Suspicious
Suspect

PE Executable
MD5: 6b2a43d39853dbaf67b8f055a96dc0f1
Size: 743.94 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 6b2a43d39853dbaf67b8f055a96dc0f1
Sha1 be66ff57dde39a0c39b5c953815bc0328bd47fb8
Sha256 a25be9533b9bf7feb8ab371e69cfdbc40cdf7a9d6f9041e8dd04d5f7755d43d0
Sha384 39df6a96645f805dc65ba13f239426d6a2501120bad4486ad2d4fbbd6b3f0be24588a72daec2a35151873bc0978ff9fb
Sha512 764a0cb5219adc54d725d3ff3a39789814f65ab4b4b00731c72703a3520abad48cd00d74a956540b658f0fdfbafd5806fc1c39f5a99be7196ff5ccbcb29e6d3c
SSDeep 12288:wUVKWHuSJMcmW7EmFCJkuhWIZk79pefg+t/aXTRXQteUqYDbW/+yR6xprjfSs2e/:vVKWOS2TmFCJkUoefT1aD2tfqeWdRafp
TLSH 1AF4F10473EAEA02E9B6ABF01970C6740779BD9EBD21D3060EE57DEB7931B405890793
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ErrorAnalyzer.Forms.MainForm.resources
ErrorAnalyzer.Properties.Resources.resources
Coloring
[NBF]root.Data
PTfP
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: cxiG.pdb
Module Name
cxiG.exe
Full Name
cxiG.exe
EntryPoint
System.Void ErrorAnalyzer.Program::Main()
Scope Name
cxiG.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
cxiG
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
438
Main Method
System.Void ErrorAnalyzer.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ErrorAnalyzer.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
cxiG.exe
Full Name
cxiG.exe
EntryPoint
System.Void ErrorAnalyzer.Program::Main()
Scope Name
cxiG.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
cxiG
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
438
Main Method
System.Void ErrorAnalyzer.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ErrorAnalyzer.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ErrorAnalyzer.Forms.MainForm.resources
ErrorAnalyzer.Properties.Resources.resources
Coloring
[NBF]root.Data
PTfP
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙