Suspicious
Suspect

7aa72965c35b7bf3c86d6294c01eaa64

PE Executable
MD5: 7aa72965c35b7bf3c86d6294c01eaa64
Size: 778.24 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 7aa72965c35b7bf3c86d6294c01eaa64
Sha1 a7a7cb0d79dc29ee8f03bd0a118a9fb08a9fa8be
Sha256 e5c0d94c239bbf3aa57e92fd08403967b62ae2eaba19d1acc40400d4a1050cb0
Sha384 e76be78286962bf0fee97774a22f966c7c1503a7457a308aa3b78a6cd516a723eed614687e8fb9158ca90288f8808be6
Sha512 2d731fdc96844e36cd66b7723713b116dd9a28091aba3789ea45eee68bbc6e1ca7caf6b320f88ed487041312a94fecd2606dd9f8422d507e523e72cb1674a48d
SSDeep 12288:JixBVn0V6gtShqZ4WM2groYVl6ROu2XY9B8vkLgAPCRVr8UNPu5yhYCHtI5VZ:JEB5y6ymqZy5c2UOubj+RphNPu5tCHM
TLSH 4AF402553747DC03C5AE2BF809A2E3F057B8ADC9B810C3578FFA6DDBB86435128491A6
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Calculator.Form1.resources
$this.Icon
[NBF]root.IconData
msp
[NBF]root.Data
ExtractAssociatedIcon.Form1.resources
Calculator.Properties.Resources.resources
mlcJ
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\InWqdCQLYV\src\obj\Debug\rfIF.pdb
Module Name
rfIF.exe
Full Name
rfIF.exe
EntryPoint
System.Void Calculator.Program::Main()
Scope Name
rfIF.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
rfIF
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
157
Main Method
System.Void Calculator.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Calculator.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Calculator.Form1.resources
$this.Icon
[NBF]root.IconData
msp
[NBF]root.Data
ExtractAssociatedIcon.Form1.resources
Calculator.Properties.Resources.resources
mlcJ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙