Suspicious
Suspect

PE Executable
MD5: 610f0cefe2baa978ab137a80e41c5001
Size: 966.66 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 610f0cefe2baa978ab137a80e41c5001
Sha1 f4e5c27fcc33ba0080d98b5f6539aeffc133582f
Sha256 769c2febefd0402ee34d4c1bbd4aee8f6b6b660c22ac74e212765978ae3e903f
Sha384 ca312af6e150a6d8c2589f6cc8693c63966bfd5103c5f10dd55fd826f5ce8bd77f060a0a624fdb9e1d2d01aaa461db34
Sha512 4bb77323b62eb9b7e15abf6708a0b7399a9f98082a6d3861032d8123b2cb79020942b3b7da5e9ce6e9c925579bb63876776020e77a6b7e4dc64af1e1c05903ce
SSDeep 24576:Kj7kHwlBqGGCAEBf7B72Cl/9BoxE0RfTbFn:ZDGVxtqCllaxEYF
TLSH C92512597650C827DA6293780870F3B4237A5DE8A120D797AFEC7EDFB9A9F014D10983
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
EstudoTaskool.frmCadastro.resources
$this.Icon
[NBF]root.IconData
EstudoTaskool.Views.frmListaUsuario.resources
EstudoTaskool.Properties.Resources.resources
foto
[NBF]root.Data
[NBF]root.Data-preview.png
hRhS
[NBF]root.Data
[NBF]root.Data-preview.png
logo
[NBF]root.Data
Database.DBModel.csdl
Database.DBModel.msl
Database.DBModel.ssdl
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
CdIa.exe
Full Name
CdIa.exe
EntryPoint
System.Void EstudoTaskool.Program::Main()
Scope Name
CdIa.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CdIa
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
144
Main Method
System.Void EstudoTaskool.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void EstudoTaskool.FrmPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
CdIa.exe
Full Name
CdIa.exe
EntryPoint
System.Void EstudoTaskool.Program::Main()
Scope Name
CdIa.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CdIa
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
144
Main Method
System.Void EstudoTaskool.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void EstudoTaskool.FrmPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
EstudoTaskool.frmCadastro.resources
$this.Icon
[NBF]root.IconData
EstudoTaskool.Views.frmListaUsuario.resources
EstudoTaskool.Properties.Resources.resources
foto
[NBF]root.Data
[NBF]root.Data-preview.png
hRhS
[NBF]root.Data
[NBF]root.Data-preview.png
logo
[NBF]root.Data
Database.DBModel.csdl
Database.DBModel.msl
Database.DBModel.ssdl
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙