Suspicious
Suspect

7d0e7a8df7b03256beddf804a4652b59

PE Executable
MD5: 7d0e7a8df7b03256beddf804a4652b59
Size: 1.13 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 7d0e7a8df7b03256beddf804a4652b59
Sha1 bf7d96a4b75c0c65a6067969b57016d1d43b2418
Sha256 e83333296efc27158b82016eb794f5dcc6ad9d5bf5c1519dfc382bd549f8a472
Sha384 c52a5cc62a69fa0fd090395c4c1ad9f250162aa0744ba39a304ccf4437dfd10c585a6bcbd94b43b5b3db7145fd8c3a22
Sha512 66f463d4beef3b0b76e777edd5fda1f1d69cc156f664f1fe848a9c3063ad0f2d4280fb699d13c6d22702c498ddbf102f010f2f07d06b6a3795594ec871e22239
SSDeep 24576:W1Yc+7mAkXZiSDGq+u4tz7kLW4UQk+x7juBQZR1JjBn+dzZwA8gp:WOc+7JDHJzqW4UQp4ILg
TLSH FD350171346B8E56C82203F2583EDF7113E6AF8C2955C209DFC67E9B757A34A082B50B
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Contacts2025.AboutBox11111.resources
logoPictureBox.Image
[NBF]root.Data
[NBF]root.Data-preview.png
WhoWantToBeMillionaire.Form1.resources
$this.Icon
[NBF]root.IconData
NA
[NBF]root.Data
errorProvider1.TrayLocation
timer1.TrayLocation
timer2.TrayLocation
Contacts2025.Form1.resources
BtnNewContact.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Contacts2025.frmAddOrEdit.resources
Contacts2025.Properties.Resources.resources
CEZ
[NBF]root.Data
[NBF]root.Data-preview.png
F
[NBF]root.Data
[NBF]root.Data-preview.png
R__1_
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: yGe.pdb
Module Name
yGe.exe
Full Name
yGe.exe
EntryPoint
System.Void Contacts2025.Program::Main()
Scope Name
yGe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yGe
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
375
Main Method
System.Void Contacts2025.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Contacts2025.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
yGe.exe
Full Name
yGe.exe
EntryPoint
System.Void Contacts2025.Program::Main()
Scope Name
yGe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yGe
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
375
Main Method
System.Void Contacts2025.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Contacts2025.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Contacts2025.AboutBox11111.resources
logoPictureBox.Image
[NBF]root.Data
[NBF]root.Data-preview.png
WhoWantToBeMillionaire.Form1.resources
$this.Icon
[NBF]root.IconData
NA
[NBF]root.Data
errorProvider1.TrayLocation
timer1.TrayLocation
timer2.TrayLocation
Contacts2025.Form1.resources
BtnNewContact.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Contacts2025.frmAddOrEdit.resources
Contacts2025.Properties.Resources.resources
CEZ
[NBF]root.Data
[NBF]root.Data-preview.png
F
[NBF]root.Data
[NBF]root.Data-preview.png
R__1_
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙