Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 5761cacc1b06e5e6e2bea6af9e4e979a
Size: 698.37 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 5761cacc1b06e5e6e2bea6af9e4e979a
Sha1 06c6b870d268153d4b489799a47da35d50d788fc
Sha256 4a803cc2bc157d801250a7bb1742fb747e2961a2d0dbe2a64bc5b91a02f3d1a9
Sha384 6e7f177b1cc325d653dbfe9a1dcbaffa261012e0abe0aec695265ac7f8cb06ce65fbd29b1bcd0c956b5cedeb68e39f7c
Sha512 a1dc3e37cb24ab5a7e8db1bb97864cae291a0b708e5691b42cefcfb5a6d33cb6f74255b65af27d1013c210f928c2f6573434438ffb3dc9eb0d9e5a21fe472ce7
SSDeep 12288:0K/xQmUKzGm3tJpIp7ZZ/lOoNX3X+uQI93JhV/NqxC58zTc8oDj2sk2VcUWltjB:0LmUCLpIpn/ZVX+ZIhJ3FqxC58zToDy5
TLSH 48E4238D7F63A925DF2517BB805B844502BE9966F931F52E13E47CA70F3B84C801F992
PeID
.NET executableHQR data fileMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
pnvW.exe
Full Name
pnvW.exe
EntryPoint
System.Void Carubbi.MetroLayoutEngine.MainC::Main()
Scope Name
pnvW.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
pnvW
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
2
Main Method
System.Void Carubbi.MetroLayoutEngine.MainC::Main()
Main IL Instruction Count
21
Main IL
ldc.i4.4 <null>
stloc.1 <null>
ldloc.1 <null>
switch dnlib.DotNet.Emit.Instruction[]
call System.Void Carubbi.MetroLayoutEngine.Tile::Ⴄ()
ldc.i4 236
ldc.i4 165
call System.Void Carubbi.MetroLayoutEngine.MainC::Ⴗ(System.Int32,System.Int16)
ldc.i4.0 <null>
ldc.i4 559
ldc.i4 632
call System.Void Carubbi.MetroLayoutEngine.MetroLayoutUserControl::Ⴅ(System.Boolean,System.Int16,System.Int16)
ldc.i4.0 <null>
stloc.1 <null>
br.s IL_0002: ldloc.1
newobj System.Void Carubbi.MetroLayoutEngine.MetroLayoutForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
ldtoken System.Void Carubbi.MetroLayoutEngine.MainC::Main()
pop <null>
ret <null>
Module Name
pnvW.exe
Full Name
pnvW.exe
EntryPoint
System.Void Carubbi.MetroLayoutEngine.MainC::Main()
Scope Name
pnvW.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
pnvW
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
2
Main Method
System.Void Carubbi.MetroLayoutEngine.MainC::Main()
Main IL Instruction Count
21
Main IL
ldc.i4.4 <null>
stloc.1 <null>
ldloc.1 <null>
switch dnlib.DotNet.Emit.Instruction[]
call System.Void Carubbi.MetroLayoutEngine.Tile::Ⴄ()
ldc.i4 236
ldc.i4 165
call System.Void Carubbi.MetroLayoutEngine.MainC::Ⴗ(System.Int32,System.Int16)
ldc.i4.0 <null>
ldc.i4 559
ldc.i4 632
call System.Void Carubbi.MetroLayoutEngine.MetroLayoutUserControl::Ⴅ(System.Boolean,System.Int16,System.Int16)
ldc.i4.0 <null>
stloc.1 <null>
br.s IL_0002: ldloc.1
newobj System.Void Carubbi.MetroLayoutEngine.MetroLayoutForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
ldtoken System.Void Carubbi.MetroLayoutEngine.MainC::Main()
pop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙