Suspicious
Suspect

6b1fb44426419a0c3ac3975739ac4470

PE Executable
MD5: 6b1fb44426419a0c3ac3975739ac4470
Size: 776.19 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 6b1fb44426419a0c3ac3975739ac4470
Sha1 c5a88bea30e15b05053298aaf35292bae5f23dbd
Sha256 ea9a27a55dfd58ccf9973c85b662c8cf3ba048e3f753c802640dc8718bde696c
Sha384 627b25976bb5ba6b328e26274f8ad4017e11c1a728d2f39e4c1749a20babee2a8f8f69553d8ecf1136d534e789db3b6c
Sha512 0e653641a14e44a412db6fd14f2706ef53471551d71dedd72e2bf87c2735a0b6b64e6b11dd81f05bc7ba136d9fe16693bec1d45f9da7bccd14e2f77165621a85
SSDeep 12288:YfZxBVn0V6gtShqZvZ6dc8M/MFZQTIs+5+FMjVG3vY9aKiW9ekScznYwGKG3TRJm:YffB5y6ymqZgdy4Qk5+wG3vY9a10ekFR
TLSH 20F402653356EC03C5AE1BF409B1D3B54BA8AE88F500C3839FFE6CDFB8657411A64692
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Calculator.Form1.resources
$this.Icon
[NBF]root.IconData
msp
[NBF]root.Data
ExtractAssociatedIcon.Form1.resources
Calculator.Properties.Resources.resources
SuZg
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\HxbDZjpgWK\src\obj\Debug\zeFD.pdb
Module Name
zeFD.exe
Full Name
zeFD.exe
EntryPoint
System.Void Calculator.Program::Main()
Scope Name
zeFD.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
zeFD
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
157
Main Method
System.Void Calculator.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Calculator.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Calculator.Form1.resources
$this.Icon
[NBF]root.IconData
msp
[NBF]root.Data
ExtractAssociatedIcon.Form1.resources
Calculator.Properties.Resources.resources
SuZg
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙