Suspicious
Suspect

PE Executable
MD5: 6119979238f8f838dcf3badb5dcb235d
Size: 972.8 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 6119979238f8f838dcf3badb5dcb235d
Sha1 72b7600962274de48d659fb73c127dc652fd76cd
Sha256 44ece3fd771b241e7adb7b8a46317aa0dce39aa4b815912805de4dc6ff631ae4
Sha384 3ac231f3b45386f60bfa63b47d8aa066361861a403515cdced4674e57d293310d53aedbc2683dcd413a7904258fb12b0
Sha512 e2eee0a7e443c0780df5d8221cd56c09ae2562f4640e9f53e26aea7ecbb4a9393466c14ad8c45e58ed49c6cca3ecf3c42436894c10c530a62b610951fbd4b68a
SSDeep 24576:QJt2X0/Fhwh5Hdiq/9wTmM/VJjghX8I165:QJtxhwhldiq/9cz/Vo8I16
TLSH BC2512983719E803C4554BB81D20E37913B48E5AF500D3928FEFBCD738A5B59BE98687
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Estevão_Bresolin.Form1.resources
$this.Icon
[NBF]root.IconData
RD
[NBF]root.Data
Estevão_Bresolin.Properties.Resources.resources
BCYn
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
zezd.exe
Full Name
zezd.exe
EntryPoint
System.Void Estevão_Bresolin.Program::Main()
Scope Name
zezd.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
zezd
Assembly Version
1.1.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
232
Main Method
System.Void Estevão_Bresolin.Program::Main()
Main IL Instruction Count
13
Main IL
newobj System.Void Estevão_Bresolin.Form1::.ctor()
dup <null>
ldc.i4.0 <null>
callvirt System.Void System.Windows.Forms.Control::set_Visible(System.Boolean)
newobj System.Void Estevão_Bresolin.Calcula_Fracoes_Model::.ctor()
stloc.0 <null>
dup <null>
ldloc.0 <null>
newobj System.Void Estevão_Bresolin.Controller::.ctor(Estevão_Bresolin.ICalculaFracao,Estevão_Bresolin.Calcula_Fracoes_Model)
pop <null>
callvirt System.Windows.Forms.DialogResult System.Windows.Forms.Form::ShowDialog()
pop <null>
ret <null>
Module Name
zezd.exe
Full Name
zezd.exe
EntryPoint
System.Void Estevão_Bresolin.Program::Main()
Scope Name
zezd.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
zezd
Assembly Version
1.1.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
232
Main Method
System.Void Estevão_Bresolin.Program::Main()
Main IL Instruction Count
13
Main IL
newobj System.Void Estevão_Bresolin.Form1::.ctor()
dup <null>
ldc.i4.0 <null>
callvirt System.Void System.Windows.Forms.Control::set_Visible(System.Boolean)
newobj System.Void Estevão_Bresolin.Calcula_Fracoes_Model::.ctor()
stloc.0 <null>
dup <null>
ldloc.0 <null>
newobj System.Void Estevão_Bresolin.Controller::.ctor(Estevão_Bresolin.ICalculaFracao,Estevão_Bresolin.Calcula_Fracoes_Model)
pop <null>
callvirt System.Windows.Forms.DialogResult System.Windows.Forms.Form::ShowDialog()
pop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Estevão_Bresolin.Form1.resources
$this.Icon
[NBF]root.IconData
RD
[NBF]root.Data
Estevão_Bresolin.Properties.Resources.resources
BCYn
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙