Suspicious
Suspect

76b073332f2bc4233e24dd9a3031be93

PE Executable
MD5: 76b073332f2bc4233e24dd9a3031be93
Size: 1.01 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 76b073332f2bc4233e24dd9a3031be93
Sha1 ad0cfb81420cc011dab8b22b8fbf21838961d8af
Sha256 fc4fbf964b1ea4b01201f4f9fa13345ee834464272d6cdc9814de53e1c4d9e6b
Sha384 0e8ec2d4084919e93ab164185be1ddbb6c87e4ba769322fcd03e853b1634a111363c6c169069d9b3b0ce4c2b1ef5bd56
Sha512 a835fb740fc491b1a278ee8af9dc3071e64d368f254609e5ea1d49c68bae9153ffa154acbe5966db98c2f37d285613bd40e44681cf08ddd36bf9b167c98c55cd
SSDeep 24576:DZQVMVJibJcDXrfcYxSCnZ8WBuszAFAJZ:DZQe8Jcjwkp+azACJZ
TLSH 5E25120A135AEA03D4A40FF469B0C3BA57B11E99E52AD3434FEB7CFFB42A7405915386
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GradientCreator.Forms.MainForm.resources
GradientCreator.Properties.Resources.resources
Teacher
[NBF]root.Data
fnnz
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xF3C00 size 13832 bytes
Info
PDB Path: Rxrr.pdb
Module Name
Rxrr.exe
Full Name
Rxrr.exe
EntryPoint
System.Void GradientCreator.Program::Main()
Scope Name
Rxrr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Rxrr
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
128
Main Method
System.Void GradientCreator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void GradientCreator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
Rxrr.exe
Full Name
Rxrr.exe
EntryPoint
System.Void GradientCreator.Program::Main()
Scope Name
Rxrr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Rxrr
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
128
Main Method
System.Void GradientCreator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void GradientCreator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GradientCreator.Forms.MainForm.resources
GradientCreator.Properties.Resources.resources
Teacher
[NBF]root.Data
fnnz
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙