Suspicious
Suspect

PE Executable
MD5: 6dadf44078eeac9411e636538cb5e134
Size: 727.55 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 6dadf44078eeac9411e636538cb5e134
Sha1 3ad01ea7b81f064bd37df912d0a6b7830d11f3c5
Sha256 2c2d25a172f507ebb2b0f827ea5a73e5270dbec25c00adecac3bd3bd7e0799bd
Sha384 4a1741abb51f390f776d18c7f631cc2622f1b2bdeb78cc0cca160a244b0a72dad19675de2a84d751c4ba890586697ad8
Sha512 bb063eb61476d685bbbd25f8ad7069d148bc72fdffd3e727f1007a0c5bd009b69ab169b7dfa6046acfdcb28a9cd3048c84ad314c87722e2139f2cc6e5155cc6c
SSDeep 12288:N1mqaJYn4pvm7ztqLSRvbXHIUuNjLCOwnLTAsTe+n/EgfFlH:zmJWE8xUSRvbXBuNLMLUs/EgfFlH
TLSH 4FF4121427AACA16D1B14B791AF2F07407F93DA9A920D31A8FC96CEF75B1F104D58B23
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ModularExponentiation.Forms.MainForm.resources
ModularExponentiation.Properties.Resources.resources
Moon
[NBF]root.Data
jKLi
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: NuGz.pdb
Module Name
NuGz.exe
Full Name
NuGz.exe
EntryPoint
System.Void ModularExponentiation.Program::Main()
Scope Name
NuGz.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
NuGz
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
224
Main Method
System.Void ModularExponentiation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ModularExponentiation.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
NuGz.exe
Full Name
NuGz.exe
EntryPoint
System.Void ModularExponentiation.Program::Main()
Scope Name
NuGz.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
NuGz
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
224
Main Method
System.Void ModularExponentiation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ModularExponentiation.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ModularExponentiation.Forms.MainForm.resources
ModularExponentiation.Properties.Resources.resources
Moon
[NBF]root.Data
jKLi
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙