Suspicious
Suspect

42b4f2257c669ccf3ea5e8be2583a034

PE Executable
MD5: 42b4f2257c669ccf3ea5e8be2583a034
Size: 1.3 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 42b4f2257c669ccf3ea5e8be2583a034
Sha1 73a3facee74907d38e38796f490ec16667d65596
Sha256 fbc2c57b9586b454e3990fe96fbf982dd49a90786a4ea9dbd29b7f2269655f04
Sha384 734e0732ac677e2ea64fccdc4721b24ff52bf96e725dbae0f85352c4132fcf978ae0184f08cb71e98dd7fa1bc8c3fb99
Sha512 ce103edb33fd7e8fe6c336fd2ebed20844a08e8ed791c97ce1ddda8871fe014408c0b52641fca1ec509ec49ce1c2683e04268b97cd5d0fdf06da6290f6bd62b8
SSDeep 24576:KguQr8TtI8oJwrNuQwL95aJgDUHz0kDw06VzHQnwhjVictE:DuW8mDJwA/aJODP0mwnQQcC
TLSH 2C552318325CDE69C9A427F011B2D2324774EE6AB221D317CDEE9CEFB58A782181D357
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BirthdayReminder.AboutBox1.resources
BirthdayReminder.Properties.Resources.resources
Clear
[NBF]root.Data
pAPvC
[NBF]root.Data
[NBF]root.Data-preview.png
werwre
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x13AC00 size 13832 bytes
Module Name
ReadOnlyDictionaryHelp
Full Name
ReadOnlyDictionaryHelp
EntryPoint
System.Void ObjectWri.IReflectableT::Main()
Scope Name
ReadOnlyDictionaryHelp
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LoowO
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
246
Main Method
System.Void ObjectWri.IReflectableT::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SecurityCriticalSc.SymLanguageVen::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
ReadOnlyDictionaryHelp
Full Name
ReadOnlyDictionaryHelp
EntryPoint
System.Void ObjectWri.IReflectableT::Main()
Scope Name
ReadOnlyDictionaryHelp
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LoowO
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
246
Main Method
System.Void ObjectWri.IReflectableT::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SecurityCriticalSc.SymLanguageVen::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BirthdayReminder.AboutBox1.resources
BirthdayReminder.Properties.Resources.resources
Clear
[NBF]root.Data
pAPvC
[NBF]root.Data
[NBF]root.Data-preview.png
werwre
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙