Suspicious
Suspect

PE Executable
MD5: 501929609f98b1c49eeade7ce6443247
Size: 1.26 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 501929609f98b1c49eeade7ce6443247
Sha1 1d4859c12fb9f60362f8123ff070d8fe22c7c0f2
Sha256 b424b9efdda544aedf50f9e9e20eb75e994196487cdc9458a73a628489c3dae3
Sha384 5e88d2adece135cd7d0e5c39e819ff06bb95eed51c0cd9bfe9ddbe102d0d8c5a9a95468231abec0c322bb037ce0dff6e
Sha512 eb690b7a31f999334f94d7d33e6dad1e3244b15d28fd763177f398b7f39fd9ad9284503b17415ea75b43ba50f7b92c4f86adf5471121efc7d75d61f849987e95
SSDeep 24576:0u2cpRIbOaGDGh/DIZp4SNoLIM61bxl7XtE2h:0uXpRISaGDMmpNe6/t
TLSH 7B45CF2930EF1156C476E7E30FEFFCB6967EF175222EB53A24A3168687A0D019D92035
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ReactionTimeTester.Forms.MainMenuForm.resources
ReactionTimeTester.Properties.Resources.resources
IDAYRV
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: hRycxV.pdb
Module Name
hRycxV.exe
Full Name
hRycxV.exe
EntryPoint
System.Void ReactionTimeTester.Program::Main()
Scope Name
hRycxV.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hRycxV
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
284
Main Method
System.Void ReactionTimeTester.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ReactionTimeTester.Forms.MainMenuForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
hRycxV.exe
Full Name
hRycxV.exe
EntryPoint
System.Void ReactionTimeTester.Program::Main()
Scope Name
hRycxV.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hRycxV
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
284
Main Method
System.Void ReactionTimeTester.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ReactionTimeTester.Forms.MainMenuForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ReactionTimeTester.Forms.MainMenuForm.resources
ReactionTimeTester.Properties.Resources.resources
IDAYRV
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙