Suspicious
Suspect

461888457071596af2a930579bac2d28

PE Executable
MD5: 461888457071596af2a930579bac2d28
Size: 1.54 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 461888457071596af2a930579bac2d28
Sha1 6d6309e71c98fb5b1b54c9de4507f3b029510887
Sha256 692a87d9c56b3a48f2e7c82b0fe5a79a463bfb09a7e3d43b8d9eea454e7bd420
Sha384 8c155459b92a801b48fe14434ba1e96a5ff407688ea95d264cbd5449470e21aead324ef86b1735174f0ecfc9223d0fb9
Sha512 990c12921e8f7a4524fcde607cc6511dd69f16616b0e93383528ae5f61adcd38163dce23ea314e07174e85ca54d900be7a79aab3a3ff8fc415cdf3dcfb5c6576
SSDeep 24576:XpoH97jCZWN1C14Ljc5MYcDpd8ZvY1g0XfTnnL0gPxUJmgxhr06lahx09VOmrmi:XpoH9Xj1CWciYc1d8adXrngdcUci
TLSH 2D6523A55906CA26D9C32B745B70F33512B58DC8FCA5C2129FF6BCA7B826A1FFC18150
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ReactionGrid.Properties.Resources.resources
GI
[NBF]root.Data
lFzB
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
gocb.exe
Full Name
gocb.exe
EntryPoint
System.Void ReactionGrid.Program::Main()
Scope Name
gocb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gocb
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
69
Main Method
System.Void ReactionGrid.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ReactionGrid.RejimnerDzev::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
gocb.exe
Full Name
gocb.exe
EntryPoint
System.Void ReactionGrid.Program::Main()
Scope Name
gocb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gocb
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
69
Main Method
System.Void ReactionGrid.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ReactionGrid.RejimnerDzev::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ReactionGrid.Properties.Resources.resources
GI
[NBF]root.Data
lFzB
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙