Suspicious
Suspect

PE Executable
MD5: 46991b391de12a9ff1692525eff2638f
Size: 669.18 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 46991b391de12a9ff1692525eff2638f
Sha1 d1346547dba22da7bce16bf428ec74426167d260
Sha256 628a3c3cbfd3a17bb69a617224e33d239729ced5665091578bf96cde788155c3
Sha384 153f645900fd2c868799749c81ddc72c9e97f16fa4128788621dd9374e6540024a9d0add899d97b8c1e907712e0e8050
Sha512 53b3479d1591469dff798e19aa0426f05313c4aa828713bb1edc6dc2b2dfba615eda01869257fdb4b2da0570685d62a694a14cb221cf150e0de7dab0e0091129
SSDeep 12288:ezpk9dt9snMevF76lIwfmm0owMDuQTU6SiJhTSU7+t8rZSsGMLqnqY15r6eRPA:em1ihmdOmS+uwUgJIheksGML8Ts+
TLSH 32E4129532E9C702C6FB4BF029B2E33513B97D9EA520D20A4DEEEDE73425B406450B97
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BuscaminasClone.Formularios.FormPrincipal.resources
BuscaminasClone.Properties.Resources.resources
GTmeCr
[NBF]root.Data
[NBF]root.Data-preview.png
Task1
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: gFWvAI.pdb
Module Name
gFWvAI.exe
Full Name
gFWvAI.exe
EntryPoint
System.Void BuscaminasClone.Program::Main()
Scope Name
gFWvAI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gFWvAI
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
260
Main Method
System.Void BuscaminasClone.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BuscaminasClone.Formularios.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
gFWvAI.exe
Full Name
gFWvAI.exe
EntryPoint
System.Void BuscaminasClone.Program::Main()
Scope Name
gFWvAI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gFWvAI
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
260
Main Method
System.Void BuscaminasClone.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BuscaminasClone.Formularios.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BuscaminasClone.Formularios.FormPrincipal.resources
BuscaminasClone.Properties.Resources.resources
GTmeCr
[NBF]root.Data
[NBF]root.Data-preview.png
Task1
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙