Suspicious
Suspect

602a4f88d3f7e60e0db420c7dec075bb

PE Executable
MD5: 602a4f88d3f7e60e0db420c7dec075bb
Size: 683.01 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 602a4f88d3f7e60e0db420c7dec075bb
Sha1 8cd3d5e46fccbe29421cf853846a865e03e34228
Sha256 faa236eaf11ddab3abe7dcc8c69613d89edf60da47060bf6dc881fa9e118cd9e
Sha384 a08f5b452a4477730390a446764dcdf786bd34a4a2ccc48118700ce2d44a8cf23e68b04d379543a01bb6f5b64f5fbee5
Sha512 cec56875555c5ef2f1d1ee5c2a225f40063d1da146f7fc3bd2f5e956c4f15d0851d8ab723a071c5ba0c883e52e9f00876c1e34bd8b41ae49984a69591c2145df
SSDeep 12288:2aqojL4eCP0hRMCOObkFRXH2dWbCpiL7Sw+ekNwNCTHp3nghSruEfny0SBqXu0:vqPP0hRDAFRAiXL7STekc8Qeueyke0
TLSH 41E412042BA49E06D5E14BB55532E2711BB1FE4EA522D32B8EE63CDF7632B019981713
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PrimeNumberGenerator.Forms.MainForm.resources
PrimeNumberGenerator.Properties.Resources.resources
crc
[NBF]root.Data
ecXW
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: IecH.pdb
Module Name
IecH.exe
Full Name
IecH.exe
EntryPoint
System.Void PrimeNumberGenerator.Program::Main()
Scope Name
IecH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
IecH
Assembly Version
3.4.3.4
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
187
Main Method
System.Void PrimeNumberGenerator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PrimeNumberGenerator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PrimeNumberGenerator.Forms.MainForm.resources
PrimeNumberGenerator.Properties.Resources.resources
crc
[NBF]root.Data
ecXW
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙