Suspicious
Suspect

PE Executable
MD5: 64f950175ed6c68e51c34db1c2dab3ee
Size: 527.88 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 64f950175ed6c68e51c34db1c2dab3ee
Sha1 98a8d4a1dddd0219b0b9057c7e510664165b6177
Sha256 5240a9ff514c4c31fa548a21ef76f684efb7b62edb0b2db9cc5fbaa00e73b87b
Sha384 9b6b340ae492b8e5bb3c4ce08a908432dc759b7a9f323748c5582724ef527ca8f15ae6f11887d249f9d129f330bb8c97
Sha512 75e439369cdf64a4dc137b9b54be42b1c9c053e9cdc913490d572e85d0a9c6bc3214c700ac5a71db7fa226ee52126d647c01433b4cf0f803cc2787aabe236376
SSDeep 12288:WmW3Su0yg+FlLilyCnlhSqFSu5VSfLBVmfow1eW73nkR:Be0yznMRnl4Q9VSCfogeWby
TLSH 03B412541609D913C5F11BB82EF0D3B816799ECDB800C75389EDFCEBB8367496A88395
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNotesApp.Properties.Resources.resources
SAdj
[NBF]root.Data
[NBF]root.Data-preview.png
htta
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x7D800 size 13832 bytes
Info
PDB Path: GoEa.pdb
Module Name
GoEa.exe
Full Name
GoEa.exe
EntryPoint
System.Void SmartNotesApp.Program::Main()
Scope Name
GoEa.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
GoEa
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
76
Main Method
System.Void SmartNotesApp.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SmartNotesApp.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
GoEa.exe
Full Name
GoEa.exe
EntryPoint
System.Void SmartNotesApp.Program::Main()
Scope Name
GoEa.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
GoEa
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
76
Main Method
System.Void SmartNotesApp.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SmartNotesApp.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNotesApp.Properties.Resources.resources
SAdj
[NBF]root.Data
[NBF]root.Data-preview.png
htta
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙