Suspicious
Suspect

PE Executable
MD5: 55334b1d1e0eb722eca1875247c9c06c
Size: 676.35 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 55334b1d1e0eb722eca1875247c9c06c
Sha1 bbf16a90b8ffa643f247430c9b202bd850567bf0
Sha256 2a8a729d0e203b203a53c0b4ab591ef3aa3eb0fd45972297a2b597404ecef986
Sha384 2591b5b0970c7667b6f2c7bdf3ac359cc046807d154b6848a5c5258fea0d4974def4146dda51d2781ad9e528eb83879d
Sha512 6b901d308b909a2bd98de3c28c00ff2f2bb702df5c59f27e3d195d251df1fb3489d26caa80150b76fcc65ec3c9c82b5d4ba180bbae4ce676bf0bca8374204cb8
SSDeep 12288:ULSCKnTKMl/DBM0xStBChg15UyDLszs1BXnFcBDX8fhSr6CuzZhan2:UvWTzthStY21WyAzInFgL8fw9
TLSH FBE4022521A9D015E1F92F342DB6D3B8977E3D8D6831C74B4BE86CAF7C36A00A4547B2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StudyGuide.Properties.Resources.resources
TARa
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: lWgd.pdb
Module Name
lWgd.exe
Full Name
lWgd.exe
EntryPoint
System.Void StudyGuide.Program::Main()
Scope Name
lWgd.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lWgd
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
101
Main Method
System.Void StudyGuide.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void StudyGuide.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
lWgd.exe
Full Name
lWgd.exe
EntryPoint
System.Void StudyGuide.Program::Main()
Scope Name
lWgd.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lWgd
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
101
Main Method
System.Void StudyGuide.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void StudyGuide.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StudyGuide.Properties.Resources.resources
TARa
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙