Suspicious
Suspect

PE Executable
MD5: 424ad59b8432e95257e14b5b7ed35934
Size: 657.92 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 424ad59b8432e95257e14b5b7ed35934
Sha1 6e0fd866dbbf1759cf8cd58258ed3873d25274d6
Sha256 90addeb56d3d3cd4aa9064861d82f68ed5e501e0149e1915e533d14c67e97e76
Sha384 e9a3bde410635cd002f853f2602c754733e924ea6331c56fa7a2d9bd7e208b4fca01af1df3e90d276aaddf59f98122f5
Sha512 af2ad6f0fd89593359958a7b4e722ba4b2a457e1e7b878d2b35b80d11283d2590957718fef07824eb6497b736c85353c7d270eba3db0af90d39c7f187526e460
SSDeep 12288:jCcFa4FjeuEYh/LWlNY8GQFPtu9DiOT0QKMZYkbqwJz4wnIo2T:laGF6Q8G/mwGMZYMqwJz4S
TLSH 50E40214237AEF07E0A71BF80970D37657796DA8B811D34A4EF66CEBB8257402D49393
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PerformanceCreator.Forms.CounterPublisherForm.resources
PerformanceCreator.Properties.Resources.resources
Teacher
[NBF]root.Data
nPSR
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: VVzY.pdb
Module Name
VVzY.exe
Full Name
VVzY.exe
EntryPoint
System.Void PerformanceCreator.Program::Main()
Scope Name
VVzY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
VVzY
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
260
Main Method
System.Void PerformanceCreator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PerformanceCreator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
VVzY.exe
Full Name
VVzY.exe
EntryPoint
System.Void PerformanceCreator.Program::Main()
Scope Name
VVzY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
VVzY
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
260
Main Method
System.Void PerformanceCreator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PerformanceCreator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PerformanceCreator.Forms.CounterPublisherForm.resources
PerformanceCreator.Properties.Resources.resources
Teacher
[NBF]root.Data
nPSR
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙