Suspicious
Suspect

7802c0fb05e7f0ced114730547d4bd7b

PE Executable
MD5: 7802c0fb05e7f0ced114730547d4bd7b
Size: 1.17 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 7802c0fb05e7f0ced114730547d4bd7b
Sha1 5c675773ec2d6d3f1e62a31bde1555fc15b6aa2e
Sha256 ed63af5b850235652affdd64e8cc4f69c2aeb2071662cafc8796afdd00722e38
Sha384 b4919ba7d5f4dd5fdfe4bf7ad63aa76eb617593a1830293576b37906d0da395b657c597c530d246be71ef5d312f61e88
Sha512 07109518b7a1340c85ec08a0a046cefae35713ecbfe38f7619a2121ac3f8e3721f3bbb98d112f6093651a0e341b59da6c63d6c7b1ec9b778db7c2410689f25a9
SSDeep 24576:/GH54wJa9/3FXpve7jvitRtIE5U+IXMyC7MvpIienVHB4c2w:/GH54wJahFXpCj0RA+IXMy+TnVHmcr
TLSH A24523171F9CE583DA422BB021B2D27063B45E5DA163E78B5FE26CDBF8A13782705913
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AlertDisplay.Forms.MainForm.resources
AlertDisplay.Properties.Resources.resources
Mars
[NBF]root.Data
uUPb
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x11B400 size 13832 bytes
Info
PDB Path: NSmn.pdb
Module Name
NSmn.exe
Full Name
NSmn.exe
EntryPoint
System.Void AlertDisplay.Program::Main()
Scope Name
NSmn.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
NSmn
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
117
Main Method
System.Void AlertDisplay.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AlertDisplay.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
NSmn.exe
Full Name
NSmn.exe
EntryPoint
System.Void AlertDisplay.Program::Main()
Scope Name
NSmn.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
NSmn
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
117
Main Method
System.Void AlertDisplay.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AlertDisplay.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AlertDisplay.Forms.MainForm.resources
AlertDisplay.Properties.Resources.resources
Mars
[NBF]root.Data
uUPb
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙