Suspicious
Suspect

6dfbfaf345226ae453c7f3a2b39fb8e5

PE Executable
MD5: 6dfbfaf345226ae453c7f3a2b39fb8e5
Size: 737.28 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 6dfbfaf345226ae453c7f3a2b39fb8e5
Sha1 dbb8bb6cd47267cf83ff3b594514451fef9f77ed
Sha256 e8b879b31a0509b447b0975ee255f07ba148c0a6a90cdba08bc7172b820d35ae
Sha384 dd0fc4b3548df5f0ee71406b445a66589fa011c6cc32263313bc7c3b516f2de558e305b8e9b6f36139115566585ccc85
Sha512 b3aadd88da967fbd15500d69ccc78b62ddb0f9e1ba9dcc3abb78054a153552ffdd291d3e055448948ef167efdb1f987e7726e768d2f2a42fbd07d4e1d0c1907d
SSDeep 12288:wvQa9doBLbOI8ewPrT19zvgKp+1hGr7wYN2ONnOx/GgE0iVDOPX3TVYoSCmLBzni:Sr9CBLbzwHzvgKp+DGnN2ONOxQlFIbSk
TLSH 1BF41245A786DA62D4F903B04931E3B71379AEDEA401C35BD8FEFCE7B8263593451282
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PerformanceObjects.Properties.Resources.resources
cls
kYaa
Name Value
Module Name
psxr.exe
Full Name
psxr.exe
EntryPoint
System.Void PerformanceObjects.Program::Main()
Scope Name
psxr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
psxr
Assembly Version
1.6.1808.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
230
Main Method
System.Void PerformanceObjects.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PerformanceObjects.StrategicForm16::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
psxr.exe
Full Name
psxr.exe
EntryPoint
System.Void PerformanceObjects.Program::Main()
Scope Name
psxr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
psxr
Assembly Version
1.6.1808.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
230
Main Method
System.Void PerformanceObjects.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PerformanceObjects.StrategicForm16::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PerformanceObjects.Properties.Resources.resources
cls
kYaa
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
6dfbfaf345226ae453c7f3a2b39fb8e5
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
6dfbfaf345226ae453c7f3a2b39fb8e5
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙