Suspicious
Suspect

PE Executable
MD5: 6ad6b8e8dad4f6555786a44725800fc0
Size: 1.07 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 6ad6b8e8dad4f6555786a44725800fc0
Sha1 9825f7f799d765eac6a9892f278aacead54b23cd
Sha256 859ffef0278c9c9835db23202f3aa67b69ad1e00a3f326350f613ab701a45ee3
Sha384 54ae0f884f3286e61f006becbfce26032ede0678d00344a36ab45305ee7930ccd9cca1335e87dfe512261c7e6f531a0b
Sha512 342d0a4216d2117b5128e4ffd78c24628b18f925dad8a9033051e705210a3b95f839460c43851debbe70e37d897a179f7b025b9ffff2f8606fb038c1904900bf
SSDeep 12288:d60BBCdnT5W/VNf9hZnLtOYU/Wjd7lV+nZJiTk6+Fl5/O0JnCBDoe8wklzEHZq9o:fm94dtUczV67iycWyF3kuHZq91OJ
TLSH E8352221331DE017D46A5EF04862D272277E6DAC9D02E54BDEC83F9F78EA3164A50B93
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
test.NotePadForm.resources
$this.Icon
[NBF]root.IconData
BPP
[NBF]root.Data
contextMenuStrip1.TrayLocation
contextMenuStrip2.TrayLocation
menuStrip1.TrayLocation
test.Properties.Resources.resources
UEf
[NBF]root.Data
[NBF]root.Data-preview.png
test.SaveChangesDialog.resources
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
nWo.exe
Full Name
nWo.exe
EntryPoint
System.Void test.Program::Main()
Scope Name
nWo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
nWo
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
164
Main Method
System.Void test.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void test.NotePadForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
test.NotePadForm.resources
$this.Icon
[NBF]root.IconData
BPP
[NBF]root.Data
contextMenuStrip1.TrayLocation
contextMenuStrip2.TrayLocation
menuStrip1.TrayLocation
test.Properties.Resources.resources
UEf
[NBF]root.Data
[NBF]root.Data-preview.png
test.SaveChangesDialog.resources
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙