Suspicious
Suspect

PE Executable
MD5: 793868cbdce3d5b279ccaf465702a31a
Size: 743.42 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 793868cbdce3d5b279ccaf465702a31a
Sha1 f8d66bb0cd5e4f95015cd9f1b47a1c30ac883f95
Sha256 b4a46f9be7587e5ca51f2a4c20e8fd08f39c2d0e36a9de245a11f90ef11fc08c
Sha384 33a4ff704f464fd1593220f19e29952b6f49fc79736f1e3f3359b57b022f37acb3eb474ccbdda7c24c5f599d4333aa43
Sha512 7ed3d326bc1f552c276e08cf2399d78ba4bbc7d2354d5a665f4ebee1880285308c4a54d2ff0aea070ffbc47d35a05948aedbe675f09578ccca2d44599d1bfd2c
SSDeep 12288:NgrfHnbS39HAbsdMSHA97m9B+3B2D5FKBromE2Hcjl72:SHnbS6bTs+3B6i7EV72
TLSH 04F4012C228E5B22C1FB5BF81411D0B653BA6D9E7551F71A8FC52CEF3D62BA20906713
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RepositoryModule.MainForm.resources
RepositoryModule.Properties.Resources.resources
DQ
cZKu
Name Value
Module Name
FfHZ.exe
Full Name
FfHZ.exe
EntryPoint
System.Void RepositoryModule.Program::Main()
Scope Name
FfHZ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
FfHZ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
679
Main Method
System.Void RepositoryModule.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void RepositoryModule.Program::InitializeApplication()
nop <null>
newobj System.Void RepositoryModule.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
FfHZ.exe
Full Name
FfHZ.exe
EntryPoint
System.Void RepositoryModule.Program::Main()
Scope Name
FfHZ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
FfHZ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
679
Main Method
System.Void RepositoryModule.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void RepositoryModule.Program::InitializeApplication()
nop <null>
newobj System.Void RepositoryModule.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
8huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RepositoryModule.MainForm.resources
RepositoryModule.Properties.Resources.resources
DQ
cZKu
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
8huhuhuhu
793868cbdce3d5b279ccaf465702a31a
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
793868cbdce3d5b279ccaf465702a31a
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙