Suspicious
Suspect

PE Executable
MD5: 7e27120fd1f2545a9d34a0e1541322a8
Size: 749.57 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 7e27120fd1f2545a9d34a0e1541322a8
Sha1 9022b64cbd7dcb7ec711ddc777a45eaf6800ad87
Sha256 14a1be3cae3d49fa9ca9cf591fa91c1cee23e3c2532625a17b31de53fe9368a5
Sha384 2945678333765f0115c8c2fcc69b201fe91f96611d7c436bfb05d01d5fb019534007d5555a21cda11d33696764bfff0d
Sha512 ab68969cc6a846d70af415ee61aae04828d2e36dd9ea29515690d0496ec4227bf33d650a8c0c04c46566af844e6db3f2135b6aba5925ed5178884b2e822cbd63
SSDeep 12288:RDI4Dfl+mrvttpxwOuRtq3DP7jbyS7QOpTAA2YSgxswFEP:60FPkizCA+KJ
TLSH 12F401893259DC03C8275BF10812E6B523F19E8CA695C3C78FDA3DDBB9A77581B52243
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Calculator.Form1.resources
$this.Icon
[NBF]root.IconData
Clear
[NBF]root.Data
menuStrip1.TrayLocation
Calculator.Form2.resources
Calculator.Properties.Resources.resources
TBOE
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
rkBD.exe
Full Name
rkBD.exe
EntryPoint
System.Void Calculator.Program::Main()
Scope Name
rkBD.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
rkBD
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
438
Main Method
System.Void Calculator.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Calculator.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
rkBD.exe
Full Name
rkBD.exe
EntryPoint
System.Void Calculator.Program::Main()
Scope Name
rkBD.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
rkBD
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
438
Main Method
System.Void Calculator.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Calculator.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Calculator.Form1.resources
$this.Icon
[NBF]root.IconData
Clear
[NBF]root.Data
menuStrip1.TrayLocation
Calculator.Form2.resources
Calculator.Properties.Resources.resources
TBOE
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙