Suspicious
Suspect

760adb84a7fe0a63be71217a1d3b9dbd

PE Executable
MD5: 760adb84a7fe0a63be71217a1d3b9dbd
Size: 101.25 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 760adb84a7fe0a63be71217a1d3b9dbd
Sha1 ca86a35ef5b992969e4f29ea7c7e60f690cc3a77
Sha256 ef2e8058072b7d590f8ac4796487db839cc60064151c136bfa58213c87f016d4
Sha384 f18aaf6e8afe12cfd1f8b5847c976edb745297ba2f33ebf9a7d2379858ded3eabbff7e73a04919009cf6a720ac345d80
Sha512 4c5157d87e365732e1413a41220f766cd0a6834f80f3e4707990069a52d31c736d8749a4a9e12fa4009954b512e55a4214bca1b50232834644c6c4854600ce39
SSDeep 1536:WAp5eznKUlIOp3YjVCguHEvQEbFqVC3woFRKpT4XP:d5eznsjsguGDFqG/
TLSH 50A3CA387D952133C67EC1F689E50A8AEB69223F3191E9ED4CA742C418B2F156EC1D1F
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Overlay_06287917.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
26fc2.resources
1973c.png
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_06287917.bin (2944 bytes)
Module Name
1.exe
Full Name
1.exe
EntryPoint
System.Void MusicExpress.Program::Main()
Scope Name
1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
1
Assembly Version
1.28.14.52
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
1178
Main Method
System.Void MusicExpress.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void MusicExpress.MusicExpressMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
1.exe
Full Name
1.exe
EntryPoint
System.Void MusicExpress.Program::Main()
Scope Name
1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
1
Assembly Version
1.28.14.52
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
1178
Main Method
System.Void MusicExpress.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void MusicExpress.MusicExpressMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Overlay_06287917.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
26fc2.resources
1973c.png
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙