Suspicious
Suspect

803519a4e1d0f86d50c0ab28bb736a57

PE Executable
MD5: 803519a4e1d0f86d50c0ab28bb736a57
Size: 791.55 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 803519a4e1d0f86d50c0ab28bb736a57
Sha1 277a50bf5a546c44ba7eb8c3f3641e62a317ced4
Sha256 fce3addf7bc763d7ab8119c76fcf745efbe557cf88b3de94b577a32f69bd304e
Sha384 a1cb5cfd376607ded1f29288d5dc2cb5618cbf1e5383205a638fdad6b7d81efabfbbd3cfdf607c57d798396b5233ebe1
Sha512 05db9863c20b82f41ee7ceae05be334baa68a7efc76d2b9f17d63d35363f347dcb4ec8239f0b8a7a3a258827ee6826fca8a04a7f81d4bd0807304fd5105357eb
SSDeep 12288:RFjZm3qIDesEbE3TUqeY+MK4D5qK9hoW1aLY7OFfIm0NKb07bI5cR9g636nz91UB:SCbYfCW1aLYyHEbI5cn36nzf9
TLSH 35F4014433AAEB03E5B61BF00471E6B403B12E9DB911E3468FE56CE7B57AF805950787
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Used_cars.Presentation.Login.resources
$this.Icon
[NBF]root.IconData
AUDI
[NBF]root.Data
Used_cars.Presentation.Add_cars.resources
Used_cars.Presentation.Car_List.resources
Used_cars.Properties.Resources.resources
tick_green_big
[NBF]root.Data
[NBF]root.Data-preview.png
xcdD
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\FwvEiuTkUD\src\obj\Debug\CDOe.pdb
Module Name
CDOe.exe
Full Name
CDOe.exe
EntryPoint
System.Void Used_cars.Program::Main()
Scope Name
CDOe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CDOe
Assembly Version
4.1.8.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
428
Main Method
System.Void Used_cars.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Used_cars.Presentation.Login::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
CDOe.exe
Full Name
CDOe.exe
EntryPoint
System.Void Used_cars.Program::Main()
Scope Name
CDOe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CDOe
Assembly Version
4.1.8.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
428
Main Method
System.Void Used_cars.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Used_cars.Presentation.Login::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Used_cars.Presentation.Login.resources
$this.Icon
[NBF]root.IconData
AUDI
[NBF]root.Data
Used_cars.Presentation.Add_cars.resources
Used_cars.Presentation.Car_List.resources
Used_cars.Properties.Resources.resources
tick_green_big
[NBF]root.Data
[NBF]root.Data-preview.png
xcdD
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙