Suspicious
Suspect

PE Executable
MD5: 5f056393ce31e9ee457335e28eb1c2c1
Size: 927.74 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 5f056393ce31e9ee457335e28eb1c2c1
Sha1 a3d996d3fa8186fc9984618fd776b61d35890db2
Sha256 a470b6f07644e28d40b1943e7bbbe82480904d0701165c21177a7e6a631f6db3
Sha384 450219677a118e64e8a0508e87d90a33e973778b7b7e9ef2207de1c5af75d0f8b0134e2813a7fd37c16e25bbc4b4b6d3
Sha512 2e4e08283b8e50c6743f4480a03fbd2a0d33937c0a062cff527e520510aa33a3aff48c42f98f1ce51f32dce50dfe6883a3a09e1daf375fac867f57d3ef0fc903
SSDeep 24576:Bv7wpfyIvZpUJQfIzEXDO6oSMpvkY5CTxvI+afHm:BvUgIHM4NotWxg+cHm
TLSH 84151265279BEC07D9A10BB019B1E3B153387DCCE504D3126EFEACDBBC296952D8C252
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WinFormServer.Form1.resources
$this.Icon
[NBF]root.IconData
crt
[NBF]root.Data
WinFormServer.Properties.Resources.resources
Drwq
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
KutS.exe
Full Name
KutS.exe
EntryPoint
System.Void WinFormServer.Program::Main()
Scope Name
KutS.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KutS
Assembly Version
1.5.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
70
Main Method
System.Void WinFormServer.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void WinFormServer.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
KutS.exe
Full Name
KutS.exe
EntryPoint
System.Void WinFormServer.Program::Main()
Scope Name
KutS.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KutS
Assembly Version
1.5.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
70
Main Method
System.Void WinFormServer.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void WinFormServer.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WinFormServer.Form1.resources
$this.Icon
[NBF]root.IconData
crt
[NBF]root.Data
WinFormServer.Properties.Resources.resources
Drwq
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙