Suspicious
Suspect

PE Executable
MD5: 4cb5e0fca67e50e87275119b3b60c710
Size: 1.59 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 4cb5e0fca67e50e87275119b3b60c710
Sha1 f6e0e4ebcfdd2b3457de726a342684d45d46de51
Sha256 7b51ada3129a95a30d3e4aedffc27278ebd8126f2e4a4f1eded5fa71307765fe
Sha384 c7228647ba57d9ae1a5a630e88a1d9e41ed2d7941a8b9943688572722c92d79e4ed075a5fbbe3d05ec2d989888930445
Sha512 0587d45c4b665dc3c933ea7d1cd2187402a56ae3877c0c57fe19eedae361790f32e1a2bf00b102c2e1424a86c4664140b55ffe611bfb154599631eed78253d96
SSDeep 24576:5LI2LI2+YjPdVvLhRcEejP1hXD7pYFR9O08k8sVW40Pyc:RI2LI2+Yjd3RcE7vLr
TLSH A675595223486ECFF17E62757523080512F2EFA36371CE9B7D80B4D90AB670587EA71A
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SpyNote_7._0.Resources.resources
ANUN
AboutSpyNote
[NBF]root.Data
[NBF]root.Data-preview.png
BuildTool
[NBF]root.Data
[NBF]root.Data-preview.png
Circle
[NBF]root.Data
[NBF]root.Data-preview.png
MenuItem
ProcessToolStripMenuItem
[NBF]root.Data
[NBF]root.Data-preview.png
SpyNote
[NBF]root.Data
[NBF]root.Data-preview.png
aBitmap
SpyNote_7._0.AboutSpyNote.resources
SpyNote_7._0.Build.resources
PBil.Image
[NBF]root.Data
[NBF]root.Data-preview.png
PictureBox2.Image
[NBF]root.Data
[NBF]root.Data-preview.png
SpyNote_7._0.devices.resources
PictureLoading.Image
[NBF]root.Data
[NBF]root.Data-preview.png
SpyNote_7._0.JAVA.resources
SpyNote_7._0.MainSpyNote.resources
$this.Icon
[NBF]root.IconData
Name Value
Module Name
SpyNote v7.0.exe
Full Name
SpyNote v7.0.exe
EntryPoint
System.Void SpyNote_7._0.My.MyApplication::Main(System.String[])
Scope Name
SpyNote v7.0.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
SpyNote v7.0
Assembly Version
7.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
5317
Main Method
System.Void SpyNote_7._0.My.MyApplication::Main(System.String[])
Main IL Instruction Count
6
Main IL
call System.Boolean Microsoft.VisualBasic.ApplicationServices.WindowsFormsApplicationBase::get_UseCompatibleTextRendering()
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call SpyNote_7._0.My.MyApplication SpyNote_7._0.My.MyProject::get_Application()
ldarg.0 <null>
callvirt System.Void Microsoft.VisualBasic.ApplicationServices.WindowsFormsApplicationBase::Run(System.String[])
ret <null>
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SpyNote_7._0.Resources.resources
ANUN
AboutSpyNote
[NBF]root.Data
[NBF]root.Data-preview.png
BuildTool
[NBF]root.Data
[NBF]root.Data-preview.png
Circle
[NBF]root.Data
[NBF]root.Data-preview.png
MenuItem
ProcessToolStripMenuItem
[NBF]root.Data
[NBF]root.Data-preview.png
SpyNote
[NBF]root.Data
[NBF]root.Data-preview.png
aBitmap
SpyNote_7._0.AboutSpyNote.resources
SpyNote_7._0.Build.resources
PBil.Image
[NBF]root.Data
[NBF]root.Data-preview.png
PictureBox2.Image
[NBF]root.Data
[NBF]root.Data-preview.png
SpyNote_7._0.devices.resources
PictureLoading.Image
[NBF]root.Data
[NBF]root.Data-preview.png
SpyNote_7._0.JAVA.resources
SpyNote_7._0.MainSpyNote.resources
$this.Icon
[NBF]root.IconData
No malware configuration was found at this point.
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
4cb5e0fca67e50e87275119b3b60c710
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
4cb5e0fca67e50e87275119b3b60c710
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙