Suspicious
Suspect

7211849d1fc4f2877ef25870f3f0f2bd

PE Executable
MD5: 7211849d1fc4f2877ef25870f3f0f2bd
Size: 781.31 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 7211849d1fc4f2877ef25870f3f0f2bd
Sha1 e946162d490a0cf80fa4968ac0780d36da0c6211
Sha256 b884a0d09ddf31990709d2f88cb41816d5ecb9514b0766b8bbca9844461d5716
Sha384 f04eb653caf1cb3e1a1d27b38032a145c845235f5b1a0f64367e18b2be6160a32503af229fd556969462301797b2d814
Sha512 e3ff0114d17524f143361d803d0ac39c0759a0c9241031a5b19cc42414e4d08a586d5215627d98c36879581d2047a55406d423db8f08bd48514e38828a4a40f3
SSDeep 12288:AGCjWHuSJMcF88tdM/tWdJdjKcPzFenvljbC4Qf+cWqc8iMFYrT:lCjWOS2H8tQsdjlPpenvlC4QGcWc
TLSH 74F4F10423AADB02E5B65BF01830D6740779BD5EB932E20A4FE57DEFB536B4058A0793
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ErrorAnalyzer.Forms.MainForm.resources
ErrorAnalyzer.Properties.Resources.resources
Coloring
[NBF]root.Data
tBql
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: AnYE.pdb
Module Name
AnYE.exe
Full Name
AnYE.exe
EntryPoint
System.Void ErrorAnalyzer.Program::Main()
Scope Name
AnYE.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
AnYE
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
438
Main Method
System.Void ErrorAnalyzer.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ErrorAnalyzer.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
AnYE.exe
Full Name
AnYE.exe
EntryPoint
System.Void ErrorAnalyzer.Program::Main()
Scope Name
AnYE.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
AnYE
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
438
Main Method
System.Void ErrorAnalyzer.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ErrorAnalyzer.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ErrorAnalyzer.Forms.MainForm.resources
ErrorAnalyzer.Properties.Resources.resources
Coloring
[NBF]root.Data
tBql
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙