Suspicious
Suspect

774807b9b75ac88b24a0811cc350c0f4

PE Executable
MD5: 774807b9b75ac88b24a0811cc350c0f4
Size: 744.96 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 774807b9b75ac88b24a0811cc350c0f4
Sha1 ae526acf7cace22c20d2b3b2b4eea535ffe5ec5e
Sha256 d27348a799f87eea272a85478ee75657d29ab30367b493368d29f4d2f20d4727
Sha384 02cd33850711023d914dfa8dd9816a6e4cbcd3e3fa370a4d74b168b4062737077699399fd0a4f04749ec98b77f648c37
Sha512 e025d3dd92303b269f4f8934b9d38b82f2d83ddd67df1fde1b2bce63343dfe3237e77fdb1a0c5cff7d579b433a2b5d003ae8bf5f71fb17c57550a3234e43976e
SSDeep 12288:yBpppppppppjHpppppppppp3j3S2SGF9RJmY0VZnHGc0+r1wSSoEBBVMqjRYm7Dd:yBpppppppppjHpppppppppp3j3iGF9RF
TLSH B4F41268359ADA12FCA817B800B1E37052754ECD7422E74B4BEDBCE33A37B166159293
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
usercontrolwithdatabinding.Form1.resources
$this.Icon
[NBF]root.IconData
bsCustomer.TrayLocation
engh
[NBF]root.Data
errorProvider1.TrayLocation
usercontrolwithdatabinding.Properties.Resources.resources
WNxw
[NBF]root.Data
[NBF]root.Data-preview.png
usercontrolwithdatabinding.UserControls.AddressControl.resources
Name Value
Module Name
DFwX.exe
Full Name
DFwX.exe
EntryPoint
System.Void usercontrolwithdatabinding.Program::Main()
Scope Name
DFwX.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DFwX
Assembly Version
1.2.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
106
Main Method
System.Void usercontrolwithdatabinding.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void usercontrolwithdatabinding.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
usercontrolwithdatabinding.Form1.resources
$this.Icon
[NBF]root.IconData
bsCustomer.TrayLocation
engh
[NBF]root.Data
errorProvider1.TrayLocation
usercontrolwithdatabinding.Properties.Resources.resources
WNxw
[NBF]root.Data
[NBF]root.Data-preview.png
usercontrolwithdatabinding.UserControls.AddressControl.resources
No malware configuration was found at this point.
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
774807b9b75ac88b24a0811cc350c0f4
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙