Suspicious
Suspect

PE Executable
MD5: 70278c60597b0460e365c6923d3cb488
Size: 540.16 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 70278c60597b0460e365c6923d3cb488
Sha1 ecbcf6799754a68cc4a41233bbb16dc5160e4ba5
Sha256 593ce4cdc76392a894b3cb77beec4352b0be6dc06b4f86b9a7352d57041c1b4e
Sha384 5d0322704c8dbd32186cbb68f8a00d189067cc030893641fcb7dc823d4d76f2391d82df5762d6001a1282c69a147bb28
Sha512 f47494b40986971cb13980ce45058ffb5aa517f46d49752f10e57d2e98190ba7da5524fede7edf2e3a26a0a4c10f49868dd88e1481ae5f6a5e382a4bf2f31a75
SSDeep 6144:QkmTWLUrD41r4oim/ciiuxhjrafyhQEdvtMyj41qMK4g2fBEw7ufHBzv:Qkmq/1rsHibhjraK+2E1qnloBEw2
TLSH 34B4E054267ADE06D0A687B719B0F5341FAE2D6AA861F2468FCA7CDF7D32B010D80753
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ModularExponentiation.Forms.MainForm.resources
ModularExponentiation.Properties.Resources.resources
Moon
[NBF]root.Data
lFmN
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: wPCv.pdb
Module Name
wPCv.exe
Full Name
wPCv.exe
EntryPoint
System.Void ModularExponentiation.Program::Main()
Scope Name
wPCv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
wPCv
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
224
Main Method
System.Void ModularExponentiation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ModularExponentiation.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
wPCv.exe
Full Name
wPCv.exe
EntryPoint
System.Void ModularExponentiation.Program::Main()
Scope Name
wPCv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
wPCv
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
224
Main Method
System.Void ModularExponentiation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ModularExponentiation.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ModularExponentiation.Forms.MainForm.resources
ModularExponentiation.Properties.Resources.resources
Moon
[NBF]root.Data
lFmN
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙