Suspicious
Suspect

PE Executable
MD5: 4f044faa93923a93ce87dfd862258871
Size: 998.4 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 4f044faa93923a93ce87dfd862258871
Sha1 3b6b07a2c2bb7d3b5b355a02e353535a8d5466e9
Sha256 84f2e7778e3a25f2b9900ddfdfce6bbc39a6814f791c44100fd7d35d38dd95af
Sha384 ac184fc5c9ff44be6ec21851024e26543cd57c66a7da2775edc3e88e16b9d3f1d9d1cfd76c9d538895798a7ecb64edd5
Sha512 5b5d03559aaa7d0232e6422420a873ab18e19e28ad4dd797381f4f3a715ff7e1a942b4a7dc474c796d8ae5ebb758abb66509e60e0de71c2ba5c905b4c0426a6b
SSDeep 24576:l9CBkTM6m0WyzBYH5NFSMR1xGxZLMTyTK8884:l9CBkbm0W5HH0yeZYYd88
TLSH 2E251218A6ADDFA3D1FD07F81570D3B623B65C9DA401D3068EDEECE378527402A906A7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
VirtualWrapper.MainForm.resources
VirtualWrapper.Properties.Resources.resources
Pdkuw
k0
Name Value
Module Name
ewGOC.exe
Full Name
ewGOC.exe
EntryPoint
System.Void VirtualWrapper.Program::Main()
Scope Name
ewGOC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ewGOC
Assembly Version
5.6.14.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
650
Main Method
System.Void VirtualWrapper.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void VirtualWrapper.Program::InitializeApplication()
nop <null>
newobj System.Void VirtualWrapper.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
ewGOC.exe
Full Name
ewGOC.exe
EntryPoint
System.Void VirtualWrapper.Program::Main()
Scope Name
ewGOC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ewGOC
Assembly Version
5.6.14.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
650
Main Method
System.Void VirtualWrapper.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void VirtualWrapper.Program::InitializeApplication()
nop <null>
newobj System.Void VirtualWrapper.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
9huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
VirtualWrapper.MainForm.resources
VirtualWrapper.Properties.Resources.resources
Pdkuw
k0
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
9huhuhuhu
4f044faa93923a93ce87dfd862258871
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
4f044faa93923a93ce87dfd862258871
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙