Suspicious
Suspect

82c84bd9f7afa0ca30ed44f9d210fa54

PE Executable
MD5: 82c84bd9f7afa0ca30ed44f9d210fa54
Size: 851.46 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 82c84bd9f7afa0ca30ed44f9d210fa54
Sha1 0c3d30c5a1397031d1ba3346c5e203abce9b7ec4
Sha256 f75840264d34021cc2dc7c5c5b7c4caf93eb5b8098015941e889a84a7de2be90
Sha384 e0c567b3d0a660887e094de29f73e7a1df9b43f989d95812912903626a7dad7e33742b764afb4cd0d9c5749cad15cd0a
Sha512 7b9ff5fed26830494194918d512ad8a9dc5d6c3a154639b4c6430841d7c1ea3b3624576c16a702a3b95531104d71db8447558ce0b531cd1710cdef8ebf8eac40
SSDeep 12288:x3L/rb8Wk0yOEq0EI20gnzDcLsJuJJHxcE4pNEa8DdB0orOnSDg+1I/1:Z7v+0yOVI2pnzwMuTRcdEa8xujnV
TLSH 800512242B5EEE03D9A127F406A0E7312378AD5CE511D2138FEEBCDB74B5B562934293
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FibonacciDrawer.IterationControlForm.resources
FibonacciDrawer.Properties.Resources.resources
NI
[NBF]root.Data
SVHK
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: bVmI.pdb
Module Name
bVmI.exe
Full Name
bVmI.exe
EntryPoint
System.Void FibonacciDrawer.Program::Main()
Scope Name
bVmI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
bVmI
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
143
Main Method
System.Void FibonacciDrawer.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void FibonacciDrawer.MainSpiralForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
bVmI.exe
Full Name
bVmI.exe
EntryPoint
System.Void FibonacciDrawer.Program::Main()
Scope Name
bVmI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
bVmI
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
143
Main Method
System.Void FibonacciDrawer.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void FibonacciDrawer.MainSpiralForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FibonacciDrawer.IterationControlForm.resources
FibonacciDrawer.Properties.Resources.resources
NI
[NBF]root.Data
SVHK
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙