Suspicious
Suspect

596dc288e8914898b0be9d57a0e3d277

PE Executable
MD5: 596dc288e8914898b0be9d57a0e3d277
Size: 855.04 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 596dc288e8914898b0be9d57a0e3d277
Sha1 06aebc4b151876e8c1c9e118f90e14aba11b284d
Sha256 64506ae267aed8afa5cfbb41ca8f5677600747f02fe27b8d8d926d12e3ad99f2
Sha384 cac7d6eb5c0d2ecd9eb74ffaf7f0535feb6ecb803dc942cc4f9c6c6967a3ca4b7a5ff63b7c0aa8a4767776b256f13056
Sha512 c19839ff9cff6ee84352e213d8761f2b77ee96174a83860561f319204d734522dced618f044e0e7fb09fb6887a56fc570aa29d1f23276691821c1a3b65cf8aa6
SSDeep 24576:bvCKX8jRLCOo0fQyrQVPwynhO0QE0Bfwh2y:bvCfjg30f9rQVBWto2y
TLSH 2D05F114331ADC13E56257F00970E37197785ED4A461E3E3CEFBADEBB9A67806809683
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
KaraokeManager.FrmAdmin.resources
$this.Icon
[NBF]root.IconData
KaraokeManager.frmDangNhap.resources
KL
[NBF]root.Data
KaraokeManager.FrmEditAccount.resources
KaraokeManager.Properties.Resources.resources
pFmv
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\hbPykizOvL\src\obj\Debug\oDEk.pdb
Module Name
oDEk.exe
Full Name
oDEk.exe
EntryPoint
System.Void KaraokeManager.Program::Main()
Scope Name
oDEk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oDEk
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
296
Main Method
System.Void KaraokeManager.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void KaraokeManager.frmDangNhap::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
KaraokeManager.FrmAdmin.resources
$this.Icon
[NBF]root.IconData
KaraokeManager.frmDangNhap.resources
KL
[NBF]root.Data
KaraokeManager.FrmEditAccount.resources
KaraokeManager.Properties.Resources.resources
pFmv
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙