Suspicious
Suspect

78e043747352358c4b19f5f2cdc29b5b

PE Executable
MD5: 78e043747352358c4b19f5f2cdc29b5b
Size: 1.24 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 78e043747352358c4b19f5f2cdc29b5b
Sha1 20381eacd3f774ddb288d84cfb707975e2e322d0
Sha256 e17202f7475e7591c9b183af853c2c1a8c1b61561b0befbcd248aa49c28f3e50
Sha384 4d1bffd80bec33d493705083bdff7aeff896b61baf4702dde7139eaaf6a11eda200cb224bbb25e05dc4d7c32a3781698
Sha512 f66943fc0f16c7524a1ffe558dd5ec8e19335d6ce67642082e2dc4918f885ae25a9f069aff72f3debd5c0795172a3b43be653a7b9698e9380697e2864b3201c6
SSDeep 24576:pUEAEbnf5WpKL+xDobfZFmhW+eFZiOs2qi:2unfvGmmhW33
TLSH FA45CF023385DF10D56F1AB1D8B2C6F41727BE04EC14C3C76AD9FEAB78B26A56951283
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HTMLValidator.Forms.MainForm.resources
HTMLValidator.Properties.Resources.resources
dr
[NBF]root.Data
lLYr
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x12A600 size 13832 bytes
Info
PDB Path: wZPU.pdb
Module Name
wZPU.exe
Full Name
wZPU.exe
EntryPoint
System.Void HTMLValidator.Program::Main()
Scope Name
wZPU.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
wZPU
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
364
Main Method
System.Void HTMLValidator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HTMLValidator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
wZPU.exe
Full Name
wZPU.exe
EntryPoint
System.Void HTMLValidator.Program::Main()
Scope Name
wZPU.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
wZPU
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
364
Main Method
System.Void HTMLValidator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HTMLValidator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HTMLValidator.Forms.MainForm.resources
HTMLValidator.Properties.Resources.resources
dr
[NBF]root.Data
lLYr
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙