Suspicious
Suspect

PE Executable
MD5: 621035273a142c173e21dce99b97eca9
Size: 1.03 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 621035273a142c173e21dce99b97eca9
Sha1 c62e643736e9c69957aafcaadf1e71909f9e239a
Sha256 33912e2315c6ce788cc44e678aeca8d5e0741d8e0d5c3f4868ef4acd8b71a523
Sha384 b1f6ef5403d1d65a4cf1744e12e4b68eafba4c774a97ee975e15fe8baf70d9d7b99baafac96566f56e775970923bf27e
Sha512 deacfcefe093301dea1c0d60b4b16bb495798308f25575f664e27cc166a214009255b36fb9f559a1e9ab94b237bb35977a3e9b70e5b2ae2be173e48910192ebe
SSDeep 12288:OrezPr9mMAlcvCY6Sy1ZEYjBnJFtgU63rPJCP9XJJQ3uvZu11PfN3UDvu3W5iBDP:2lcqY6fFyUuDJSB83uqSvwBDhYu
TLSH FF25121156D9D414E4F63FB41AB1F3B8977ABDCDA931C30A87E86CAF7C216806C24366
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StudyGuide.Properties.Resources.resources
CQyu
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: dkxT.pdb
Module Name
dkxT.exe
Full Name
dkxT.exe
EntryPoint
System.Void StudyGuide.Program::Main()
Scope Name
dkxT.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dkxT
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
101
Main Method
System.Void StudyGuide.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void StudyGuide.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StudyGuide.Properties.Resources.resources
CQyu
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙