Suspicious
Suspect

PE Executable
MD5: 5b6c2014a562b48f654c514a6844e923
Size: 835.58 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 5b6c2014a562b48f654c514a6844e923
Sha1 d6576dbf098220e6444b75ca1ab95d395583631a
Sha256 27d9bc341947a02d196c43a4ecc1ad5d0506e34b901fa8dd1d74be4eaa8753cf
Sha384 1420f573bb6b7eabb94287011141ecbc7d8c485718dcf5fc0ea10d8efbbdef6a3cb4f769d756bcd1f3eb75aa7336bd80
Sha512 b1bb1ae51337894b9a9d44bb6bbae00ed4b5433d8663b267399bb342598318660c844d51905cabb5ba491f487b0d23c3d91116d9db23c51a97ae99c53b75cc65
SSDeep 12288:Gznnf4izggW4e8U8HQfhmG3pOMpvoJlZnW9WqvUhPoCSO5e4c7QjD0e:0nnf4izgbpNdpvoJlZnW9dvUhWO5w3
TLSH D90501993241DA13D5A517F0892AE3FCA2781E9EB830EF02BED47DCB3839751954B127
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Calculator_Project.Calculator.resources
$this.Icon
[NBF]root.IconData
greyder
[NBF]root.Data
Login_And_Register_Form.registerForm.resources
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox2.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Login_And_Register_Form.frmLogin.resources
Login_And_Register_Form.Properties.Resources.resources
NXz
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
dkC.exe
Full Name
dkC.exe
EntryPoint
System.Void Login_And_Register_Form.Program::Main()
Scope Name
dkC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dkC
Assembly Version
6.3.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
174
Main Method
System.Void Login_And_Register_Form.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Login_And_Register_Form.registerForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
dkhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Calculator_Project.Calculator.resources
$this.Icon
[NBF]root.IconData
greyder
[NBF]root.Data
Login_And_Register_Form.registerForm.resources
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox2.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Login_And_Register_Form.frmLogin.resources
Login_And_Register_Form.Properties.Resources.resources
NXz
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
dkhuhuhuhu
5b6c2014a562b48f654c514a6844e923
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙