Suspicious
Suspect

5632d16148705bb21e324af741e62114

PE Executable
MD5: 5632d16148705bb21e324af741e62114
Size: 1.37 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 5632d16148705bb21e324af741e62114
Sha1 72bb26a7bb33a6f4a788d8e06915353f70cb3f7f
Sha256 d5ffca1430a7af94f3bbc02893f7494b0a2b3d3cdb90c013f1946f14a26556d7
Sha384 346fd6973416b8fd2659eab98162c64e2c699890a9948dbbad36ba44269a12dcd60f5019c33a66d90b93393c01f9e6ec
Sha512 8ec38ac377dd89b64e94da066b6b35852bfbcd697ef3e389e2046c844dd37268e1418910bc0ec36cab8e7075ae13b33f4426391b112395480164db00b2137941
SSDeep 24576:2OLh6cDk/YZAyRA8Sy+hBgidO89FLommAePSCesTgOUzfsuOvsfgbFS:FV6cAUihBo80PSCBUzfsuOvfFS
TLSH F95523242B86E503CB9063746E70F27D27B95DA8F811D247AFCDAEEBB461F045D049E2
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordLength.Forms.MainForm.resources
WordLength.Properties.Resources.resources
foto
[NBF]root.Data
[NBF]root.Data-preview.png
kHkS
[NBF]root.Data
[NBF]root.Data-preview.png
logo
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: yfIN.pdb
Module Name
yfIN.exe
Full Name
yfIN.exe
EntryPoint
System.Void WordLength.Program::Main()
Scope Name
yfIN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yfIN
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
182
Main Method
System.Void WordLength.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WordLength.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordLength.Forms.MainForm.resources
WordLength.Properties.Resources.resources
foto
[NBF]root.Data
[NBF]root.Data-preview.png
kHkS
[NBF]root.Data
[NBF]root.Data-preview.png
logo
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙