Suspicious
Suspect

PE Executable
MD5: 50a45ffb4edd95232ee419d8281a6277
Size: 666.11 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 50a45ffb4edd95232ee419d8281a6277
Sha1 4e8167b8aede68fe4e0e29d65100d833ed200cea
Sha256 911d8e4c53b4226bb2e1ef12bd7aaf32e88f4f025cf630ad6b02b39261b9dd84
Sha384 a50797f54384de4c7be5489f2f0333ed0113e58a01c6568e3e542b5426cbf6afdb1bd7aa30539fcbacdae4ca3f2a9f24
Sha512 687689da70eb9635ad7464a0c8ee2084c1b86c0a5c0901316029936a7a4a22966af1228b1ca24ec0d8eb36135c5501117fccb393921d1e45fa81ee2205a49090
SSDeep 12288:qyb0OWZWG6Pdb44baSBf0jkrcTYb0U1SZcKCPrvzN/g62q/Wf6l3a5cv7BM8q/:qoG2GSZBKYDjoVf6ti8q/
TLSH 88E41264179AD903E9A25BF4AD60D33463B97ED9B421C3075EED9CDB3823B462C84783
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
LoremMaker.Forms.MainForm.resources
LoremMaker.Properties.Resources.resources
KS
[NBF]root.Data
jTRh
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: dAmr.pdb
Module Name
dAmr.exe
Full Name
dAmr.exe
EntryPoint
System.Void LoremMaker.Program::Main()
Scope Name
dAmr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dAmr
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
350
Main Method
System.Void LoremMaker.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void LoremMaker.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
LoremMaker.Forms.MainForm.resources
LoremMaker.Properties.Resources.resources
KS
[NBF]root.Data
jTRh
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙