e063da6477062a9cb628d50c666009ad9040dfde21
Sha384 95a94272a036c01b9ccea4d3d89e1bcf670d95bb07edd118baa7657f2bdbc681c0259d3351bf928a5fc107f6727c833d
Sha512 cc30a1266471f6ff8fd60ea20c76ec91ec8305645900d1a58cbf647801c8f70584c600ac052a153809f90de58ff607f112a132656fb611a6e09154491c0ed4f6
SSDeep 1536:WAp5eznKUlIOp3YjVCguHEvQEbFqVC3woFRKpT4v8+:d5eznsjsguGDFqGvF
TLSH 18A3CA387D952133C67EC1F689E90A8AEB69223F3191E9ED4CA742C418B2F156DC1D1F
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Overlay_5ce6d1c7.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
26fc2.resources
1973c.png
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_5ce6d1c7.bin (2688 bytes)
Module Name
1.exe
Full Name
1.exe
EntryPoint
System.Void MusicExpress.Program::Main()
Scope Name
1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
1
Assembly Version
1.28.14.52
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
1178
Main Method
System.Void MusicExpress.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void MusicExpress.MusicExpressMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
1.exe
Full Name
1.exe
EntryPoint
System.Void MusicExpress.Program::Main()
Scope Name
1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
1
Assembly Version
1.28.14.52
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
1178
Main Method
System.Void MusicExpress.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void MusicExpress.MusicExpressMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Overlay_5ce6d1c7.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
26fc2.resources
1973c.png
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙