Suspicious
Suspect

7a4ffbe1dd9fca0dd05ed6e799ef703f

PE Executable
MD5: 7a4ffbe1dd9fca0dd05ed6e799ef703f
Size: 621.06 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 7a4ffbe1dd9fca0dd05ed6e799ef703f
Sha1 87e9d5f16da9535508cfde659919bc4637a577dd
Sha256 e6e8ef9be0380cfb43b1127f85909488095f2056d67d4ec8512a3ea40f8a4803
Sha384 f661af78d4422e5017c65ff0dca436da5b7e0998a44e7d7df6e5950a691ee8938b40e1cdd3fc8f03ccee52750a7175bd
Sha512 59aa6cdc898d7ae4600bc916ecbae6382fbab4414ced9a77d6c4ae432fe75b9afd07deb1d0b2bb2b2e971a6f921441f88e35ded7b7e134858d83015d894f653d
SSDeep 12288:80Emb13jXFRqjToZ92rZ+X0Z3S62tz477zV2eqBQ0sEAmD:80Emb13j/qjTow+W2a7XV2vBy
TLSH 84D4F0A1371ECE46D8461FF00961E37022759E4CA850D20B5EFE7EABB57731338696A3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BitonicVisualizer.Forms.MainForm.resources
BitonicVisualizer.Properties.Resources.resources
AVR
[NBF]root.Data
[NBF]root.Data-preview.png
owu
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: utk.pdb
Module Name
utk.exe
Full Name
utk.exe
EntryPoint
System.Void BitonicVisualizer.Program::Main()
Scope Name
utk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
utk
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
169
Main Method
System.Void BitonicVisualizer.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BitonicVisualizer.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
utk.exe
Full Name
utk.exe
EntryPoint
System.Void BitonicVisualizer.Program::Main()
Scope Name
utk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
utk
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
169
Main Method
System.Void BitonicVisualizer.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BitonicVisualizer.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BitonicVisualizer.Forms.MainForm.resources
BitonicVisualizer.Properties.Resources.resources
AVR
[NBF]root.Data
[NBF]root.Data-preview.png
owu
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙