Suspicious
Suspect

PE Executable
MD5: 570cdb3610c4f77d78d885e6dd3b8ec8
Size: 700.93 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 570cdb3610c4f77d78d885e6dd3b8ec8
Sha1 3be99924dbdf353ce0c03603d92bfc1065c69929
Sha256 0f67fe74fb4cf4338c01d4fef99efbc2d7fa49d5acd524e0dd7a7700c8c80af4
Sha384 5583973c02b6917ebab1ecadb2d0734fba83c6be3349bd0d721f428b5abb55cdc1a748b6ff99e74937fc3c4228c34203
Sha512 45964aea81e75d45cdff20c9adceeebea71d76ac90fb4e9972a0ac11a9e191fb1d196cd338002cf87f52cbd9cec5f597af0d335764778fa753c4a11a0aa57c14
SSDeep 12288:osw/CqQnyzEeVYBGC3lLBrB8cM7t9EoK2EhgkFUch3MdSwuhzh8sTEAuO7xKqX:oR/TEepC3ldKR7tWoagkFU8Ky18sTEAd
TLSH 96E412483719EB17D965A7F91570E27403BA3EAEA822D3175EDA2EFB7835B004C44393
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
UnitConvert.BidirectionalConverterForm.resources
UnitConvert.Properties.Resources.resources
KDJI
[NBF]root.Data
[NBF]root.Data-preview.png
de
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: rGkC.pdb
Module Name
rGkC.exe
Full Name
rGkC.exe
EntryPoint
System.Void UnitConvert.Program::Main()
Scope Name
rGkC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
rGkC
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
387
Main Method
System.Void UnitConvert.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void UnitConvert.MainMenuForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
UnitConvert.BidirectionalConverterForm.resources
UnitConvert.Properties.Resources.resources
KDJI
[NBF]root.Data
[NBF]root.Data-preview.png
de
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙