Suspicious
Suspect

72c5ef0a366ebacab963cd77a6fe8873

PE Executable
MD5: 72c5ef0a366ebacab963cd77a6fe8873
Size: 912.9 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 72c5ef0a366ebacab963cd77a6fe8873
Sha1 1b8ca0653ba6669d38f545096645bfa6890ff518
Sha256 d58c12abba6d1d929cc2b5cfdd3e5df87e467319e33cc4e68b33a4a9476d0292
Sha384 d1f1e33c1a18ee4533631cd69132a4d1b9b435a69a7b024d52207d7b11c41b2900b43020cffd08afe3c1980537e2e84b
Sha512 a27e414db3732fcf7f509d391b46420c804ec97e7c0f86f80660de95ba877c677b1f2c4af5b6d438e90bef715efbe55cabac69da2214b3531d80fbd9c1509f82
SSDeep 24576:Sfy060LTCCVTiymW6zH8NfUw2ithDUE+:SyaLTCCV+ytdUpit
TLSH 811512982A11EB06CD654BF44A31F2742B7A4EDCE922D6178EE93EFB3876F011C50653
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MatrixOperations.Forms.MainForm.resources
MatrixOperations.Properties.Resources.resources
Sort1
[NBF]root.Data
Thinking
[NBF]root.Data
[NBF]root.Data-preview.png
Thinking_Spinner
[NBF]root.Data
[NBF]root.Data-preview.png
YjQX
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: DPDG.pdb
Module Name
DPDG.exe
Full Name
DPDG.exe
EntryPoint
System.Void MatrixOperations.Program::Main()
Scope Name
DPDG.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DPDG
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
158
Main Method
System.Void MatrixOperations.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void MatrixOperations.Forms.MenuForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
DPDG.exe
Full Name
DPDG.exe
EntryPoint
System.Void MatrixOperations.Program::Main()
Scope Name
DPDG.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DPDG
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
158
Main Method
System.Void MatrixOperations.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void MatrixOperations.Forms.MenuForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MatrixOperations.Forms.MainForm.resources
MatrixOperations.Properties.Resources.resources
Sort1
[NBF]root.Data
Thinking
[NBF]root.Data
[NBF]root.Data-preview.png
Thinking_Spinner
[NBF]root.Data
[NBF]root.Data-preview.png
YjQX
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙